A Business Associate Agreement (BAA) is a legally required contract between a HIPAA covered entity and any business associate that creates, receives, maintains, or transmits protected health information (PHI) on behalf of the covered entity. Without a proper BAA in place, both parties are in violation of HIPAA, regardless of whether a breach has occurred. This guide covers everything you need to know about BAAs, from determining who qualifies as a business associate to structuring compliant agreements.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
Operating without a required BAA is a HIPAA violation for both the covered entity and the business associate, regardless of whether a breach occurs. OCR settlements for missing BAAs have ranged from $50,000 to $1.55 million. Both parties face potential enforcement action and have no contractual mechanism to enforce HIPAA compliance obligations.
Yes. Any cloud provider that stores, processes, or transmits PHI on behalf of a covered entity or business associate is itself a business associate and requires a BAA. This applies even if the data is encrypted and the cloud provider does not hold the decryption keys, because the provider maintains the ePHI.
BAAs should be reviewed and updated whenever HIPAA regulations change, when the scope of services changes, when the business associate's data handling practices are modified, or at minimum annually. Organizations should avoid treating BAAs as static documents that are signed once and never revisited.
A BAA (Business Associate Agreement) is required by HIPAA for U.S. healthcare data, while a DPA (Data Processing Agreement) is required by GDPR for EU personal data. Both govern how third parties handle sensitive data, but they have different legal bases, required provisions, and applicable penalties. Organizations handling both types of data may need both agreements with a single vendor.
Yes. A BAA can be a standalone document or incorporated as an addendum or exhibit to a larger service agreement. What matters is that all required provisions under 45 CFR 164.504(e) are included and that the BAA is executed before PHI is shared. Many organizations prefer a standalone BAA for clarity and easier updating.
Yes. The 2013 Omnibus Rule requires business associates to execute downstream BAAs with any subcontractor that creates, receives, maintains, or transmits PHI on the business associate's behalf. This requirement flows down through the entire chain of entities handling PHI.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for HIPAA compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free