TL;DR

A Business Associate Agreement (BAA) is a HIPAA-required contract between a covered entity and any vendor that handles protected health information (PHI) on the entity’s behalf. It spells out what the vendor can and cannot do with PHI, what safeguards are required, how breaches get reported, and what happens when the relationship ends. A signed BAA is legally required before PHI flows to a vendor, but it is not a magic compliance badge. Safe practices also require verifying the vendor’s actual safeguards, confirming which services are covered, and keeping patient data inside protected channels.

What Is a Business Associate Agreement?

A Business Associate Agreement is a written HIPAA contract between a covered entity (like a healthcare provider, health plan, or clearinghouse) and a business associate (a vendor or partner that handles PHI on the entity’s behalf). The agreement can also exist between a business associate and its subcontractor when that subcontractor touches PHI.

The purpose is straightforward. HIPAA says covered entities can outsource functions that involve patient data, but only with written satisfactory assurances that the vendor will safeguard the information and use it only for the work it was hired to do.

Under 45 CFR § 160.103, a business associate is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity for regulated functions or listed services. That includes subcontractors who do the same for a business associate.

In practical terms: if you run a clinic and a vendor touches patient data for your practice, you almost certainly need a BAA in place before any PHI changes hands.

Explore AC Health pricing to see how a HIPAA-compliant patient engagement platform handles this for rehab clinics.

Why BAAs Exist

Healthcare organizations outsource constantly. Billing companies process claims. Cloud platforms store records. Messaging tools carry patient communications. IT consultants manage servers full of electronic PHI.

Without a contract, there is no legally binding obligation for those vendors to protect patient data the way HIPAA requires. The BAA fills that gap. It extends HIPAA’s privacy and security duties into the vendor chain by creating enforceable contract terms around PHI use, disclosure, safeguards, and breach reporting.

This is not just paperwork. Business associates face direct liability for certain HIPAA violations, including failure to comply with the Security Rule, breach notification failures, impermissible uses or disclosures of PHI, and failure to enter BAAs with their own subcontractors.

Who Needs a Business Associate Agreement?

The simplest way to decide whether a BAA is needed is a three-part test.

The PHI Flow Test

1. Is there PHI or ePHI?
The information identifies (or could reasonably identify) a person and relates to their health, care, or payment for care.

2. Does a third party create, receive, maintain, transmit, or access it?
This includes storing encrypted files, processing claims, sending messages, hosting databases, logging support tickets, or running analytics on patient data.

3. Is the third party doing that work for your practice or for another business associate?
If the vendor is performing a function on your behalf (not for its own independent purposes), the business associate framework applies.

If all three are true and no exception applies, a BAA should be in place before PHI moves.

Common Examples Where a BAA Is Needed

  • EHR or practice management system
  • Patient engagement or home exercise program app that stores identifiable patient plans, messages, photos, or videos
  • Remote therapeutic monitoring (RTM) platform
  • HIPAA messaging tool for patient questions, photos, and care updates
  • Cloud storage provider (even if it only stores encrypted data and cannot decrypt it)
  • Billing or claims processing company
  • IT consultant or managed service provider with admin access to systems containing ePHI
  • Online fax provider
  • AI scribe or clinical documentation tool
  • Analytics or reporting vendor that receives patient-identifiable data

That cloud encryption point trips people up frequently. HHS has stated explicitly that a cloud service provider qualifies as a business associate even if it stores only encrypted ePHI and lacks the decryption key. Practitioners on Reddit echo this, noting in r/hipaa discussions about cloud backup that sharing PHI with a vendor without signed assurances is not legally permitted, regardless of the vendor’s encryption posture.

If your clinic communicates with patients through digital channels, understanding how PHI can leak through everyday tools matters. Learn more about preventing PHI leaks through SMS.

When a BAA Is Not Required

Not every vendor relationship triggers a BAA. Overcorrecting is common. Knowing the exceptions saves time and prevents unnecessary contract negotiations.

Provider-to-provider treatment disclosures. When a hospital sends records to a specialist for treatment, or a physician sends PHI to a lab for treatment, no BAA is required. HHS gives these as specific examples where the business associate framework does not apply.

Conduit services. USPS, FedEx, UPS, and their electronic equivalents acting solely as transport conduits do not require BAAs.

Software with no PHI access. A vendor that sells downloadable or locally hosted software and never accesses the clinic’s PHI is not a business associate.

De-identified data only. A vendor receiving only properly de-identified data (meeting the Privacy Rule’s de-identification standard) does not need a BAA for that data.

Incidental or no-PHI contractors. A contractor who never accesses, creates, receives, maintains, or transmits PHI is outside the business associate definition.

One Reddit thread in r/hipaa highlighted a common confusion point: clinicians asking whether they need a BAA with the lab down the street. The answer, consistent with HHS guidance, is no, when the lab receives PHI for treatment purposes.

