Office Consumer is reader-supported. We may earn an affiliate commission from qualified links on our site.

What Must Be Included in a Business Associate Agreement? (w/Examples) + FAQs

A compliant business associate agreement must include ten specific provisions that federal law requires: permitted uses of protected health information (PHI), required safeguards, breach-reporting duties, subcontractor flow-down, and termination rights. Missing even one clause can trigger penalties up to $1,919,173 per violation, the exposure an incomplete BAA creates for both sides of the contract.

This matters right away for covered entities, business associates, and their subcontractors, because HHS treats a missing or incomplete BAA as its own violation, separate from any data breach that follows it. This guide walks through every required clause as of 2026, shows what OCR settlements have cost noncompliant groups, and flags the drafting mistakes that turn a routine vendor deal into a costly liability.

📄 What HIPAA's ten required BAA provisions say, in plain language

⚖️ Which situation fits you: covered entity, business associate, or subcontractor

🚫 What business associates are never allowed to do with PHI

💰 What OCR settlements have cost groups without a compliant BAA

✅ The mistakes, do's, and don'ts that keep a BAA enforceable

This article reflects federal HIPAA rules and OCR guidance as of 2026. Penalty amounts and enforcement priorities shift over time, so confirm current figures before you rely on them for a live contract. It offers general education, not legal advice. It does not replace a review from a healthcare attorney or a compliance officer who knows your specific vendors.

What a Business Associate Agreement Must Include

HIPAA does not leave the content of a BAA to guesswork. The Privacy Rule at 45 CFR 164.504(e) lists the exact provisions every BAA must contain. This holds true whether the parties are a hospital and a billing vendor, or a business associate and its own subcontractor. HHS even publishes sample provisions for each one, though using that exact wording is optional.

  1. Permitted and required uses. The BAA must spell out how the business associate may use or share PHI, tied to the real service it performs.
  2. No unauthorized further use. The business associate cannot use or share PHI beyond what the contract or law allows, even when a use feels harmless.
  3. Required safeguards. The business associate must use safeguards that block unauthorized use or disclosure, including the technical and physical controls the Security Rule demands for electronic PHI.
  4. Breach and incident reporting. The business associate must tell the covered entity about any use or disclosure outside the contract's terms, including breaches of unsecured PHI.
  5. Individual rights support. The business associate must help the covered entity answer a patient's request for records, a correction, or a list of disclosures.
  6. Privacy Rule delegation. If the business associate carries out part of the covered entity's Privacy Rule duties, it must follow the same rules that bind the covered entity.
  7. HHS access for review. The business associate must open its internal records to HHS so investigators can check the covered entity's compliance.
  8. Return or destroy PHI at the end. When the contract ends, the business associate must return or destroy all PHI it holds, if that step is feasible.
  9. Subcontractor flow-down. Any subcontractor that touches PHI on the business associate's behalf must agree, in writing, to the same limits.
  10. Termination for cause. The covered entity must be able to end the contract if the business associate breaks a major term.

These ten items are the floor, not the ceiling, of what a BAA can say. A contract can add extra protection, like insurance rules or indemnity, but it cannot remove or soften any of the ten. A BAA that skips even one, such as the subcontractor flow-down clause, is not a valid BAA under HIPAA. That holds no matter what the parties call it.

Which Situation Fits You

The right BAA checklist depends on where a group sits in the chain. HIPAA names several distinct roles. Each one carries a different set of duties and a different amount of leverage. Find your role below before you sign anything.

If You're the Covered Entity

As the covered entity, you carry final responsibility for every later use of patient data, even after PHI leaves your own systems. A BAA must be signed before any vendor creates, receives, keeps, or sends PHI on your behalf. Sign it before the work starts, not after. If a vendor resists HHS's required terms, treat that resistance as a warning sign worth raising before you grant any data access.

Your leverage peaks before the underlying service contract gets signed. Use the BAA talks to push for short breach-notice windows and clear insurance rules. Once a services deal is signed without an attached BAA, business associates have far less reason to accept strict terms later. Build BAA review into buying decisions, not into IT setup after the tools are already live.

If You're the Business Associate

As the business associate, you might be a billing firm, an IT vendor, a consultant, or a cloud host. Whichever role fits, you take on direct legal risk under HIPAA, not only contract risk tied to the covered entity. OCR can fine a business associate directly for a bad disclosure or a missing risk check, apart from any penalty against the covered entity. Read the permitted-use section closely, since a BAA without your own management-and-administration use can make it hard to run your business without breaking the contract.

Push for reporting deadlines you can meet. A BAA that demands notice within 24 hours may clash with how your incident response works. Ask whether the covered entity expects direct patient notice, since that duty often shifts quietly onto business associates. Confirm the deal allows subcontractors, and make sure their BAA mirrors the same limits the main agreement carries.

If You're a Subcontractor to a Business Associate

Subcontractors face the same direct legal risk as the business associate above them in the chain. This has been true since the HITECH Act folded them into HIPAA's Omnibus Rule. A cloud storage firm, transcription service, or records-destruction company that touches PHI needs its own BAA with the business associate, not a general vendor contract. Skipping this step because the client is a business associate, not a hospital, is a common myth that does not lower your risk at all.

Whatever limits bind the business associate above a subcontractor must also bind it, word for word, under the flow-down rule. Review the primary BAA between the business associate and the covered entity whenever you can. Doing so keeps the duties flowing down clear before you sign. Ask for a copy in writing rather than a summary, since summaries can quietly drop a clause.

If You're Evaluating a SaaS or Cloud Vendor

Software-as-a-service and cloud hosting sit in a group people often get wrong. If a vendor's platform stores, handles, or sends PHI, even encrypted data the vendor's own staff never view, that vendor counts as a business associate. It needs a BAA signed before any real patient record goes into the system. Several large cloud firms offer a standard BAA as an add-on, and skipping it while storing PHI anyway builds a gap fast.

Check whether your actual plan tier even includes BAA coverage, since some entry-level or free tiers leave it out entirely. Confirm which specific features inside the platform the BAA covers. A vendor may offer a BAA for core storage while leaving newer AI or analytics add-ons outside it. Ask for the vendor's current BAA on request, since a trust page is not the same as an executed agreement.

What Business Associates Are Not Permitted to Do

A signed BAA does not hand a business associate free use of PHI. It does the opposite: the contract narrows what the business associate may do with that data. Any use outside those specific terms counts as a HIPAA violation. That holds true even when no complaint or breach ever follows it.

  • Use or share PHI for anything outside the BAA's stated permitted uses, including marketing unrelated products.
  • Sell PHI, or use it for the business associate's own gain, outside the data-aggregation or management exceptions the BAA allows.
  • Share PHI with a subcontractor that has not signed its own compliant agreement.
  • Ignore the Security Rule's risk-check and safeguard duties for any electronic PHI it touches.
  • Hold back notice to the covered entity after finding a breach or a security incident.
  • Keep PHI for good after the contract ends, when return or destruction is feasible.
  • Treat de-identified data as still covered once it truly meets HIPAA's Safe Harbor or expert-review standard, since that step removes it from the PHI definition entirely.
  • Charge the covered entity extra fees for basic compliance work the BAA already requires, such as breach-notice support.
  • Change the agreement's permitted-use section on its own, after signing, without the covered entity's written okay.

A common myth holds that any use tied to patient care is always fine. The minimum necessary standard still applies. A business associate must limit PHI access to what a task truly needs, not what is merely easy to grab. When unsure whether a use fits inside the BAA, the safer move is asking the covered entity first, not assuming.

Worked Example: What Ten Real BAA Failures Cost

Numbers make the stakes clear. HIPAA Journal tracked ten OCR settlements between 2016 and 2024. In each one, a missing or noncompliant BAA was the sole reason for the fine, or a major factor in its size. Averaging those ten cases shows what a BAA failure costs in practice, not only what the top penalty tier allows.

