Business Associate Agreement Template for the United States

Generate a bespoke document

What is a Business Associate Agreement?

Business Associate Agreements are required across the United States wherever a healthcare provider, health plan or clearinghouse engages a vendor that will handle protected health information. Typical business associates include billing companies, IT and cloud hosting providers, transcription services, analytics vendors and legal or accounting advisers. Since the HITECH Act, business associates are directly liable for certain HIPAA obligations rather than only contractually liable to the covered entity, and the agreement must flow substantially the same terms down to any subcontractor.

Trusted by high-performance teams

Frequently Asked Questions

When is a Business Associate Agreement required?

Whenever a vendor creates, receives, maintains or transmits protected health information on behalf of a covered entity. Disclosing protected health information to a service provider without a compliant agreement is itself a HIPAA violation, so it must be in place before access begins.

Is a cloud hosting provider a business associate?

Yes, if it maintains electronic protected health information, even where it never views the data. The Department of Health and Human Services has confirmed that a hosting provider holding encrypted protected health information is still a business associate and needs an agreement.

What terms must a BAA contain?

45 CFR 164.504(e) prescribes them: permitted and prohibited uses, safeguards, reporting of impermissible use and breaches, subcontractor flow-down, individual access and amendment rights, an accounting of disclosures, availability of records to regulators, and return or destruction on termination.

How quickly must a business associate report a breach?

HIPAA sets an outer limit, but covered entities almost always contract for something shorter, often days rather than weeks. The covered entity has its own notification deadline and needs time to investigate before it reports, so the contractual window is deliberately tighter.

Do subcontractors need their own agreement?

Yes. A business associate passing protected health information to a subcontractor must obtain substantially the same assurances it gave the covered entity. This is a direct requirement rather than good practice, and it applies down the whole chain.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

United States

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Business Associate Agreement

A Business Associate Agreement is the contract HIPAA requires before a covered entity may disclose protected health information to a vendor acting on its behalf. It is not an optional protection: the required terms are prescribed by 45 CFR 164.504(e), and disclosing protected health information without a compliant agreement is itself a violation.

When do you need this document?

You need a Business Associate Agreement whenever a vendor will create, receive, maintain or transmit protected health information for a covered entity. That includes cloud hosting and IT support with access to systems holding patient data, billing and revenue cycle providers, transcription and coding services, analytics and population health vendors, and professional advisers who see patient records. A business associate engaging its own subcontractor needs an equivalent agreement down the chain.

What does it cover?

The agreement limits what the business associate may do with the information, requires safeguards to protect it, and obliges the business associate to report impermissible uses, security incidents and breaches within a defined period. It provides for individuals' rights, including access, amendment and an accounting of disclosures, and makes records available to regulators. It also deals with the end of the relationship by requiring the information to be returned or destroyed, and by extending the obligations to any copies that cannot be destroyed.

Common pitfalls

The most frequent error is treating the BAA as a standalone document and never reconciling it with the underlying services contract, so that a broad data usage right in the service terms contradicts the narrow permitted use in the BAA. The second is accepting a breach reporting window that is no shorter than the covered entity's own notification deadline, which leaves no time to investigate and notify. The third is failing to flow the obligations down to subcontractors, which is a direct requirement rather than a matter of good practice.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it