What Must Be in a Business Associate Agreement?

HHS lists the required contract elements that every BAA must include. Think of this as the minimum checklist.

  1. Permitted and required uses/disclosures of PHI. The BAA must define exactly what the vendor can do with PHI.
  2. Prohibition on further disclosure beyond what the contract or law allows.
  3. Safeguards requirement, including Security Rule safeguards for ePHI.
  4. Breach and security incident reporting to the covered entity.
  5. Support for individual rights, including patient access, amendment, and accounting of disclosures as applicable.
  6. Compliance when performing covered entity obligations under the Privacy Rule.
  7. HHS access to books and records for compliance verification.
  8. Return or destruction of PHI at termination, if feasible.
  9. Subcontractor flow-down terms, requiring subcontractors with PHI access to agree to the same restrictions.
  10. Termination rights if the business associate violates a material term.

Business associates must also notify covered entities of breaches of unsecured PHI no later than 60 calendar days after discovery. This timeline should be spelled out clearly in the agreement.

A BAA Does Not Equal HIPAA Compliance

This is the single most important thing to understand about business associate agreements, and the point most articles gloss over.

A signed BAA is a starting line, not a finish line.

HHS does not endorse, certify, or recommend specific technology products as HIPAA compliant. No vendor can truthfully claim that signing a BAA alone makes their product safe for PHI. The BAA is required paperwork. Actual compliance depends on scope, covered services, access controls, encryption, audit logs, breach response processes, subcontractor coverage, staff training, and whether your team is using the tool as it was configured.

Practitioners on LinkedIn have been vocal about this gap. One compliance professional shared that a major legal tech vendor effectively told her that its “HIPAA-ready” marketing and large customer base should be sufficient, without offering a contract-specific BAA for the services actually being used. Sales assurances and generic security language do not substitute for a binding agreement that identifies what services are covered.

A related problem: BAAs that cover only certain plans, tiers, or features. If your team uses a vendor’s free tier or a feature outside the BAA’s scope, the agreement may not protect you. Practitioners on Reddit report that teams frequently enable new AI or product features before updating data-flow documentation, risk reviews, or BAA scope.

For practices evaluating vendors, a structured approach helps. Review our vendor selection checklist for practical criteria beyond the BAA itself.

Red Flags to Watch Before Signing or Relying on a BAA

Not all BAAs are created equal. Some are missing critical elements, and some vendors resist signing one at all. Here are the warning signs.

The vendor refuses to sign a BAA but wants access to PHI. This is the clearest red flag. If a vendor handles PHI and will not provide written assurances, do not put patient data into that tool. LinkedIn practitioners in healthcare compliance warn that some AI vendors refuse BAAs because they did not build compliance into their product architecture and do not want to share liability.

The vendor says “we’re secure” but cannot produce a BAA for the specific service or account. Security and compliance are related but not identical. A vendor can have strong encryption and still lack the contractual obligations HIPAA requires.

The BAA covers only some services, but your team uses non-covered features. Read the scope. A BAA with a platform might cover its HIPAA-eligible tier but not its standard consumer product.

The vendor requires you to warrant that no PHI will be transmitted. If the use case obviously involves PHI (patient messaging, care plans, clinical documentation), this clause is a liability transfer, not a real protection.

Broad rights to de-identify, aggregate, sell, or train AI models on patient data without clear limits. Health-tech legal commentary on LinkedIn flags model training, secondary use, and data retention as increasingly common BAA review points for AI tools.

No subcontractor flow-down language. If the vendor uses sub-processors and the BAA does not require downstream agreements, there is a gap in the PHI chain.

No clear return or destruction process at termination. When the relationship ends, what happens to the data?

Vague safeguard language with no specifics on access controls, encryption, audit logging, or incident response.

What Happens Without a BAA?

Using a cloud service provider to maintain ePHI without first executing a business associate agreement violates HIPAA. That is not ambiguous.

OCR enforcement data through October 2024 shows the agency had received over 374,321 HIPAA complaints, resolved 99% of cases, and settled or imposed civil penalties in 152 cases totaling nearly $145 million.

Real enforcement examples make the stakes concrete:

Raleigh Orthopaedic Clinic settled for $750,000 after allegedly failing to execute a BAA before turning over PHI of 17,300 people to a potential business partner.

Cottage Health agreed to a $3 million settlement after breaches affecting over 62,500 individuals. Among OCR’s findings: failure to obtain a written BAA with a contractor maintaining ePHI.

Care New England settled for $400,000 in a case that highlighted the importance of reviewing and updating existing BAAs over time.

These cases share a pattern. BAA failures rarely appear alone. They tend to surface alongside broader problems: incomplete risk analyses, weak safeguards, and inadequate breach response.

