HEALTHCARE COMPLIANCE
What Is Business Associate Agreement (BAA)?
DEFINITION
A Business Associate Agreement (BAA) is a contract required under HIPAA between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It obligates the vendor to apply Security Rule safeguards, report breaches and security incidents, and flow the same terms down to subcontractors, and it establishes direct HIPAA liability for the business associate.
A Business Associate Agreement is the legal mechanism HIPAA uses to extend privacy and security obligations beyond the covered entity itself. When a hospital, clinic, or health plan hands PHI to an outside party, such as a billing company, EHR host, cloud provider, analytics vendor, or IT managed services firm, HIPAA requires a written agreement before that data changes hands. The BAA must describe permitted uses of PHI, require Security Rule safeguards, mandate breach and incident reporting back to the covered entity, and require the business associate to bind its own subcontractors to equivalent terms.
BAAs apply to both sides of the relationship. Covered entities must obtain them, and business associates are directly liable under HIPAA for Security Rule compliance and breach notification whether or not the contract is well drafted. Signing a BAA without an underlying security program is a liability, not a shield.
The practical implication is that vendor inventory and BAA tracking are compliance controls, not paperwork. Organizations frequently discover during a security risk assessment that PHI flows to vendors with no BAA in place, which is itself a violation. Healthcare organizations can see how vendor risk fits into a managed security program on our healthcare industry page.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →