What is a business associate agreement? What is BAA, and what a BAA contract must contain

Updated

A business associate agreement, almost always shortened to BAA, is the contract a HIPAA covered entity signs with any organisation that creates, receives, maintains or transmits protected health information on its behalf. Your billing company has one. So does your practice management vendor, your document shredding company, your answering service, your cloud backup provider and, in most arrangements, your IT support firm. The reason a provider organisation ends up with dozens of them is that every new supplier who touches patient data brings one, and the reason nobody can produce the list on request is that they arrive one at a time, from different departments, attached to different purchases. This page explains what the agreement is, what the rule requires it to say, and how to keep the set of them straight.

Who needs one, and who does not

The test is function, not job title. If an organisation performs a service for or on behalf of a covered entity that involves creating, receiving, maintaining or transmitting protected health information, it is a business associate and needs an agreement. A subcontractor of a business associate that touches the same information needs one too, from the business associate rather than from you. What does not need one is a conduit that only transports data without accessing it, or another covered entity you are exchanging information with for treatment purposes. Where an arrangement is genuinely borderline, that is a question for counsel rather than for a template.

What a BAA contract must contain

The rule is specific about the provisions. A contract between the covered entity and a business associate must establish the permitted and required uses and disclosures of protected health information, and provide that the business associate will not use or further disclose the information other than as permitted by the contract or required by law, will use appropriate safeguards, will report to the covered entity any use or disclosure not provided for by the contract including breaches of unsecured protected health information, and will ensure that its subcontractors agree to the same restrictions (45 CFR 164.504(e)(2)). It must also address return or destruction of the information at termination and permit the covered entity to terminate for a material breach.

The clock in the agreement you will care about most

Breach reporting is where the agreement stops being paperwork. A business associate must notify the covered entity following discovery of a breach of unsecured protected health information without unreasonable delay and in no case later than 60 calendar days after discovery (45 CFR 164.410(b)). That outer limit is the regulatory floor, not a target, and many organisations negotiate a shorter reporting window into the agreement, because the covered entity's own notification obligations start running from what the business associate tells it. Whatever your agreements say, the number that matters is the one your contract sets, which is why the abstract has to record it.

The problem is not the template, it is the set

Most organisations get individual BAAs approximately right, because the vendor supplies a template and legal reviews it once. What they get wrong is the collection: nobody holds a list of which suppliers have a current agreement, which ones changed hands or changed subprocessors, and which ones lapsed when the underlying service contract was renegotiated. Treat the BAA as one of the four document families in the folder, abstract it to the same fixed shape as everything else with the reporting window and the termination terms recorded, and put its dates in the same register. The question a regulator or an acquirer asks is never about one agreement; it is for the list.

Questions people ask about what is a business associate agreement

Is a BAA the same as a data processing agreement?

No, though they solve a similar problem in different regimes. A BAA is a HIPAA instrument with provisions the rule specifies; a data processing agreement belongs to data protection law. An organisation operating under both may need each, and the presence of one does not satisfy the other.

Do we need a BAA with a vendor who only might see patient data?

If the service involves maintaining or transmitting protected health information, incidental access is still access, which is why maintenance, storage and support arrangements usually need one. The practical rule most compliance officers apply is that if the vendor can reach the data, get the agreement.

How should we keep track of the ones we hold?

The same way as every other agreement: one record per BAA with the counterparty, the underlying service, the breach reporting window, the termination and return-or-destroy terms, and the date it was signed, all in the register the rest of the folder uses. Medcontra's worksheet abstracts it to that shape from your own copy.

Sources

Related answers

Keep this abstract in Medcontra ProNever miss a renewal: start Pro