Modern Edge Cases Worth Understanding

AI Tools and Clinical Documentation

AI scribes, note generators, and clinical summarization tools are among the fastest-growing categories in healthcare technology. When these tools access, process, or store PHI for a provider, they are strong BAA candidates.

But the BAA scope matters more than usual here. Health-tech practitioners on LinkedIn emphasize that AI BAAs should address permitted uses, restrictions on secondary use, model training on patient data, data retention policies, subcontractor access, and human support access to PHI. A BAA that covers “the platform” generically may not address what happens to patient data inside the AI pipeline.

Analytics and Tracking Technologies

HHS guidance states that regulated entities using tracking technologies on their websites or apps must evaluate whether those tracking vendors receive PHI. Where the vendor meets the business associate definition, a BAA is required. Privacy policies, cookie banners, and terms of service alone do not create valid HIPAA authorization.

Note: a federal court vacated part of prior HHS guidance regarding IP addresses combined with visits to unauthenticated public webpages. Tracking is a legally active area. If patient portals, appointment pages, or apps send data to analytics or advertising platforms, consult counsel.

Patient Messaging, SMS, and Email

If a tool transmits identifiable patient care information for a provider, it should trigger a BAA review. Personal texting, consumer email, and general messaging apps were not built for PHI. They lack the access controls, audit logging, and contractual protections HIPAA requires.

This is a practical concern for rehab clinics and therapy practices. Providers who need to share exercise videos, progress photos, or treatment updates with patients should use channels designed for that purpose. For more on keeping PHI out of personal messaging, read about avoiding emailing PHI to patients.

BAA Considerations for Therapy and Rehab Practices

The business associate agreement question comes up constantly for physical therapists, occupational therapists, speech-language pathologists, chiropractors, and athletic trainers. Here is why.

A PT clinic that sends home exercise plans, patient videos, progress updates, or in-app messages through a digital platform should treat that platform as part of its PHI workflow. If the platform creates, receives, maintains, or transmits identifiable patient information on the clinic’s behalf, the clinic needs a BAA in place, and the covered services should match how the team actually uses the tool.

Community discussions among healthcare app builders on Reddit list common places PHI can flow in a digital health product: cloud hosting, authentication, database storage, email gateways, SMS, video, analytics, logging, AI APIs, and sub-processors. For a single rehab app, the vendor chain can easily involve five or more downstream services, each potentially requiring its own business associate agreement.

Quick Clinic Tech Stack Audit

Before your next annual HIPAA review, walk through these questions for every tool that touches patient information:

  • Is there a signed BAA with this vendor?
  • Does the BAA cover the specific product, tier, or feature set your team uses?
  • Does the vendor use subcontractors that access PHI? Are those covered by downstream agreements?
  • Has anything changed since the BAA was signed (new features, new integrations, new sub-processors)?
  • Is your team using the tool the way it was configured for HIPAA, or have workarounds crept in?

Private practice owners on LinkedIn advise auditing the full tech stack: EHR, email, texting tools, fax services, and any other platform touching client data. The BAA question is not a one-time checkbox. It is part of ongoing compliance hygiene.

See how AC Health supports PT clinics with HIPAA-private messaging, personalized video care plans, and RTM workflows.

How Often Should BAAs Be Reviewed?

BAAs do not have a fixed expiration date, but they should not be treated as “sign once and forget” documents either.

Review and potentially update a business associate agreement when:

  • The vendor adds or changes services, features, or integrations
  • Your team enables new product features (especially AI, analytics, or messaging capabilities)
  • The vendor changes subcontractors or sub-processors
  • PHI data flows change
  • Regulations change (HHS proposed Security Rule updates in December 2024 that, if finalized, would strengthen cybersecurity requirements for ePHI)
  • The vendor changes which plans or tiers are covered

For clinics, the natural review point is during annual HIPAA risk assessment and whenever adding new patient-facing technology. A Reddit thread on “future product BAAs” highlighted a practical gap: teams often turn on new features before updating their data-flow documentation or confirming the BAA scope still applies.

For practices exploring secure ways to send patient photos and videos, reviewing the vendor’s BAA scope for media handling is an important step.

BAA vs. NDA: Not the Same Thing

A non-disclosure agreement (NDA) protects confidential information in general terms. A BAA is a HIPAA-specific contract with mandated content: permitted uses and disclosures, safeguards, breach reporting timelines, subcontractor flow-down obligations, HHS access rights, and return or destruction duties.

An NDA might prevent a vendor from sharing your business secrets. It does not satisfy HIPAA’s requirements for how PHI must be handled. If a vendor offers an NDA as a substitute for a BAA, that is another red flag.

Legal Disclaimer

This article is for general education and is not legal advice. HIPAA obligations depend on the facts of each relationship, data flow, vendor role, and applicable state and federal law. Work with qualified counsel or a HIPAA compliance professional when drafting, reviewing, or signing business associate agreements.

