HIPAA

What is a Business Associate Agreement (BAA)?

5 min read · Certifyi research team · Updated July 2026

Short answer

A Business Associate Agreement is a contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf. It must be executed before PHI access begins and must flow down to subcontractors.

What a BAA must contain

HIPAA specifies required provisions. A generic vendor agreement with a confidentiality clause is not a BAA.

  • Permitted and required uses and disclosures of PHI
  • A commitment not to use or disclose PHI beyond what is permitted
  • Requirement to implement appropriate safeguards
  • Obligation to report breaches and security incidents
  • Flow-down of the same obligations to subcontractors
  • Return or destruction of PHI at termination
  • Availability of records to the regulator

Who needs one

The test is access to PHI, not the vendor category. If a tool can see PHI, even incidentally, it needs a BAA.

  • Cloud hosting, storage and database providers
  • Email and collaboration platforms
  • Support and ticketing systems
  • Analytics or monitoring tools running on authenticated pages
  • Contractors and consultants with production access

Timing is the compliance point

The BAA must be signed before the vendor touches PHI. Executing one after the fact does not remediate the exposure period, and this is exactly the pattern regulators pursue after a breach.

Where teams get caught

  • A tool trialled on production data before procurement completes
  • A vendor whose free tier does not include a BAA
  • A subcontractor engaged by your vendor with no flow-down
  • Auto-enabled vendor features that begin processing new data

Managing them at scale

Once you pass a handful of vendors, tracking BAAs in email becomes the failure point. Keep a register with vendor, PHI access scope, BAA status, signature date and renewal date, and reconcile it against your actual vendor list at least annually.

Key takeaways

  • A BAA is mandatory before any vendor touches PHI.
  • Confidentiality clauses do not satisfy the requirement.
  • Obligations must flow down to subcontractors.
  • Track BAAs in a register, not an inbox.

Frequently asked questions

Does every vendor need a BAA?

Only those that can access PHI. A design tool with no PHI exposure does not, but be honest about incidental access.

What if a vendor refuses to sign?

Then they cannot process PHI. In practice this means either changing vendor or architecting PHI out of that tool.

Do we need a BAA with our own subcontractors?

Yes. If you are a business associate and you engage subcontractors who touch PHI, the same obligations flow down.

Is a BAA enough on its own?

No. It is a contractual control. You still need the safeguards, risk analysis and monitoring behind it.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead, with transparent, scope-based pricing.

Book a 20-min deal readiness call
Scroll to Top