Establishing secure connection…Loading editor…Preparing document…

Business Associate Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (the "Agreement") is entered into as of Effective Date: by and between Covered Entity: with principal place of business at and Business Associate: with principal place of business at .

RECITALS

WHEREAS, Covered Entity possesses certain protected health information and related data that are governed by applicable law and that Covered Entity may disclose to Business Associate for purposes of performing services described in the underlying services arrangement between the parties; and

WHEREAS, Business Associate will receive, create, maintain or transmit protected health information on Covered Entity's behalf and must agree to certain safeguards, reporting obligations and restrictions on uses and disclosures; and

WHEREAS, the parties intend by this Agreement to establish the requirements and responsibilities of Business Associate and Covered Entity with respect to such information.

NOW, THEREFORE

In consideration of the mutual promises and covenants herein, the parties agree as follows:

1. DEFINITIONS

1.1 "Protected Health Information" or "PHI" means individually identifiable health information, whether oral or recorded in any form or medium, that relates to the past, present or future physical or mental health condition of an individual, provision of health care to an individual, or payment for the provision of health care, and that is created, received, maintained or transmitted by Business Associate on behalf of Covered Entity, as defined in applicable law.

1.2 "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted by law or this Agreement that compromises the security or privacy of the PHI, subject to any legal exceptions applicable to an unauthorized acquisition, access, use or disclosure.

2. PERMITTED USES AND DISCLOSURES

2.1 Business Associate may use and disclose PHI only as necessary to perform services specified in the underlying services arrangement between the parties and consistent with this Agreement. Business Associate shall not use or further disclose PHI other than as permitted hereunder or as required by law.

2.2 Permitted purposes (check all that apply):
       

2.3 Any use of PHI for fundraising, marketing, sale of PHI, or other purposes not specifically permitted by this Agreement is prohibited unless expressly authorized in writing by Covered Entity and consistent with applicable law.

3. OBLIGATIONS OF BUSINESS ASSOCIATE

3.1 Business Associate shall implement and maintain administrative, physical and technical safeguards designed to protect the confidentiality, integrity and availability of PHI and to prevent any use or disclosure of PHI other than as permitted by this Agreement.

3.2 Business Associate shall ensure that any person or entity to whom it provides PHI, including its workforce and subcontractors, is subject to written obligations at least as protective as those in this Agreement and shall take reasonable steps to remedy any material breach by such persons or entities.

3.3 Business Associate shall report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, any security incident, and any Breach of unsecured PHI of which Business Associate becomes aware. Such report shall be made without unreasonable delay and, in any event, no later than 60 days after Business Associate discovers the Breach, and shall include sufficient information to permit Covered Entity to meet its notification obligations under applicable law.

4. SUBCONTRACTORS

4.1 Business Associate shall obtain reasonable written assurances from any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate that such subcontractor will appropriately safeguard PHI and comply with the same restrictions and conditions that apply to Business Associate under this Agreement.

5. ACCESS, AMENDMENT AND ACCOUNTING

5.1 To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make such PHI available to Covered Entity or to an individual as necessary to satisfy Covered Entity's obligations under applicable law to provide access or an accounting of disclosures.

5.2 Business Associate shall, upon receipt of written notice from Covered Entity, incorporate any agreed amendments to PHI maintained by Business Associate and shall notify Business Associate's subcontractors as necessary to effect such amendments.

6. SECURITY SAFEGUARDS

6.1 Business Associate shall implement appropriate administrative, physical and technical safeguards to reasonably and appropriately protect the confidentiality, integrity and availability of PHI, including access controls, audit controls, encryption where appropriate, and policies for workforce training and incident response.

6.2 Business Associate shall periodically assess the effectiveness of safeguards and document actions taken to address identified vulnerabilities.

7. REPORTING OF BREACHES

7.1 In the event of a Breach, Business Associate shall, without unreasonable delay and no later than 60 days after discovery, provide Covered Entity with a written report containing: a description of the nature and scope of the Breach, the PHI involved, steps taken to mitigate harm, the individuals affected (if known), and contact information for Business Associate's privacy officer or other responsible person.

8. RETURN OR DESTRUCTION OF PHI

8.1 Upon termination of this Agreement or upon Covered Entity's written request, Business Associate shall return to Covered Entity or securely destroy all PHI received from Covered Entity that Business Associate still maintains in any form. If return or destruction is not feasible, Business Associate shall continue to protect the PHI in accordance with this Agreement and shall limit further uses and disclosures to those purposes that make return or destruction infeasible.

9. AUDITS AND RECORDS

9.1 Business Associate shall make its internal practices, books and records relating to the use and disclosure of PHI available to Covered Entity, and to any appropriate regulatory authority as required by law, for purposes of determining compliance with applicable law and this Agreement; provided that any such access respects applicable confidentiality obligations to third parties.

10. INDEMNIFICATION

10.1 Business Associate shall indemnify, defend and hold harmless Covered Entity from and against any losses, liabilities, damages, costs and expenses (including reasonable attorneys' fees) arising from Business Associate's breach of this Agreement or from Business Associate's negligent or willful acts or omissions in the performance of its obligations hereunder.

