Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
☰
Compliance and security

What is a business associate agreement (BAA)?

Avatar photo Anja Dodevska
Last Updated: October 6, 2026
Reviewed by: Avatar photo Lucy Galloway

A business associate agreement (BAA) is the contract HIPAA requires between a healthcare provider and any vendor that handles its patients’ protected health information (PHI). The vendor commits to safeguarding that data, reporting breaches, and binding its own subcontractors to the same rules.

The agreement must be signed before any PHI changes hands. The U.S. Department of Health and Human Services (HHS) sets out what it has to contain. Missing BAAs are a recurring finding in enforcement cases brought by the HHS Office for Civil Rights (OCR).

Key takeaways
Found our content helpful?

Key takeaways

A business associate agreement (BAA) is a mandatory HIPAA contract between a covered entity and any vendor that handles protected health information (PHI).

Every tool that touches PHI, including your EHR, billing software, and telehealth platform, needs a signed BAA before you share patient data.

AWS, Google Workspace, Microsoft 365, and Zoom all offer BAAs, but each one has to be accepted or signed before it applies.

Operating without a BAA exposes your practice to OCR penalties that start at $145 per violation and reach $2,190,294 per violation in the top tier.

Pabau’s practice management platform includes a BAA for every US covered-entity customer as part of standard onboarding.

What is a business associate agreement?

A business associate agreement is a written contract between a HIPAA-covered entity and a third-party vendor, known as a business associate. It sets out how that vendor may use, store, and safeguard protected health information. Its required contents are fixed by 45 CFR § 164.504(e), so a general non-disclosure agreement (NDA) can’t stand in for one.

An NDA only restricts sharing. A BAA makes the business associate directly accountable under HIPAA and commits it to four obligations:

  • Implement specific security safeguards for PHI
  • Report breaches within defined timeframes
  • Use PHI only for the purposes the contract allows
  • Extend the same obligations to any subcontractors

Three parties can sit inside this framework: the covered entity (CE), the business associate (BA), and the BA’s own subcontractors. The 2013 HIPAA Omnibus Final Rule treats those subcontractors as downstream business associates.

Who qualifies as a business associate under HIPAA?

A business associate is any person or organization that performs a service for a covered entity involving the use or disclosure of PHI. The function must be performed on behalf of the covered entity, not just alongside it.

Common examples relevant to medical practices and med spas:

  • Medical billing companies and revenue cycle management firms
  • EHR, practice management, and scheduling software vendors
  • Telehealth platforms that transmit patient video or notes
  • Cloud storage providers where patient records are hosted
  • Medical transcription services
  • IT support companies with access to systems containing PHI
  • Accountants or attorneys who access financial records tied to patient data
  • Answering services that handle patient calls

Two groups are commonly misidentified. Workforce members, meaning your own employees and contracted staff under your direct supervision, are not business associates. Neither are conduits, which only transport PHI without accessing it, such as postal carriers or basic internet service providers. The conduit exception is narrow and applies only when the entity has no way to access the information it carries.

After the 2013 Omnibus Final Rule, subcontractors of business associates are themselves directly liable under HIPAA. If your billing company uses a cloud platform to store claim data, that platform is a subcontractor BA. Your billing company must then have its own BAA in place with it.

Put together, those rules come down to three questions you can ask about every vendor on your list.

Decision flow deciding whether a vendor needs a HIPAA business associate agreement.
Only a vendor that could encounter PHI needs a BAA, and one that refuses to sign can’t receive it. Based on HHS business associate guidance.

When is a business associate agreement required?

A business associate agreement is required before a covered entity shares PHI with any third-party vendor performing functions on its behalf. The trigger is the potential for access, not actual access. If a vendor could encounter PHI in the course of performing their service, a BAA is required before any relationship begins.

Many practices underestimate how many vendors qualify. Consider a typical mid-sized med spa in the US. It likely uses separate tools for scheduling, billing, telehealth, email marketing, data analytics, and cloud storage.

Every one of those vendors that could encounter patient data requires a signed BAA. That’s why medical office HIPAA compliance starts with an audit of the full vendor stack, beyond the primary EHR.

The BAA must be executed before PHI is shared. Retroactive BAAs are not a cure for violations that already occurred, though signing one after the fact does help limit ongoing exposure.

What a HIPAA-compliant BAA must include

HHS specifies the mandatory provisions for every BAA at 45 CFR § 164.504(e). A vendor contract labeled a “BAA” that omits these clauses is not HIPAA-compliant, regardless of what the vendor claims.