YearCovered EntityOCR Penalty
2024Providence Medical Institute$240,000
2020Athens Orthopedic Clinic$1,500,000
2019Sentara Hospitals$2,175,000
2018Pagosa Springs Medical Center$111,400
2018Advanced Care Hospitalists$500,000
2017Center for Children's Digestive Health$31,000
2016Care New England Health System$400,000
2016Oregon Health & Science University$2,700,000
2016Raleigh Orthopaedic Clinic$750,000
2016North Memorial Health Care$1,550,000
OCR settlements where a missing or noncompliant BAA was a factor, 2016–2024 (source: HIPAA Journal enforcement tracking).
OCR settlements where a missing or noncompliant BAA was a factor, 2016–2024 (source: HIPAA Journal enforcement tracking).

Add the ten penalties in the table and the total comes to $9,957,400. Divide that by ten cases and the average lands at $995,740, close to a million dollars per group that let a BAA slip. Even the smallest fine on the list is a $31,000 penalty against a small digestive-health practice. That amount alone tops what many small practices set aside for compliance in a typical year.

These totals sit inside a wider penalty structure set by federal rule. A 2023 review by a healthcare law firm found that HIPAA's civil penalties for a BAA violation range from $127 to $1,919,173 per violation. The amount depends on whether the conduct was unknowing, tied to reasonable cause, or the result of willful neglect left uncorrected.

HHS raises these tiers most years for inflation. By 2024, the per-violation floor had already risen to $141, with a $2,134,831 yearly cap for repeat violations of one identical rule. Confirm the current figures with OCR before estimating exposure for a specific case.

Compare that average settlement to what prevention costs. A custom counsel-drafted BAA, covered later in this guide, typically runs a few hundred to a few thousand dollars to negotiate from scratch. Weighed against a $995,740 average settlement, that legal bill is the real return on one afternoon of careful contract review.

Lessons From BAA Enforcement Actions

Behind every settlement number sits a specific failure any group could repeat. Three of the cases below come from OCR's public record. One is an illustrative scenario built from patterns compliance lawyers describe often. Each one teaches a different lesson about how a BAA problem begins.

Lesson One: No Agreement at All

In 2017, OCR closed its case against the Center for Children's Digestive Health with a $31,000 settlement, the smallest amount among these BAA-related actions. The practice had shared PHI with a business associate without ever signing a written agreement. That is the most basic failure the rule addresses. Size did not shield the practice from risk, and it will not shield any small clinic that repeats the mistake today.

What OCR FoundResult
PHI shared with no signed BAA in place$31,000 settlement plus a corrective action plan

The lesson here is not the dollar amount. It is timing. A BAA has to exist before PHI starts moving, not after a vendor deal has already run for months without one. A single unsigned page can undo months of otherwise careful HIPAA compliance work elsewhere in the practice.

Lesson Two: An Agreement Missing Required Terms

Having a signed BAA is not always enough on its own. A 2023 review by a healthcare law firm noted that OCR handed down a $400,000 settlement against a health system. The penalty was tied in part to the covered entity's failure to include required terms in its own BAA. The group had a contract, but it left out language HIPAA requires every agreement to carry.

The BAA IncludedThe BAA Was Missing
A description of services and general confidentiality languageBreach-reporting duties and the subcontractor flow-down clause

This is the mistake a well-built template guards against. It is also the mistake a rushed, attorney-free deal invites. Checking a proposed BAA against HHS's ten required elements, one by one, catches the gap before signature. That check is far cheaper than catching it after an OCR probe finds it.

Lesson Three: Scale Does Not Reduce Exposure

Not every BAA failure involves a small practice. Oregon Health & Science University, a large academic medical center, faced a $2,700,000 settlement in 2016. That is the largest amount among the ten cases HIPAA Journal tracked. Bigger legal teams and more staff do not always mean tighter BAA management, especially across dozens of departments and vendor deals.