11. LIMITATION OF LIABILITY

11.1 Except for obligations to indemnify or liability arising from willful misconduct or a material breach of this Agreement, neither party shall be liable to the other for consequential, incidental, special or punitive damages. Nothing in this section shall limit a party's liability to the extent required by applicable law.

12. TERM AND TERMINATION

12.1 Term. This Agreement shall commence on the Effective Date and shall continue for the term of the underlying services arrangement between the parties, unless earlier terminated as provided herein.

12.2 Termination for Cause. Covered Entity may terminate this Agreement upon written notice if Covered Entity determines Business Associate has violated a material term of this Agreement and Business Associate fails to cure such violation within thirty (30) days of notice, or if cure is not feasible.

12.3 Effect of Termination. Upon termination, Business Associate shall return or destroy PHI as set forth in Section 8 and shall continue to be bound by the obligations of this Agreement with respect to any PHI retained.

13. SURVIVAL

13.1 The obligations of Business Associate under Sections 3, 5, 6, 7, 8, 9, 10 and this Section 13 shall survive termination of this Agreement.

14. NOTICES

14.1 All notices, requests, consents, claims, demands, waivers and other communications hereunder must be in writing and addressed to the parties at the addresses set forth below or at such other address that a party may designate by notice given in accordance with this Section.

15. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

15.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the state specified below without regard to its conflicts of law principles.

Choose governing law state:

15.2 Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements, understandings and representations related to the protection and use of PHI.

15.3 Severability. If any provision of this Agreement is held to be invalid, illegal or unenforceable in any respect, the remaining provisions shall continue in full force and effect and the parties shall endeavor to replace the invalid provision with a valid provision accomplishing, to the extent possible, the original intent.

16. AMENDMENT; WAIVER; COUNTERPARTS

16.1 Amendment. This Agreement may be amended only by a written instrument executed by both parties. The parties acknowledge that applicable law may require modifications to this Agreement and agree to negotiate in good faith to incorporate any required changes.

16.2 Waiver. No delay or failure to exercise any right hereunder shall operate as a waiver of that right, and any waiver must be in writing.

16.3 Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument.

17. MISCELLANEOUS

17.1 Relationship of the Parties. Business Associate is an independent contractor. Nothing in this Agreement creates a partnership, joint venture or agency relationship between the parties.

17.2 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with applicable law.

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What a Business Associate Agreement covers

A Business Associate Agreement (BAA) is a written contract between a HIPAA-covered entity and a vendor or partner that creates, receives, maintains, or transmits protected health information (PHI) on the covered entity's behalf. The BAA defines permitted uses and disclosures of PHI, required administrative, physical, and technical safeguards, breach-notification procedures, subcontractor flowdown obligations, and termination rights. A properly executed BAA documents responsibilities for protection of PHI and supports regulatory compliance while enabling business relationships where PHI must be shared. Electronic execution is acceptable when parties consent under ESIGN and applicable state law.

Why a BAA matters for HIPAA compliance

A Business Associate Agreement assigns regulatory and contractual responsibilities, limits misuse of PHI, clarifies breach-notification duties, and establishes data safeguards. It is required under the HIPAA Privacy and Security Rules when PHI is handled by a vendor (45 CFR §164.504(e)).

Why a BAA matters for HIPAA compliance

Who typically needs a Business Associate Agreement

Covered entities and vendors engaged with PHI commonly use BAAs to document responsibilities and controls.

  • Hospitals, clinics, and physician practices that outsource billing, transcription, or cloud hosting of PHI.
  • Health IT providers, EHR vendors, and cloud-storage firms that store, process, or transmit PHI.
  • Billing companies, analytics vendors, consultants, and subcontractors handling PHI on behalf of a covered entity.

Even small vendors or contractors that access PHI should evaluate whether a signed BAA is required before work begins.

Who signs and who approves

Health System Counsel

General counsel or privacy officer usually reviews and approves BAAs for covered entities, ensuring terms meet HIPAA requirements and align with organizational risk tolerance. They confirm breach-notification timing, security measures, and indemnity provisions before execution.

Vendor Authorized Rep

An officer or designated representative with authority to bind the business associate should sign the BAA. That signer accepts subcontractor flowdowns, security obligations, and breach reporting requirements on behalf of the vendor.

Essential clauses to include in a professional BAA

A robust Business Associate Agreement contains clear, enforceable clauses that allocate responsibilities, limit uses of PHI, and require safeguards, reporting, and return or destruction of PHI at termination.

Definitions

Precisely define terms such as PHI, permitted uses, business associate, subcontractor, and handling exceptions to avoid ambiguity during enforcement or audits.

Permitted Uses

State exactly which activities the business associate may perform with PHI and prohibit any uses not necessary for the agreed services.

Safeguards

Specify administrative, physical, and technical safeguards required to protect PHI, including encryption, access controls, vulnerability management, and periodic testing.

Breach Notification

Require prompt notification to the covered entity for suspected breaches, timeframes for reporting, and cooperation for breach investigations and notifications.

Subcontractor Flowdown

Mandate that subcontractors handling PHI agree to the same obligations and require the business associate to monitor and enforce compliance.