Required provisions at a glance

Required clause Regulatory source Plain-language summary
Permitted uses and disclosures 45 CFR § 164.504(e)(2)(i) Specifies the exact purposes for which the BA may use or share PHI
Safeguard obligations 45 CFR § 164.504(e)(2)(ii)(B) BA must implement administrative, physical, and technical safeguards to protect electronic PHI (ePHI)
Breach notification 45 CFR § 164.410 BA must notify the CE of a breach within 60 days of discovery
Subcontractor BAAs 45 CFR § 164.504(e)(2)(ii)(D) BA must obtain a BAA from any subcontractor that handles PHI on its behalf
Access and amendment rights 45 CFR § 164.504(e)(2)(ii)(E-F) BA must make PHI available for access, amendment, and accounting of disclosures
Return or destruction of PHI 45 CFR § 164.504(e)(2)(ii)(J) At termination, BA must return or destroy all PHI and certify destruction
Termination for breach 45 CFR § 164.504(e)(2)(iii) CE may terminate the agreement if the BA materially breaches BAA obligations

The safeguard clause in the table refers to the HIPAA Security Rule safeguards, which come in three kinds: administrative, physical, and technical. In practice, the BA must run documented policies, access controls, encryption, audit logs, and workforce training that protect ePHI. A placeholder such as “adequate safeguards will be maintained” gives a covered entity very little legal protection if a breach occurs.

Pro Tip

Review any vendor BAA against the table above before signing. If the safeguard obligations clause does not reference administrative, physical, and technical controls specifically, ask the vendor to revise it. A BAA that omits any of the seven clauses listed is non-compliant regardless of what the vendor calls it.

Cloud software vendors and your BAA obligations

Cloud tools are where unsigned BAAs tend to pile up. Scheduling software, patient communication platforms, telehealth tools, and even general productivity suites like email can all touch PHI.

Four of the most widely used vendors each offer a BAA, but none of them applies automatically:

  • AWS: Amazon’s Business Associate Addendum is available to eligible AWS customers. It must be actively accepted through the AWS Management Console. Practices building on AWS infrastructure (or using tools hosted there) must confirm the BAA is in place.
  • Google Workspace: Google offers a HIPAA Business Associate Amendment on paid Workspace plans, and free consumer Gmail isn’t covered. It applies only to the Google services designated as HIPAA-covered, such as Gmail, Calendar, Drive, and Docs. An admin accepts it in the Google Admin Console under Account settings → Legal and Compliance.
  • Microsoft 365 and Azure: Microsoft makes a BAA available through its Products and Services Data Protection Addendum. Healthcare customers must specifically enable HIPAA-covered features and sign the addendum rather than relying on the standard service agreement.
  • Zoom: Zoom offers a HIPAA BAA for eligible healthcare plans. The standard Zoom free or basic plan does not carry a BAA. Practices using Zoom for telehealth must verify their plan includes BAA coverage and that the agreement is signed.

Verify BAA terms directly with each vendor before using any tool for patient-related work. Covered services and plan requirements change, so a vendor’s terms may have moved on since this article was written.

Does your practice management software have a BAA?

Practice management software is where many practices discover a missing BAA. Some smaller or newer platforms don’t offer one at all. Storing or processing PHI in one of them is a HIPAA violation, however good the software is otherwise. When you compare HIPAA compliance software, ask these questions before signing a contract:

  • Do you provide a BAA as part of standard onboarding for healthcare customers?
  • Which specific services and data types are covered under the BAA?
  • What breach notification process does your BAA establish, and what is the guaranteed notification timeline?
  • Do you require BAAs from your own subcontractors and hosting providers?
  • What happens to patient data if we terminate our subscription?

Before committing to any platform, confirm the BAA is available, review its provisions against the table above, and retain a signed copy.

Penalties for operating without a BAA

OCR enforces HIPAA BAA requirements through a tiered civil monetary penalty structure. The tiers reflect culpability, not just the size of the breach. The figures below took effect on January 28, 2026, after OCR’s latest inflation adjustment. Amounts change over time, so check current figures at hhs.gov/hipaa/for-professionals/compliance-enforcement.

