HIPAA Basics

What a Business Associate Agreement Must Contain

A HIPAA business associate agreement (BAA) is a written contract that must, at minimum, define what the business associate may do with protected health information (PHI), require appropriate safeguards, require reporting of unauthorized uses and disclosures including breaches, flow the same obligations down to subcontractors, support the individual rights the Privacy Rule grants patients, make the business associate's records available to HHS, address return or destruction of PHI at termination, and let the covered entity terminate for a material breach. Those requirements come from 45 CFR 164.504(e), with additional contract requirements for electronic PHI at 45 CFR 164.314(a). A BAA that omits any of them is not a compliant BAA.

The short answer

The Office for Civil Rights (OCR) publishes sample business associate agreement provisions and a plain summary of what such a contract must do. That summary is the most reliable checklist available, because it is written by the agency that enforces the rule. The list below tracks it directly.

A BAA is a floor, not a ceiling. OCR's sample provisions are explicitly optional language, and they note that the sample alone may not be enough to form a binding contract under state law. Treat the regulatory elements as the minimum and negotiate the commercial terms on top.

When a BAA is required

You need a BAA when a person or entity outside your workforce creates, receives, maintains, or transmits PHI in order to perform a function or activity on your behalf, or to provide certain services to you — a billing company, a cloud host that stores PHI, a shredding vendor, an IT contractor who can reach systems holding PHI, a claims clearinghouse.

The chain does not stop at the first vendor. A subcontractor that handles PHI on behalf of a business associate is itself a business associate, and the business associate must have a written agreement with it carrying the same restrictions and conditions. Ask your vendors how they paper their own supply chain, not merely whether they signed your BAA.

The required elements, one by one

A written contract between a covered entity and a business associate must:

  1. Establish permitted and required uses and disclosures. The contract cannot authorize uses or disclosures that would violate the Privacy Rule if the covered entity did them, with narrow exceptions for the business associate's own proper management and administration and for data aggregation services.
  2. Prohibit other uses and disclosures. The business associate will not use or further disclose the information other than as permitted or required by the contract, or as required by law.
  3. Require appropriate safeguards. Including, for electronic PHI, complying with the Security Rule.
  4. Require reporting. The business associate must report any use or disclosure not provided for by the contract of which it becomes aware, including breaches of unsecured PHI.
  5. Flow obligations down to subcontractors. Any subcontractor handling PHI on the business associate's behalf must agree to the same restrictions and conditions.
  6. Support individual access. Make PHI available so the covered entity can meet its obligations when individuals request copies of their information.
  7. Support amendment and accounting. Make PHI available for amendment, incorporate amendments, and make available the information needed for an accounting of disclosures.
  8. Carry the covered entity's obligations where delegated. If the business associate performs an obligation of the covered entity under the Privacy Rule, it must comply with the requirements that apply to that obligation.
  9. Make records available to HHS. The business associate must make its internal practices, books, and records relating to PHI available to the Secretary for compliance determinations.
  10. Address termination. Return or destroy all PHI at termination if feasible, retaining no copies; if that is not feasible, extend the contract's protections to the retained information and limit further uses. The contract must also authorize the covered entity to terminate if the business associate violates a material term.

Contracts between a business associate and its subcontractors are subject to these same requirements.

What a BAA may not do

The contract may notBecause
Permit a use or disclosure the covered entity could not make itselfLimited exceptions exist for the business associate's own management and administration, its legal responsibilities, and data aggregation
Waive the reporting obligation for unauthorized uses or disclosuresReporting, including breaches of unsecured PHI, is a required element
Let subcontractors operate on looser termsDownstream agreements must carry the same restrictions and conditions
Substitute a vendor's HIPAA-compliant marketing claim for a signed agreementOnly a written contract or other permitted arrangement satisfies the rule

When a BAA is not required

  • Disclosures to a provider for treatment. Sending records to a specialist so they can treat your patient does not make that specialist your business associate.
  • Your own workforce. Employees are covered by your policies and training, not by a BAA.
  • Entities that are merely conduits. OCR describes a narrow conduit exception for entities that transport information without routine access to it. A vendor that stores PHI is generally not a conduit, even if it says it never looks at the data.
  • Certain government arrangements. Where both parties are governmental entities, a memorandum of understanding accomplishing the same objectives can satisfy the requirement.

