{"id":829,"date":"2026-08-17T04:46:11","date_gmt":"2026-08-17T04:46:11","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=829"},"modified":"2026-08-17T04:46:11","modified_gmt":"2026-08-17T04:46:11","slug":"business-associate-agreement","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/business-associate-agreement\/","title":{"rendered":"Business Associate Agreement: What a BAA Needs"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: BUSINESS ASSOCIATE AGREEMENT\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A business associate agreement is the contract HIPAA requires before a vendor can handle protected health information on a covered entity&#8217;s behalf.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A business associate agreement, or BAA, is a written contract between a covered entity and a business associate that sets out how PHI may be used, what safeguards must be in place, what happens after a breach, and what becomes of the data when the relationship ends. Without a signed BAA, disclosing PHI to that vendor is itself a HIPAA violation, regardless of how secure the vendor is.<\/p>\n<\/div>\n\n<p>It is a paperwork requirement with teeth. Enforcement actions regularly cite missing BAAs where no breach of data ever occurred.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#when\">When you need one<\/a><\/li>\n    <li><a href=\"#contains\">What a BAA must contain<\/a><\/li>\n    <li><a href=\"#chain\">The subcontractor chain<\/a><\/li>\n    <li><a href=\"#not\">What a BAA does not do<\/a><\/li>\n    <li><a href=\"#osto\">How Osto supports the obligations<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"when\">When you need one<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Relationship<\/th><th>BAA needed?<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Cloud hosting provider storing your patient database<\/td><td>Yes, even if the data is encrypted and they never look at it<\/td><\/tr>\n    <tr><td>Analytics or error-monitoring tool receiving identifiers<\/td><td>Yes, if any PHI reaches it<\/td><\/tr>\n    <tr><td>A subcontractor your business associate uses<\/td><td>Yes, signed between the associate and the subcontractor<\/td><\/tr>\n    <tr><td>An internet provider carrying encrypted traffic only<\/td><td>No, the conduit exception applies to transmission without storage<\/td><\/tr>\n    <tr><td>Your own employees<\/td><td>No, workforce members are covered by policy and training instead<\/td><\/tr>\n    <tr><td>Another provider treating the same patient<\/td><td>No, treatment disclosures between providers are permitted<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Encryption does not remove the requirement<\/p>\n  <p>The conduit exception is narrow. It covers pure transmission, like a courier or a telecoms carrier. A cloud provider that stores encrypted PHI, even without the key, is a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/business-associate\/\">business associate<\/a> and needs a BAA.<\/p>\n<\/div>\n\n<h2 id=\"contains\" class=\"c-sage\">What a BAA must contain<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Required BAA clauses: permitted uses, safeguards, subcontractor flow-down, breach reporting, individual rights, and return or destruction of data.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">REQUIRED CLAUSES<\/text>\n\n  <rect x=\"12\" y=\"42\" width=\"238\" height=\"62\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"131\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Permitted uses<\/text>\n  <text x=\"131\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">What the associate may do with PHI<\/text>\n\n  <rect x=\"261\" y=\"42\" width=\"238\" height=\"62\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Safeguards<\/text>\n  <text x=\"380\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Security Rule controls, applied<\/text>\n\n  <rect x=\"510\" y=\"42\" width=\"238\" height=\"62\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"629\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Subcontractor flow-down<\/text>\n  <text x=\"629\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Same terms passed downstream<\/text>\n\n  <rect x=\"12\" y=\"116\" width=\"238\" height=\"62\" rx=\"13\" fill=\"#f0e6f3\"\/>\n  <text x=\"131\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">Breach reporting<\/text>\n  <text x=\"131\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Notify the covered entity, on a clock<\/text>\n\n  <rect x=\"261\" y=\"116\" width=\"238\" height=\"62\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"380\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#2f6a89\">Individual rights<\/text>\n  <text x=\"380\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Support access and amendment requests<\/text>\n\n  <rect x=\"510\" y=\"116\" width=\"238\" height=\"62\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"629\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Return or destruction<\/text>\n  <text x=\"629\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">At termination, including backups<\/text>\n\n  <rect x=\"12\" y=\"196\" width=\"736\" height=\"40\" rx=\"11\" fill=\"#f4f5fd\"\/>\n  <text x=\"380\" y=\"221\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Also required: the covered entity may terminate on breach of the agreement, and HHS gets access on request.