The myth here is that compliance gets easier as a group grows larger, as if more staff closes every gap on its own. In practice, a bigger footprint means more contracts to track and more subcontractors to watch. It also means more chances for one department to skip a check that another department runs correctly. A large budget buys more tools, but it does not buy attention to every vendor file by itself.

Lesson Four: The Subcontractor Nobody Flowed Down

Consider a solo dermatology practice, call it Dr. Renner's clinic, that hires a scheduling platform to text appointment reminders. The platform signs a BAA directly with the practice. But it quietly routes text delivery through a separate messaging subcontractor that never signs anything. That firm now handles PHI, appointment times tied to patient names, with zero contractual duty to protect it.

Provision HIPAA RequiresPresent in This Chain?
BAA between practice and scheduling platformYes
BAA between scheduling platform and its messaging subcontractorNo

This gap stays common because it stays invisible from the covered entity's side, since the practice's own BAA looks complete on paper. Ask every vendor directly whether it uses subcontractors that touch PHI. Demand proof of a flow-down BAA before you renew the contract next year. A short written questionnaire at renewal time catches this gap far cheaper than an OCR inquiry does.

Beyond the Minimum: Provisions Worth Adding

HIPAA's ten provisions set the legal floor. HHS's own model agreement includes extra language many groups choose to add. These optional terms do not appear in the statute, but they shift risk in ways both sides should understand before signing. Skipping that talk because the required provisions are checked off leaves real protection sitting on the table.

Additional TermWho It Protects
Independent-contractor clauseCovered entity, by limiting blame for the business associate's own misconduct
Insurance requirement for HIPAA violationsCovered entity, by making sure funds exist if a claim arises
Indemnification for breach costsCovered entity, by shifting cleanup costs to the party that caused the breach
Reasonable, negotiated reporting deadlineBusiness associate, by avoiding a same-day notice rule it cannot meet
Confirmation the entity is truly a business associateBusiness associate, by voiding the BAA if the deal never involved PHI

Covered entities tend to push for indemnity and insurance rules, while business associates tend to push back on tight reporting deadlines and liability caps. Neither side is wrong to negotiate, since HIPAA stays silent on these points precisely because they are business terms, not compliance rules. Read the underlying service agreement alongside the BAA. A clash between the two documents can undercut the protection either one is meant to provide.

Federal HIPAA sets the floor, but state law can add duties a BAA should reflect too. California's Confidentiality of Medical Information Act and similar laws can set stricter breach-notice rules than HIPAA alone requires. If a group works in a state with its own health-privacy law, ask counsel whether the BAA needs a state-law addendum. Do not lean on the federal template alone.

Procurement teams often negotiate the master service deal and the BAA on separate tracks. That split often causes them to miss this overlap. Loop a privacy or compliance lead into vendor talks from the start, not after legal has already marked up the service terms. That single change in process closes more gaps than any single clause added to the BAA itself.

Template BAA versus a custom counsel-drafted BAA across cost, speed, and liability coverage.
Template BAA versus a custom counsel-drafted BAA across cost, speed, and liability coverage.