Return / Destruction

Address the return or secure destruction of PHI on contract termination and procedures for retaining limited records where required by law.

Required BAA information at a glance

Covered Entity Name: Full legal entity
Business Associate Name: Full legal entity
Services Description: Scope of services
PHI Types: Categories of PHI
Breach Contact: Notification point
Security Standards: Required safeguards

Step-by-step: completing a Business Associate Agreement

Follow a clear sequence: gather information, customize terms to the relationship, obtain signatures, and retain the executed agreement for compliance and audits.

  • 01
    Gather details: Collect legal names, services, PHI types, and contacts.
  • 02
    Customize clauses: Tailor permitted uses, safeguards, and termination language.
  • 03
    Obtain signatures: Sign electronically or on paper by authorized parties.
  • 04
    Store executed copy: Retain per retention policy with audit trail.

Configuring an electronic BAA workflow

Set up signer authentication, required fields, audit-trail capture, and automated retention to ensure legally defensible e-execution and recordkeeping.

Field Configuration
Authentication Email + SMS code or stronger
Signature Type Electronic signature with audit trail
Audit Trail Capture IP, timestamp, and actions
Retention Automate secure storage and export

Digital signing and technical requirements

Choose an eSignature platform that supports secure authentication, tamper-evident audit trails, and exportable signed records for audits.

  • Authentication: Email, SMS, or advanced options
  • Integrations: EHR, NetSuite, CRM systems
  • File types: PDF, DOCX, and export formats

Penalties and risks of an incomplete or incorrect BAA

Regulatory Fines: Civil penalties possible
Criminal Exposure: Severe HIPAA violations risk prosecution
Contract Liability: Indemnity and damages
Breach Costs: Notification and remediation expenses
Operational Disruption: Service interruptions and audits
Reputational Harm: Loss of trust and business

Common mistakes to avoid when preparing a BAA

  • Using vague descriptions of services and PHI types that leave permitted uses open to interpretation and create compliance gaps during audits or breaches.
  • Failing to require subcontractor flowdowns, which can leave covered entities exposed if a downstream vendor mishandles PHI without contractual safeguards.
  • Not specifying technical safeguards such as encryption or access controls, making it difficult to verify whether the business associate meets security expectations.
  • Delaying execution or relying on unsigned templates; working before a signed BAA increases legal and regulatory risk if PHI is exchanged.

Key timing and notification expectations for BAAs

Certain timeframes are important: effective dates, prompt breach reporting, and retention start points. Build contractual deadlines into the BAA.

Effective Date:

Specify MM/DD/YYYY when obligations commence

Execution Deadline:

Require signature before PHI exchange or within set days

Breach Notification:

Business associate must notify covered entity without unreasonable delay (see HIPAA breach rules)

Record Retention Start:

Retention begins on creation or last effective date

Termination Notice:

Define cure period and effective termination timeline

Lifecycle milestones for a Business Associate Agreement

A BAA typically follows discrete stages from negotiation to termination and post-termination obligations; map those milestones in your contracting process.

01

Negotiation

Clarify scope, safeguards, and liability terms with legal review

02

Execution

Obtain authorized signatures before exchanging PHI

03

Operational Monitoring

Conduct periodic compliance reviews and security assessments

04

Termination & Disposal

Return or securely destroy PHI and archive necessary records

Real-world examples of BAAs in use

These short examples show how organizations use BAAs to document responsibilities when PHI is shared with external vendors.

Fertility Centers of Illinois — John Butler

A regional healthcare provider needed remote vendor processing for patient records

  • The vendor signed a BAA and implemented encryption
  • "The airSlate SignNow team has been exceptional, responsive, the API has been great, and we're extremely happy that we chose airSlate SignNow as a company."

Xerox — Kodi-Marie Evans

A large enterprise integrated signature workflows with NetSuite for HR and vendor contracts

  • Xerox required BAAs for all PHI-handling integrations
  • "airSlate SignNow provides us with the flexibility needed to get the right signatures on the right documents, in the right formats, based on our integration with NetSuite."

eSignature platform pricing and compliance overview (vendor comparison)

Compare common vendor factors relevant to executing Business Associate Agreements: starting price, trial availability, bulk send, audit trail, HIPAA support, and envelope limits.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/yr Varies Varies Varies

Practical tips for accurate and efficient BAA completion

Follow a consistent process for drafting, review, execution, and storage to reduce legal risk and operational friction when managing BAAs.

Be specific about PHI
Limit permitted uses to the minimum necessary and list PHI categories to reduce ambiguity and downstream compliance exposure.
Include subcontractor requirements
Require flowdown obligations and the right to audit subcontractors who handle PHI, ensuring layered compliance across the vendor chain.
Document technical safeguards
Specify encryption, access control, logging, and incident response processes so technical expectations are enforceable and auditable.
Maintain an executed record
Store the signed BAA and execution audit trail in a secure, access-controlled repository for at least the regulatory minimum.

Common questions about Business Associate Agreements

Answers to frequent BAA questions covering enforceability, signatures, breach obligations, notarization, and practical next steps for compliance.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users