Business Associate Agreement: What a BAA Needs

Business associate agreement required clauses under HIPAA

A business associate agreement is the contract HIPAA requires before a vendor can handle protected health information on a covered entity’s behalf.

  • Glossary
  • HIPAA

The short answer

A business associate agreement, or BAA, is a written contract between a covered entity and a business associate that sets out how PHI may be used, what safeguards must be in place, what happens after a breach, and what becomes of the data when the relationship ends. Without a signed BAA, disclosing PHI to that vendor is itself a HIPAA violation, regardless of how secure the vendor is.

It is a paperwork requirement with teeth. Enforcement actions regularly cite missing BAAs where no breach of data ever occurred.

When you need one

RelationshipBAA needed?
Cloud hosting provider storing your patient databaseYes, even if the data is encrypted and they never look at it
Analytics or error-monitoring tool receiving identifiersYes, if any PHI reaches it
A subcontractor your business associate usesYes, signed between the associate and the subcontractor
An internet provider carrying encrypted traffic onlyNo, the conduit exception applies to transmission without storage
Your own employeesNo, workforce members are covered by policy and training instead
Another provider treating the same patientNo, treatment disclosures between providers are permitted

Encryption does not remove the requirement

The conduit exception is narrow. It covers pure transmission, like a courier or a telecoms carrier. A cloud provider that stores encrypted PHI, even without the key, is a business associate and needs a BAA.

What a BAA must contain

REQUIRED CLAUSES Permitted uses What the associate may do with PHI Safeguards Security Rule controls, applied Subcontractor flow-down Same terms passed downstream Breach reporting Notify the covered entity, on a clock Individual rights Support access and amendment requests Return or destruction At termination, including backups Also required: the covered entity may terminate on breach of the agreement, and HHS gets access on request.

The subcontractor chain

Obligations flow downhill. A covered entity signs with its business associate. That associate signs with any subcontractor that touches PHI. The chain continues for as long as the data does, and each link owes the same protections upward.

Since the 2013 Omnibus Rule, business associates carry direct liability for Security Rule compliance. Regulators can act against a vendor without going through the covered entity first.

What a BAA does not do

It does not make you compliant

The contract sets obligations. Meeting them still requires the controls to actually exist and run.

It does not transfer your risk

A covered entity remains accountable for choosing vendors and overseeing the relationship.

It does not certify the vendor

There is no HIPAA certification. A signed BAA is a promise, not third-party assurance.

How Osto supports the obligations

A BAA commits you to Security Rule safeguards. Osto is where those safeguards run: access control and MFA, encryption, audit logging, endpoint control and cloud posture, with evidence mapped to technical, physical and administrative safeguards. When a customer asks what you have in place before signing, the evidence is already collected.

Free security assessment

Meet what your BAA commits you to

A BAA promises Security Rule safeguards. Osto is where those safeguards run, with the evidence collected as they do.

Get a free security assessment Book a platform walkthrough

Controls plus evidence · Questionnaires answered · One platform, everything

Frequently asked questions

What is a business associate agreement?

A written contract between a HIPAA covered entity and a vendor that handles PHI on its behalf. It defines permitted uses, required safeguards, breach reporting duties and what happens to the data at termination.

When is a BAA required?

Whenever a vendor creates, receives, maintains or transmits PHI for a covered entity. That includes cloud hosting, analytics and support tools. It must be signed before PHI is shared, not afterwards.

What happens if you do not have a BAA?

Disclosing PHI without one is itself a violation. Enforcement actions have imposed substantial penalties for missing BAAs where no data was ever exposed, because the failure is the disclosure without a contract.

Do subcontractors need their own BAA?

Yes. A business associate must have a BAA with any subcontractor that touches PHI, on terms at least as protective as its own. Obligations flow down the whole chain.

Does a BAA make a vendor HIPAA compliant?

No. There is no HIPAA certification and a BAA is a contractual commitment rather than proof. Vendors typically demonstrate their controls through a SOC 2 report or an independent assessment.