Violation tier What it means Penalty range (per violation)
Unknowing The CE did not know, and could not have known, of the violation $145 to $73,011 per violation
Reasonable cause The CE should have known but did not act out of willful neglect $1,461 to $73,011 per violation
Willful neglect, corrected The CE knew and failed to act, but corrected the violation $14,602 to $73,011 per violation
Willful neglect, not corrected The CE knew, failed to act, and did not correct the issue $73,011 to $2,190,294 per violation

A missing BAA with a single vendor across a year of operations can constitute hundreds of individual violations, one per patient record or transaction. OCR also considers whether the missing BAA led to a breach. If it did, handling a HIPAA violation correctly becomes critical to limiting further exposure. Criminal penalties under 42 U.S.C. § 1320d-6 can apply when violations involve intentional misuse of PHI.

How to execute a business associate agreement

Executing a business associate agreement is straightforward, but it takes deliberate action. Many BAA failures start with an assumption: the practice believed a BAA was already in place when it wasn’t.

  1. Audit your vendor stack. List every tool, contractor, and service provider that could encounter PHI. Include billing companies, scheduling software, cloud storage, telehealth platforms, IT support, and email. A small practice typically has five to 15 vendors that qualify.
  2. Request or review the vendor’s BAA. Large vendors (AWS, Google, Microsoft) offer standardized addenda. Smaller vendors may provide a custom BAA or ask you to use your own template. HHS publishes model BAA provisions at hhs.gov/hipaa that can serve as a starting point.
  3. Verify the required provisions. Use the table in the section above. Confirm all seven required clauses are present. Flag any missing provisions and request amendments before signing.
  4. Execute and retain signed copies. Both parties must sign. Store a copy in your compliance files. HIPAA requires you to keep each BAA for at least six years (45 CFR § 164.530(j)). The clock runs from the date it was created or last in effect, whichever is later.
  5. Know what to do if a vendor refuses. If a vendor declines to sign a BAA, you cannot legally use their service for any function that involves PHI. You have two options: find an alternative vendor that will sign, or restructure the service so PHI is never shared with that vendor. Do not accept verbal assurances or informal data protection promises in place of a signed BAA.

BAA template: Key clauses to include

If you are issuing your own BAA to a subcontractor or smaller vendor, confirm the document includes these elements before presenting it for signature:

  • A clear description of services the BA will perform and the PHI involved
  • Explicit permitted and prohibited uses of PHI
  • Obligation to implement administrative, physical, and technical safeguards (reference the HIPAA Security Rule)
  • 60-day breach notification requirement with reporting process
  • Subcontractor BAA requirement (the BA must flow down obligations)
  • CE’s right to audit or inspect BA’s compliance practices
  • PHI return or certified destruction upon termination
  • Termination-for-cause provision if the BA materially breaches the agreement

The HHS model BAA provisions available at hhs.gov/hipaa are the authoritative starting point. Use them as the base and add organization-specific terms rather than drafting from scratch. This is not legal advice. Practices should have any BAA reviewed by healthcare counsel before execution.

Managing your BAA portfolio over time

A signed BAA still needs upkeep. Covered entities stay responsible for their BA relationships for as long as PHI flows. Vendor lists also tend to grow faster than the paperwork behind them.

A simple BAA tracker keeps that paperwork current. Record each vendor, the date the BAA was signed, the services covered, and the next scheduled review date. Annual review is a reasonable cadence for most practices. Compliance management software can hold the same record alongside your policies and audit logs, so reviews don’t depend on one person’s spreadsheet.

Four events trigger a BAA update regardless of the scheduled review cycle:

  • New services: If a vendor expands the scope of what they do with your PHI, the original BAA may not cover the new activity. Request an amendment or updated agreement.
  • Vendor acquisition or ownership change: When a vendor is acquired, the acquiring company may not automatically inherit BAA obligations. Request confirmation in writing and a new agreement if necessary.
  • Breach involving the vendor: A breach does not automatically terminate a BAA, but it does require reassessment. Review the vendor’s remediation plan against the BAA’s safeguard obligations.
  • Regulatory changes: HHS periodically updates HIPAA guidance. Any regulatory change that affects BAA requirements means existing agreements may need to be revisited.

Keep every BAA for at least six years from its creation date or the date it last applied, whichever is later. That means BAAs for vendors you no longer use must still be retained. Store them somewhere that is itself HIPAA-compliant, such as a secure document store inside your practice software.