Frequently Asked Questions

What does BAA stand for in healthcare?

BAA stands for Business Associate Agreement. It is a HIPAA-required contract that defines how a vendor or subcontractor may use, disclose, safeguard, report, return, or destroy PHI handled on behalf of a covered entity or another business associate.

Is a BAA required by HIPAA?

Yes. When a covered entity discloses PHI to a business associate, HIPAA generally requires written satisfactory assurances in the form of a contract. Sharing PHI with a vendor without a BAA in place is a HIPAA violation.

Who signs the BAA?

The covered entity and the business associate both sign it. If a business associate hires a subcontractor that creates, receives, maintains, or transmits PHI, the business associate and subcontractor need a separate downstream BAA.

Does a BAA make a vendor HIPAA compliant?

No. A BAA is required when a vendor handles PHI, but it does not prove that every workflow, feature, configuration, safeguard, or user behavior is compliant. HHS does not endorse or certify any specific technology product as HIPAA compliant.

Do I need a BAA with another healthcare provider?

Usually not when PHI is disclosed to another provider for treatment. HHS gives specific examples: a hospital does not need a BAA with a specialist receiving a patient’s chart for treatment, and a physician does not need one with a lab for treatment disclosures.

Do cloud vendors need BAAs?

Yes, if they create, receive, maintain, or transmit ePHI on behalf of a covered entity or business associate. This remains true even if the cloud provider stores only encrypted ePHI and lacks the decryption key, according to HHS.

Can a BAA be signed electronically?

Yes. HHS states that electronic business associate contracts can satisfy HIPAA requirements if the electronic contract meets applicable state contract law standards.

What is the breach notification deadline for a business associate?

A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery.


Choosing the right tools for patient communication is one of the most consequential compliance decisions a clinic makes. If your practice wants care plans, exercise videos, and provider-to-patient messaging inside a single HIPAA-private channel, schedule a conversation with AC Health.

{ “@context”: “https://schema.org”, “@type”: “FAQPage”, “@id”: “#faq”, “mainEntity”: [ { “@type”: “Question”, “@id”: “#faq-question-1”, “name”: “What does BAA stand for in healthcare?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “BAA stands for Business Associate Agreement. It is a HIPAA-required contract that defines how a vendor or subcontractor may use, disclose, safeguard, report, return, or destroy PHI handled on behalf of a covered entity or another business associate.” } }, { “@type”: “Question”, “@id”: “#faq-question-2”, “name”: “Is a BAA required by HIPAA?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes. When a covered entity discloses PHI to a business associate, HIPAA generally requires written satisfactory assurances in the form of a contract. Sharing PHI with a vendor without a BAA in place is a HIPAA violation.” } }, { “@type”: “Question”, “@id”: “#faq-question-3”, “name”: “Who signs the BAA?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “The covered entity and the business associate both sign it. If a business associate hires a subcontractor that creates, receives, maintains, or transmits PHI, the business associate and subcontractor need a separate downstream BAA.” } }, { “@type”: “Question”, “@id”: “#faq-question-4”, “name”: “Does a BAA make a vendor HIPAA compliant?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “No. A BAA is required when a vendor handles PHI, but it does not prove that every workflow, feature, configuration, safeguard, or user behavior is compliant. HHS does not endorse or certify any specific technology product as HIPAA compliant.” } }, { “@type”: “Question”, “@id”: “#faq-question-5”, “name”: “Do I need a BAA with another healthcare provider?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Usually not when PHI is disclosed to another provider for treatment. HHS gives specific examples: a hospital does not need a BAA with a specialist receiving a patient’s chart for treatment, and a physician does not need one with a lab for treatment disclosures.” } }, { “@type”: “Question”, “@id”: “#faq-question-6”, “name”: “Do cloud vendors need BAAs?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes, if they create, receive, maintain, or transmit ePHI on behalf of a covered entity or business associate. This remains true even if the cloud provider stores only encrypted ePHI and lacks the decryption key, according to HHS.” } }, { “@type”: “Question”, “@id”: “#faq-question-7”, “name”: “Can a BAA be signed electronically?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “Yes. HHS states that electronic business associate contracts can satisfy HIPAA requirements if the electronic contract meets applicable state contract law standards.” } }, { “@type”: “Question”, “@id”: “#faq-question-8”, “name”: “What is the breach notification deadline for a business associate?”, “acceptedAnswer”: { “@type”: “Answer”, “text”: “A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. — Choosing the right tools for patient communication is one of the most consequential compliance decisions a clinic makes. If your practice wants care plans, exercise videos, and provider-to-patient messaging inside a single HIPAA-private channel, [schedule a conversation with AC Health](https://ac-health.com/contact-us/).” } } ] }