Mistakes to Avoid

  • Signing a vendor contract before the BAA is signed. PHI that flows during that gap is an unauthorized disclosure the moment it happens, no matter how fast the BAA follows.
  • Reusing a pre-2013 form agreement. An older template misses the HITECH Act's subcontractor flow-down rule and the current breach-notice definition, so it fails a fresh review right away.
  • Treating a signed BAA as the finish line. A contract missing even one of the ten required provisions is not a valid BAA, and OCR has fined groups for exactly that gap.
  • Skipping subcontractor flow-down. A vendor's own subcontractor without a matching BAA creates a compliance hole hidden from the covered entity's side until a breach exposes it.
  • Accepting an unworkable reporting deadline. A same-day notice clause a business associate cannot meet turns a routine incident into a breach of the BAA itself, on top of any HIPAA exposure.
  • Leaving the permitted-use section too narrow. Leaving out the business associate's own management-and-administration use can make it hard for the vendor to run its business without breaking the contract.
  • Assuming de-identified data stays exempt without checking the method. PHI only loses its protected status under HIPAA's Safe Harbor or expert-review standard, and a shortcut method can leave the data covered after all.
  • Never revisiting a BAA after the first signature. Rules and vendor relationships change, and a BAA that fit a deal three years ago may no longer match how the vendor handles data today.
  • Assuming a small vendor doesn't need one. The smallest settlement in OCR's public record, $31,000, came from exactly this assumption.

Do's and Don'ts for BAA Negotiation

Do

  • Do put the BAA in place before any PHI moves, even for a short pilot or trial period.
  • Do check every vendor against the definition of business associate, including scheduling apps, transcription services, and cloud backups, not only obvious IT vendors.
  • Do require subcontractor flow-down in writing, and ask for proof rather than a spoken promise.
  • Do negotiate reporting timelines you can meet, since an unworkable deadline creates a second violation on top of the first incident.
  • Do review existing BAAs on a set schedule, at least every one to two years or whenever the underlying service changes.
  • Do loop in compliance or legal review before signing, not after buying is already final.

Don't

  • Don't rely on a mutual NDA instead of a BAA. A confidentiality agreement does not meet HIPAA's specific required provisions.
  • Don't assume a vendor's marketing claim of "HIPAA compliant" replaces a signed BAA. Only the signed agreement itself meets the legal requirement.
  • Don't let a vendor's standard contract override the BAA's terms. Confirm which document controls whenever the two clash.
  • Don't skip the review only because the vendor is small or the deal is short-term. Size and length do not change HIPAA's rules.
  • Don't forget to name subcontractors directly. A BAA silent on subcontractors leaves a foreseeable gap unaddressed.
  • Don't destroy PHI at contract's end without checking whether return is required instead, since some agreements name one over the other.

Pros and Cons of a Template BAA vs. Custom Counsel-Drafted BAA

Most groups choose between a vendor's standard template BAA and a custom deal built with a healthcare attorney. Both paths can meet HIPAA's ten required provisions. The real gap shows up in speed, cost, and how much protection sits beyond the legal floor. Weigh the trade-offs below against the size of the vendor deal and how sensitive the data is.

Pros

  • Faster to sign. A vendor's standard BAA, often built from HHS's own sample language, can be signed the same day a service deal closes.
  • Lower upfront cost. Many software vendors give a template BAA at no extra charge as part of onboarding.
  • Steady baseline coverage. A template built from HHS's sample provisions covers all ten required elements by default, cutting the risk of an accidental gap.
  • Easier for small practices to manage. A solo or small-group practice without in-house counsel can still meet its legal duty with a well-built template.
  • Predictable for vendors serving many clients. A vendor offering one standard BAA to every client keeps its own compliance program simpler to check.

Cons

  • Little room to negotiate reporting timelines. A take-it-or-leave-it template often sets breach-notice deadlines that favor the vendor, not the covered entity.
  • May miss group-specific risks. A generic template will not cover a covered entity's unique data flows, like PHI shared with subcontractors abroad.
  • Weaker liability protection. Templates rarely include indemnification or insurance rules, leaving the covered entity to absorb more cost after a breach.
  • No link to the underlying deal. A standalone template BAA may not reference or match the service agreement, opening gaps between the two documents.
  • Harder to enforce extra promises. A spoken promise from a sales rep about added protection carries no weight if the signed template doesn't reflect it.

