Definition
A business associate agreement is a written arrangement that establishes permitted and required uses and disclosures of PHI and the safeguards and responsibilities between the parties.
In practice
- A cloud service's BAA is reviewed alongside the exact services used, account configuration, access model, and logs.
- A billing vendor's subcontractor is added to the oversight inventory before PHI is shared.
Who this applies to
- Covered entities engaging business associates
- Business associates engaging subcontractors
- Procurement, legal, privacy, security, and vendor-management teams
What the rule asks for
- Determine whether the service relationship falls within the business associate definition.
- Address permitted uses, safeguards, reporting, individual rights support, and return or destruction obligations.
- Flow relevant requirements to subcontractors and maintain oversight.
How teams put it into practice
- Review the BAA with the product, security documentation, retention behavior, and support model.
- Track signature, scope, subprocessors, renewals, incidents, and offboarding.
- Use a risk-based vendor review instead of treating the BAA as the entire assessment.
Common mistakes
- Assuming a BAA makes either party automatically compliant.
- Signing a generic agreement that does not match the service.
- Ignoring support personnel, subprocessors, backups, or deletion behavior.
Questions that come up
Do I need a BAA with a cloud provider?
If the provider is a business associate because it creates, receives, maintains, or transmits PHI for a covered entity or business associate, the parties should address the applicable business associate requirements and contractual arrangement.
References
- Business associate contracts HHS Office for Civil Rights