The Security Rule layer

For electronic PHI, 45 CFR 164.314(a) adds contract requirements tied to the Security Rule: the business associate must comply with the applicable Security Rule requirements, ensure subcontractors do the same, and report security incidents, including breaches of unsecured PHI, to the covered entity. The regulation does not set a specific deadline for business-associate-to-covered-entity reporting, so the timeframe is a negotiated term — and silence here is a common source of pain after an incident. A well-drafted BAA defines what counts as a reportable security incident and how fast it must be reported.

Business associates are directly liable

Business associates are directly liable under the HIPAA Rules for certain obligations, including uses and disclosures not authorized by their contract or required by law, and failing to safeguard electronic PHI in accordance with the Security Rule. Nor does signing a BAA transfer away the covered entity's own risk: a covered entity is out of compliance if it knew of a pattern of activity or practice by the business associate that materially breached the agreement and failed to take reasonable steps to cure it, and, if unsuccessful, to terminate the contract where feasible.

What the proposed Security Rule updates could change

HHS has issued a Notice of Proposed Rulemaking (NPRM) to modify the HIPAA Security Rule. These changes are proposed, not final. They are not in effect, and the final outcome is not settled — HHS may adopt them, modify them, or decline to finalize them.

Among other things, the proposal would strengthen the contract-related expectations placed on business associates. The concepts under discussion include periodic written verification by business associates that required technical safeguards are actually deployed, and prompt notification to covered entities when a contingency plan is activated. Read the NPRM itself rather than secondhand summaries. Know what is proposed, watch for a final rule, and make sure your existing BAAs satisfy the requirements that are in force.

House position: The 2026-era Security Rule updates are a proposed rule. Any vendor, consultant, or article telling you that new Security Rule requirements are already mandatory is describing a rule that has not been finalized.

Common mistakes

  • No inventory. Many organizations cannot produce a current list of which vendors touch PHI and which have signed BAAs. Build the list first; the contracts follow.
  • A BAA in the file, but no diligence. A signature does not tell you whether the vendor encrypts data, restricts access, or has ever conducted a risk analysis.
  • Ignoring the subcontractor chain. Ask which downstream providers hold your PHI and confirm agreements exist.
  • Undefined incident timelines. Negotiate a concrete reporting deadline and a named contact before you need them.
  • No exit plan. Decide in advance whether PHI will be returned or destroyed at termination, and how destruction will be evidenced.

The bottom line

A compliant business associate agreement is not a formality. It defines the vendor's permitted uses, obliges safeguards and reporting, extends the same duties to subcontractors, preserves patient rights, keeps the door open for HHS, and gives you a way out. Start from the required elements at 45 CFR 164.504(e) and OCR's sample provisions, then negotiate the practical terms — incident timelines, security evidence, and data return — that the regulation leaves to the parties.

Common questions

Is a business associate agreement required by law?

Yes. The HIPAA Rules generally require covered entities and business associates to obtain satisfactory assurances through a written contract or other permitted arrangement before disclosing PHI to a business associate. The contract requirements are at 45 CFR 164.504(e).

Does a BAA need to be a separate document?

No. OCR notes that the required provisions may be incorporated into a services agreement or set out in a standalone business associate agreement. What matters is that the required elements are present in a binding contract.

Do I need a BAA with another doctor I refer patients to?

Generally no. Disclosures from one health care provider to another for the treatment of an individual do not make the receiving provider a business associate.

Do the proposed 2026 Security Rule changes mean I must update my BAAs now?

No. Those changes are proposed, not final, and are not in effect. Track the NPRM, but base your current agreements on the requirements that are in force today.