Business Associate Agreement Template for the United States
Generate a bespoke document
What is a Business Associate Agreement?
Business Associate Agreements are required across the United States wherever a healthcare provider, health plan or clearinghouse engages a vendor that will handle protected health information. Typical business associates include billing companies, IT and cloud hosting providers, transcription services, analytics vendors and legal or accounting advisers. Since the HITECH Act, business associates are directly liable for certain HIPAA obligations rather than only contractually liable to the covered entity, and the agreement must flow substantially the same terms down to any subcontractor.
Trusted by high-performance teams
Frequently Asked Questions
When is a Business Associate Agreement required?
Whenever a vendor creates, receives, maintains or transmits protected health information on behalf of a covered entity. Disclosing protected health information to a service provider without a compliant agreement is itself a HIPAA violation, so it must be in place before access begins.
Is a cloud hosting provider a business associate?
Yes, if it maintains electronic protected health information, even where it never views the data. The Department of Health and Human Services has confirmed that a hosting provider holding encrypted protected health information is still a business associate and needs an agreement.
What terms must a BAA contain?
45 CFR 164.504(e) prescribes them: permitted and prohibited uses, safeguards, reporting of impermissible use and breaches, subcontractor flow-down, individual access and amendment rights, an accounting of disclosures, availability of records to regulators, and return or destruction on termination.
How quickly must a business associate report a breach?
HIPAA sets an outer limit, but covered entities almost always contract for something shorter, often days rather than weeks. The covered entity has its own notification deadline and needs time to investigate before it reports, so the contractual window is deliberately tighter.
Do subcontractors need their own agreement?
Yes. A business associate passing protected health information to a subcontractor must obtain substantially the same assurances it gave the covered entity. This is a direct requirement rather than good practice, and it applies down the whole chain.
About the Business Associate Agreement
A Business Associate Agreement is the contract HIPAA requires before a covered entity may disclose protected health information to a vendor acting on its behalf. It is not an optional protection: the required terms are prescribed by 45 CFR 164.504(e), and disclosing protected health information without a compliant agreement is itself a violation.
When do you need this document?
You need a Business Associate Agreement whenever a vendor will create, receive, maintain or transmit protected health information for a covered entity. That includes cloud hosting and IT support with access to systems holding patient data, billing and revenue cycle providers, transcription and coding services, analytics and population health vendors, and professional advisers who see patient records. A business associate engaging its own subcontractor needs an equivalent agreement down the chain.
What does it cover?
The agreement limits what the business associate may do with the information, requires safeguards to protect it, and obliges the business associate to report impermissible uses, security incidents and breaches within a defined period. It provides for individuals' rights, including access, amendment and an accounting of disclosures, and makes records available to regulators. It also deals with the end of the relationship by requiring the information to be returned or destroyed, and by extending the obligations to any copies that cannot be destroyed.
Common pitfalls
The most frequent error is treating the BAA as a standalone document and never reconciling it with the underlying services contract, so that a broad data usage right in the service terms contradicts the narrow permitted use in the BAA. The second is accepting a breach reporting window that is no shorter than the covered entity's own notification deadline, which leaves no time to investigate and notify. The third is failing to flow the obligations down to subcontractors, which is a direct requirement rather than a matter of good practice.
GOVERNING LAW
Applicable law
This Business Associate Agreement is drafted to comply with United States law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