What to Do Next

Once the current BAA picture is clear, work through these steps in order:

  1. Pull every current vendor contract that could touch PHI and check whether a signed BAA exists for each one.
  2. Compare each existing BAA against the ten required provisions listed above, and flag any missing clause in writing.
  3. Confirm every vendor's own subcontractors have signed a matching flow-down BAA, not only a general confidentiality agreement.
  4. Set a BAA review date at least once every two years, or sooner if a vendor's service or subcontractors change.
  5. Bring in a healthcare attorney or compliance officer for any BAA tied to a high-PHI-volume vendor, a multi-subcontractor deal, or a contract that has never been checked.
  6. Keep signed BAAs in one searchable file, since OCR can ask for proof of an agreement during any probe.

Frequently Asked Questions

What should be included in a business agreement?

A business agreement should spell out the scope of work, payment terms, confidentiality duties, and termination rights. When PHI changes hands, HIPAA adds ten specific rules on top of those general terms. These cover safeguards, breach reporting, and subcontractor flow-down.

What are the elements of a BAA?

The required elements are permitted PHI uses, use limits, safeguards, breach reporting, patient-rights support, HHS audit access, return-or-destroy at the end, subcontractor flow-down, and termination rights. Each maps to one of the ten specific clauses HIPAA's Privacy Rule requires.

What are business associates not permitted to do?

Business associates cannot use or share PHI beyond what their BAA specifically allows. That includes selling data, marketing unrelated services, or ignoring the Security Rule for electronic PHI. It also includes letting a subcontractor touch PHI without its own compliant agreement.

What are common BAA mistakes?

The most common mistake is signing a vendor contract before the BAA itself is signed. Close behind are missing subcontractor flow-down language and reusing an outdated pre-2013 template. Also common is accepting reporting deadlines the business associate cannot realistically meet.

Who counts as a business associate under HIPAA?

Any person or firm that creates, receives, keeps, or sends PHI on behalf of a covered entity counts as a business associate. Common examples include billing firms, IT vendors, consultants, cloud hosts, and transcription services.

Does a cloud storage vendor need a BAA?

Yes, if the vendor's platform stores or handles PHI, it needs a BAA before any of it is uploaded. This holds even when the data is encrypted. It also holds even if the vendor's own staff never view it directly.

What happens if a business associate breaches PHI without a BAA in place?

Without a BAA, the underlying disclosure to that business associate was likely already a HIPAA violation, apart from the breach itself. OCR can penalize both the covered entity and the business associate. Comparable settlements have reached into the millions.

Can a covered entity be liable for a business associate's HIPAA violation?

Yes, a covered entity can face risk if it knew of a business associate's violation and failed to act. HIPAA requires the covered entity to take fair steps to fix the problem, or end the deal once it learns of one.

How long should a covered entity keep a signed BAA on file?

Covered entities should keep a signed BAA for at least six years from the date it was created or last in effect. That period matches HIPAA's general record-keeping rule. OCR can request the file during any probe.

Do subcontractors of business associates need their own BAA?

Yes, subcontractors that create, receive, keep, or send PHI need their own BAA with the business associate that hired them. This flow-down rule has applied since the HITECH Act folded subcontractors into HIPAA's Omnibus Rule.

Is a spoken agreement ever enough instead of a written BAA?

No, HIPAA requires the business associate's assurances to be in writing, whether as a standalone BAA or a contract section. A spoken promise to protect PHI does not meet the Privacy Rule, no matter how detailed the conversation was.

What is the difference between a BAA and a standard NDA?

A standard NDA only protects confidential data in general, while a BAA meets specific HIPAA rules an NDA does not cover. Those extras include breach reporting, safeguard duties, and the right for the covered entity to end the deal over a major violation.

How often should a BAA be reviewed or updated?

Most compliance advisors suggest reviewing BAAs at least every one to two years, or right after a rule change. A BAA drafted before the HITECH Act's 2013 Omnibus Rule almost certainly needs an update today.

Does a BAA need to be signed before any PHI is shared?

Yes, the agreement should be signed before the business associate creates, receives, keeps, or sends any PHI. Sharing PHI first and signing later leaves a gap where the disclosure itself is unauthorized.