A business associate agreement is the contract HIPAA requires before a vendor can handle protected health information on a covered entity’s behalf.
The short answer
A business associate agreement, or BAA, is a written contract between a covered entity and a business associate that sets out how PHI may be used, what safeguards must be in place, what happens after a breach, and what becomes of the data when the relationship ends. Without a signed BAA, disclosing PHI to that vendor is itself a HIPAA violation, regardless of how secure the vendor is.
It is a paperwork requirement with teeth. Enforcement actions regularly cite missing BAAs where no breach of data ever occurred.
On this page
When you need one
| Relationship | BAA needed? |
|---|---|
| Cloud hosting provider storing your patient database | Yes, even if the data is encrypted and they never look at it |
| Analytics or error-monitoring tool receiving identifiers | Yes, if any PHI reaches it |
| A subcontractor your business associate uses | Yes, signed between the associate and the subcontractor |
| An internet provider carrying encrypted traffic only | No, the conduit exception applies to transmission without storage |
| Your own employees | No, workforce members are covered by policy and training instead |
| Another provider treating the same patient | No, treatment disclosures between providers are permitted |
Encryption does not remove the requirement
The conduit exception is narrow. It covers pure transmission, like a courier or a telecoms carrier. A cloud provider that stores encrypted PHI, even without the key, is a business associate and needs a BAA.
What a BAA must contain
The subcontractor chain
Obligations flow downhill. A covered entity signs with its business associate. That associate signs with any subcontractor that touches PHI. The chain continues for as long as the data does, and each link owes the same protections upward.
Since the 2013 Omnibus Rule, business associates carry direct liability for Security Rule compliance. Regulators can act against a vendor without going through the covered entity first.
What a BAA does not do
It does not make you compliant
The contract sets obligations. Meeting them still requires the controls to actually exist and run.
It does not transfer your risk
A covered entity remains accountable for choosing vendors and overseeing the relationship.
It does not certify the vendor
There is no HIPAA certification. A signed BAA is a promise, not third-party assurance.
How Osto supports the obligations
A BAA commits you to Security Rule safeguards. Osto is where those safeguards run: access control and MFA, encryption, audit logging, endpoint control and cloud posture, with evidence mapped to technical, physical and administrative safeguards. When a customer asks what you have in place before signing, the evidence is already collected.
Free security assessment
Meet what your BAA commits you to
A BAA promises Security Rule safeguards. Osto is where those safeguards run, with the evidence collected as they do.
Get a free security assessment Book a platform walkthroughControls plus evidence · Questionnaires answered · One platform, everything
Frequently asked questions
What is a business associate agreement?
A written contract between a HIPAA covered entity and a vendor that handles PHI on its behalf. It defines permitted uses, required safeguards, breach reporting duties and what happens to the data at termination.
When is a BAA required?
Whenever a vendor creates, receives, maintains or transmits PHI for a covered entity. That includes cloud hosting, analytics and support tools. It must be signed before PHI is shared, not afterwards.
What happens if you do not have a BAA?
Disclosing PHI without one is itself a violation. Enforcement actions have imposed substantial penalties for missing BAAs where no data was ever exposed, because the failure is the disclosure without a contract.
Do subcontractors need their own BAA?
Yes. A business associate must have a BAA with any subcontractor that touches PHI, on terms at least as protective as its own. Obligations flow down the whole chain.
Does a BAA make a vendor HIPAA compliant?
No. There is no HIPAA certification and a BAA is a contractual commitment rather than proof. Vendors typically demonstrate their controls through a SOC 2 report or an independent assessment.