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"chain\" class=\"c-apri\">The subcontractor chain<\/h2>\n\n<p>Obligations flow downhill. A covered entity signs with its business associate. That associate signs with any subcontractor that touches PHI. The chain continues for as long as the data does, and each link owes the same protections upward.<\/p>\n\n<p>Since the 2013 Omnibus Rule, business associates carry direct liability for Security Rule compliance. Regulators can act against a vendor without going through the covered entity first.<\/p>\n\n<h2 id=\"not\" class=\"c-plum\">What a BAA does not do<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">It does not make you compliant<\/p>\n    <p>The contract sets obligations. Meeting them still requires the controls to actually exist and run.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">It does not transfer your risk<\/p>\n    <p>A covered entity remains accountable for choosing vendors and overseeing the relationship.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">It does not certify the vendor<\/p>\n    <p>There is no HIPAA certification. A signed BAA is a promise, not third-party assurance.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto supports the obligations<\/h2>\n\n<p>A BAA commits you to Security Rule safeguards. Osto is where those safeguards run: <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">access control and MFA<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">encryption<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">audit logging<\/a>, endpoint control and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a>, with evidence mapped to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/technical-safeguards\/\">technical<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/physical-safeguards\/\">physical<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/administrative-safeguards\/\">administrative safeguards<\/a>. When a customer asks what you have in place before signing, the <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-evidence-collection\/\" target=\"_blank\" rel=\"noopener\">evidence is already collected<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Meet what your BAA commits you to<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">A BAA promises Security Rule safeguards. Osto is where those safeguards run, with the evidence collected as they do.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Controls plus evidence &middot; Questionnaires answered &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a business associate agreement?<\/summary>\n  <p>A written contract between a HIPAA covered entity and a vendor that handles PHI on its behalf. It defines permitted uses, required safeguards, breach reporting duties and what happens to the data at termination.<\/p>\n<\/details>\n\n<details>\n  <summary>When is a BAA required?<\/summary>\n  <p>Whenever a vendor creates, receives, maintains or transmits PHI for a covered entity. That includes cloud hosting, analytics and support tools. It must be signed before PHI is shared, not afterwards.<\/p>\n<\/details>\n\n<details>\n  <summary>What happens if you do not have a BAA?<\/summary>\n  <p>Disclosing PHI without one is itself a violation. Enforcement actions have imposed substantial penalties for missing BAAs where no data was ever exposed, because the failure is the disclosure without a contract.<\/p>\n<\/details>\n\n<details>\n  <summary>Do subcontractors need their own BAA?<\/summary>\n  <p>Yes. A business associate must have a BAA with any subcontractor that touches PHI, on terms at least as protective as its own. Obligations flow down the whole chain.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a BAA make a vendor HIPAA compliant?<\/summary>\n  <p>No. There is no HIPAA certification and a BAA is a contractual commitment rather than proof. Vendors typically demonstrate their controls through a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> report or an independent assessment.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> Business Associate &middot; Covered Entity &middot; PHI &middot; HIPAA Security Rule &middot; HIPAA Breach Notification Rule &middot; SOC 2<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A business associate agreement is the contract HIPAA requires before a vendor can handle protected health information on a covered\u2026<\/p>\n","protected":false},"author":8,"featured_media":830,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[118,117,327],"class_list":["post-829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-baa","tag-business-associate-agreement","tag-hipaa-baa"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=829"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/829\/revisions"}],"predecessor-version":[{"id":831,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/829\/revisions\/831"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/830"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}