Required Terms and Red Flags

Business Associate Agreements: What to Look For Before You Sign

Knowing what to look for in a business associate agreement protects your organization when a vendor handles protected health information. A BAA is legally required whenever a business associate creates, receives, maintains, or transmits PHI on your behalf, but not every BAA is equally protective. This guide covers the terms HIPAA requires, the provisions worth negotiating, and red flags that should give you pause. It isn't legal advice, so have counsel review any agreement. Custom Healthcare Solutions signs BAAs for projects involving PHI and can walk you through ours.

When a Business Associate Agreement Is Required

A business associate is a person or organization that performs functions or services for a covered entity involving the use or disclosure of PHI. Software developers, cloud hosts, billing companies, and IT support vendors commonly qualify. Business associates can also have subcontractors who need their own agreements. Understanding when a BAA is required prevents both gaps and unnecessary paperwork. Our healthcare compliance and security page explains when we sign one.

Vendors That Handle PHI

Any vendor that creates, receives, stores, or transmits PHI for you needs a BAA, including software developers with production access, hosting providers, analytics vendors, messaging platforms, and outsourced support teams and call centers.

The Conduit Exception

Services that only transmit data without storing it, such as internet service providers, generally fall under the narrow conduit exception. Cloud providers storing PHI, even encrypted, do not qualify for this exception.

Subcontractor Agreements

Business associates must obtain BAAs from subcontractors that handle PHI on their behalf. Ask vendors to list subcontractors with PHI access and confirm those downstream agreements exist and are current.

When a BAA Isn't Needed

Vendors that never access PHI, such as a developer working only with synthetic data, may not need one. Document that determination, and revisit it if the vendor's access changes.

Terms HIPAA Requires in Every BAA

HIPAA specifies required elements for business associate agreements. A BAA missing any of them may not satisfy the rule, even if both parties signed it in good faith. HHS publishes sample BAA provisions that many organizations use as a baseline. Review any vendor's agreement against the required terms below before looking at negotiable provisions, and ask counsel to confirm the agreement meets current requirements for your situation and state.

Permitted Uses and Disclosures

The BAA must define how the business associate may use and disclose PHI, limited to performing its services and certain legally permitted purposes. Anything broader should be questioned carefully before signing.

Safeguards and Reporting

The business associate must use appropriate safeguards, comply with the Security Rule for electronic PHI, and report uses or disclosures not permitted by the agreement, including breaches of unsecured PHI.

Subcontractor Flow-Down

The agreement must require the business associate to ensure subcontractors handling PHI agree to the same restrictions and conditions. This protection follows your data downstream wherever it travels across vendors.

Access, Amendment, Return, and Termination

The BAA must support patient access and amendment rights, make records available to HHS, allow termination for material violations, and require return or destruction of PHI when the relationship ends.

Provisions Worth Negotiating

Required terms set the minimum. The provisions below determine how well the agreement actually protects you in practice. Vendors often offer standard BAAs designed to limit their obligations, and many will negotiate reasonable changes, especially for larger contracts. Focus on the terms that affect your response to incidents and your ability to leave the relationship cleanly, because those are where weak agreements cause the most real-world problems for covered entities.

Breach Notification Timing

HIPAA allows business associates up to 60 days to report a breach, but that leaves you little time to meet your own deadlines. Negotiate shorter notice, such as five to ten days.

Security Incident Details

Require prompt reporting of security incidents, with enough detail to assess impact: what happened, which data was involved, affected individuals, and remediation steps. Vague notices slow your investigation and response significantly.

Indemnification and Insurance

Consider requiring the business associate to cover costs from breaches it causes, such as notification and credit monitoring, and to maintain adequate cyber liability insurance with appropriate coverage limits.

Data Return and Destruction

Specify timelines and methods for returning or destroying PHI at termination, including backups, and require written certification. If destruction isn't feasible, the BAA should extend protections for as long as data remains.

BAA Red Flags to Watch For

Some BAAs technically include required terms but undermine them elsewhere, or reveal a vendor that isn't prepared to handle PHI responsibly. These red flags don't always mean you should walk away, but they warrant questions and possibly legal review before signing. If a vendor refuses to sign any BAA while handling PHI, that's not a red flag; it's a dealbreaker. Our PHI project pricing page shows how our projects involving PHI are structured.

Coverage Limited to Certain Services

Some BAAs cover only specific products, plan tiers, or features. Confirm the services you'll actually use are listed, and keep PHI out of anything the agreement excludes entirely, at all times.

Broad Rights to Use or Aggregate Data

Clauses allowing the vendor to use PHI for product development, analytics, or AI training beyond permitted purposes deserve scrutiny. De-identification rights should follow HIPAA's standards explicitly and be clearly defined.

Maximum Notification Windows

A BAA that simply mirrors the 60-day maximum for breach reporting, with no commitment to prompt notice, suggests the vendor prioritizes its own convenience over your response obligations to patients.

Liability Caps That Exclude Breaches

Low liability caps that exclude or limit breach-related costs can leave you paying for a vendor's mistakes. Review limitation-of-liability clauses in the main contract alongside the BAA itself.

Frequently Asked Questions About Business Associate Agreements

What must a business associate agreement include?

HIPAA requires a BAA to define permitted uses and disclosures of PHI, require appropriate safeguards and Security Rule compliance, require reporting of breaches and unauthorized uses, flow requirements down to subcontractors, support patient rights, make records available to HHS, and require return or destruction of PHI at termination.

Who needs to sign a BAA?

Covered entities must sign BAAs with any business associate that creates, receives, maintains, or transmits PHI on their behalf, such as software developers, cloud hosts, billing services, and IT vendors. Business associates must also sign BAAs with subcontractors that handle PHI for them.

How quickly must a business associate report a breach?

HIPAA requires business associates to notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI. Because covered entities have their own notification deadlines, many negotiate shorter reporting windows, such as five to ten days, in the BAA.

Does a cloud provider need to sign a BAA?

Yes, if it stores or processes PHI, even encrypted PHI without access to the keys, according to HHS guidance. Major cloud providers offer BAAs, but they typically cover only specific HIPAA-eligible services, so confirm every service handling PHI is covered before using it.

What happens if we don't have a BAA with a vendor?

Sharing PHI with a business associate without a BAA can violate HIPAA and has resulted in OCR settlements. It also leaves you without contractual protections if the vendor mishandles data. If you discover a missing BAA, stop PHI sharing, execute an agreement, and document the remediation.