HIPAAmart

Third-party risk · 10 min read

Business Associate Agreements

A practical center for deciding when a BAA is needed and connecting contract terms to the vendor's actual service.

Reviewed August 2026

Definition

A business associate agreement is a written arrangement that establishes permitted and required uses and disclosures of PHI and the safeguards and responsibilities between the parties.

In practice

  • A cloud service's BAA is reviewed alongside the exact services used, account configuration, access model, and logs.
  • A billing vendor's subcontractor is added to the oversight inventory before PHI is shared.

Who this applies to

  • Covered entities engaging business associates
  • Business associates engaging subcontractors
  • Procurement, legal, privacy, security, and vendor-management teams

What the rule asks for

  • Determine whether the service relationship falls within the business associate definition.
  • Address permitted uses, safeguards, reporting, individual rights support, and return or destruction obligations.
  • Flow relevant requirements to subcontractors and maintain oversight.

How teams put it into practice

  • Review the BAA with the product, security documentation, retention behavior, and support model.
  • Track signature, scope, subprocessors, renewals, incidents, and offboarding.
  • Use a risk-based vendor review instead of treating the BAA as the entire assessment.

Common mistakes

  • Assuming a BAA makes either party automatically compliant.
  • Signing a generic agreement that does not match the service.
  • Ignoring support personnel, subprocessors, backups, or deletion behavior.

Questions that come up

Do I need a BAA with a cloud provider?

If the provider is a business associate because it creates, receives, maintains, or transmits PHI for a covered entity or business associate, the parties should address the applicable business associate requirements and contractual arrangement.

References