Pro Tip

Build a BAA expiry calendar by adding each vendor’s BAA to your practice calendar with an annual review reminder. When a vendor sends a contract renewal, make it a trigger to check whether the BAA also needs updating. A five-minute annual review per vendor is far cheaper than an OCR investigation.

How Pabau keeps your BAA list short

Many practices build their stack one tool at a time: a booking app, an e-signature tool for forms, a separate EHR, a billing service. Each one handles PHI, so each one needs its own BAA, its own review date, and its own signed copy on file.

Pabau brings scheduling, digital forms, patient records, and billing into one platform. Every US covered-entity customer gets a BAA as part of standard onboarding, covering the patient data held across the system.

Fewer vendors means fewer agreements to chase, track, and renew, and fewer places where PHI can leak. You can read how Pabau approaches data protection on its HIPAA compliance page.

Digital forms
Pabau’s digital forms save signed intake and consent forms straight to the patient record, so PHI stays with a vendor already covered by your BAA.

Pabau includes a BAA as standard

US practices using Pabau get a HIPAA Business Associate Agreement as part of onboarding. See how Pabau handles patient data, consent forms, and clinical records in a HIPAA-compliant environment.

Pabau HIPAA-compliant clinic management platform

Conclusion

If you act on one part of this guide, make it the vendor audit. List every tool and contractor that could see patient data, then match each one to a signed BAA. A vendor without one either signs or stops receiving PHI.

The audit itself takes an afternoon. The ongoing cost is upkeep, because every new tool, acquisition, or change of scope reopens the list. Running fewer vendors keeps that upkeep small.

Book a demo to see how one Pabau BAA covers your scheduling, forms, and patient records.

Continue your research

Continue your research

Ready to check your own safeguards? HIPAA risk assessment walks through the risk analysis the Security Rule expects from every covered entity.

Worried about what a missing BAA could cost? HIPAA violation penalties breaks down each penalty tier and how to avoid them.

Emailing patients from Google Workspace or Microsoft 365? HIPAA compliant email covers the encryption requirements and the BAA your email provider must sign.

Concerned about social media and patient privacy? HIPAA and social media covers what practices can and cannot post about patient interactions.

Frequently asked questions

What is the purpose of a business associate agreement (BAA)?

A business associate agreement binds any vendor that handles protected health information for a covered entity to HIPAA’s rules. The vendor must implement safeguards, report breaches within 60 days, limit PHI to agreed uses, and return or destroy data when the relationship ends. Unlike a general confidentiality agreement, a BAA is mandated by HIPAA, and operating without one is a federal compliance violation.

When is a BAA required under HIPAA?

A BAA is required whenever a covered entity shares PHI with a third-party vendor that performs a service on its behalf. That includes billing companies, EHR vendors, telehealth platforms, cloud storage providers, and IT support firms. The agreement must be in place before any PHI is shared, not after the relationship has already started.

Which cloud vendors (AWS, Google, Microsoft, Zoom) offer BAAs?

All four offer BAAs, but none applies automatically. AWS customers must accept the Business Associate Addendum through the AWS Management Console. Google Workspace admins accept the HIPAA Business Associate Amendment in the Google Admin Console, under Account settings → Legal and Compliance. It is available on paid Workspace plans, and free consumer Gmail isn’t covered. Microsoft makes a BAA available through its Data Protection Addendum. Zoom offers a BAA for eligible healthcare plans, not for free or basic accounts. Verify current terms directly with each vendor before using any service for PHI.

What are the penalties for not having a BAA in place?

OCR’s civil penalties start at $145 per violation for unknowing violations and reach $2,190,294 per violation for uncorrected willful neglect. Those amounts took effect on January 28, 2026. Because each patient record or transaction can constitute a separate violation, total penalties can reach millions of dollars. Criminal charges are also possible when PHI is intentionally misused. Current penalty figures are published at hhs.gov/hipaa/for-professionals/compliance-enforcement.

Can a subcontractor be a business associate?

Yes. Since the 2013 HIPAA Omnibus Final Rule, subcontractors of business associates are themselves directly liable under HIPAA. A business associate must obtain a signed BAA from any subcontractor that handles PHI on its behalf. That subcontractor then carries the same obligations as the primary BA.

How long should a BAA be retained?

HIPAA requires you to keep each BAA for at least six years (45 CFR § 164.530(j)). The clock runs from the date it was created or last in effect, whichever is later. This applies even to BAAs for vendors you no longer use. Store them in a HIPAA-compliant location.

Found our content helpful?
×