Establishing secure connection…Loading editor…Preparing document…

Business Associate Agreement Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement ("Agreement") is entered into as of Effective Date: by and between Covered Entity Name: with Entity Type: and Business Associate Name: with Entity Type: (each, a "Party" and collectively, the "Parties").

RECITALS

WHEREAS, Covered Entity possesses Protected Health Information ("PHI") that is subject to privacy and security regulations under applicable law; and

WHEREAS, Business Associate performs certain services for Covered Entity that require access to PHI; and

WHEREAS, the Parties desire to comply with applicable law governing PHI and to set forth their respective obligations with respect to the use, disclosure, safeguarding, and return or destruction of PHI.

NOW, THEREFORE, in consideration of the mutual covenants contained herein, the Parties agree as follows:

1. DEFINITIONS

1.1 "Protected Health Information" or "PHI" means individually identifiable health information created, received, maintained or transmitted by either Party that is protected under applicable law. Terms used but not otherwise defined in this Agreement shall have the same meaning as those terms in the Privacy Rule, Security Rule, and applicable law.

2. PERMITTED USES AND DISCLOSURES

2.1 Business Associate may use and disclose PHI only (a) as necessary to perform the services described in the underlying services agreement between the Parties, (b) as required by law, and (c) as otherwise permitted in this Agreement. Business Associate shall not use or disclose PHI in any manner that would violate applicable law if done by Covered Entity.

2.2 Specific permitted purposes (select all that apply):

3. BUSINESS ASSOCIATE OBLIGATIONS

3.1 Business Associate shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of PHI in accordance with applicable law and the Security Rule. Business Associate shall document such safeguards and provide a description upon Covered Entity's reasonable request.

3.2 Business Associate shall notify Covered Entity of any Security Incident or of any breach of unsecured PHI discovered by Business Associate without unreasonable delay and in no event later than 60 days after discovery. Such notice shall include: a brief description of the incident, the types of PHI involved, steps taken to mitigate harm, and contact information for further inquiries.

3.3 Business Associate shall ensure that any subcontractor or agent to whom it provides PHI agrees in writing to the same restrictions and conditions that apply to Business Associate under this Agreement.

4. PERMITTED REQUESTS BY COVERED ENTITY

4.1 Covered Entity may request reasonable assurances and documentation from Business Associate demonstrating compliance with this Agreement. Business Associate shall provide such information within a reasonable period not to exceed 30 days unless otherwise agreed in writing.

5. ACCESS, AMENDMENT AND ACCOUNTING

5.1 To the extent Business Associate has possession of PHI in a Designated Record Set, Business Associate shall make such PHI available to Covered Entity for access or amendment in accordance with the Privacy Rule. Business Associate shall also make available records necessary for Covered Entity to provide an accounting of disclosures as required by law.

6. RETURN OR DESTRUCTION OF PHI

6.1 Upon termination of the underlying services arrangement or this Agreement, Business Associate shall, at Covered Entity's election, return or securely destroy all PHI received from Covered Entity, and retain no copies. If return or destruction is not feasible, Business Associate shall extend protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, and shall notify Covered Entity of the reasons for infeasibility.

7. AUDIT AND INSPECTION

7.1 Upon reasonable notice and during regular business hours, Business Associate shall make its facilities, systems and records related to PHI available to Covered Entity or its designee for the purpose of determining compliance with this Agreement, subject to confidentiality restrictions and applicable law.

8. INDEMNIFICATION

8.1 Business Associate shall indemnify, defend and hold harmless Covered Entity from and against any claims, liabilities, damages and expenses (including reasonable attorneys' fees) resulting from Business Associate's material breach of this Agreement or Business Associate's negligent or intentional acts or omissions that cause unauthorized use or disclosure of PHI.

9. TERM AND TERMINATION

9.1 Term. This Agreement shall commence on the Effective Date and shall terminate upon expiration or termination of the Parties' underlying services agreement, unless earlier terminated as provided herein.

9.2 Termination for Cause. Covered Entity may terminate this Agreement if Covered Entity determines that Business Associate has violated a material term of this Agreement and Business Associate fails to cure such breach within a reasonable time, not to exceed 30 days after written notice.

10. MISCELLANEOUS PROVISIONS

10.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of: without regard to conflict of laws principles.

10.2 Entire Agreement. This Agreement constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior agreements and understandings, whether written or oral.

10.3 Severability. If any provision of this Agreement is held invalid or unenforceable, the remainder of the Agreement shall remain in full force and effect and the invalid or unenforceable provision shall be reformed to the minimum extent necessary to make it enforceable.

10.4 Amendments; Waiver. Any amendment to this Agreement must be in writing and signed by both Parties. Failure to enforce any provision shall not constitute waiver of that provision or any other provision.

10.5 Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument.

11. NOTICES

Notices shall be given in writing to the addresses below and shall be effective upon receipt.

12. SECURITY AND RISK MANAGEMENT

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What the Business Associate Agreement Document Is

A Business Associate Agreement Document (BAA) is a written contract between a HIPAA-covered entity and a business associate that creates, receives, maintains, or transmits protected health information (PHI) on the covered entity's behalf. The BAA defines permitted uses and disclosures of PHI, required administrative, physical, and technical safeguards, breach notification procedures, subcontractor flow-down obligations, and terms for return or destruction of PHI. When executed electronically, BAAs are enforceable under federal e-signature law (15 U.S.C. §7001) and state electronic transaction statutes such as UETA where adopted.

Why a BAA Matters for Compliance and Risk Management

A BAA documents each party's responsibilities to protect PHI, reduces legal exposure, and supports HIPAA audits and investigations.

Why a BAA Matters for Compliance and Risk Management

Who Typically Prepares and Signs a BAA

BAAs are used across healthcare and any organization that handles PHI on behalf of a covered entity; several roles commonly prepare and review the agreement.

  • Covered entities and their legal or compliance teams responsible for HIPAA adherence and vendor oversight.
  • Business associates such as IT vendors, billing companies, cloud providers, and consultants who handle PHI.
  • Privacy officers or compliance officers who negotiate safeguards and monitor vendor performance.

Each signer should have authority to bind their organization and confirm technical and administrative safeguards are in place.

Core Sections to Include in a Professional BAA

A complete BAA is structured to assign duties clearly and reduce ambiguity about PHI handling, incident response, and termination.

Parties & Definitions

Identify the covered entity and business associate by legal name and define PHI, permitted uses, and key terms to avoid ambiguity.

Permitted Uses

List specific purposes for which the business associate may use or disclose PHI and prohibit any uses not explicitly authorized.

Safeguards

Specify administrative, physical, and technical safeguards required to protect PHI, including encryption, access controls, and workforce training obligations.

Breach Notification

Detail timelines and processes for notifying the covered entity about breaches, cooperating with investigations, and preserving evidence.

Subcontractors

Require the business associate to flow down BAA obligations to subcontractors handling PHI and to remain liable for subcontractor breaches.

Termination & Return

Define termination rights, steps to return or securely destroy PHI, and conditions under which termination may be delayed for compliance reasons.

Essential Information and Fields to Capture

Covered Entity: Full legal name
Business Associate: Full legal name
Effective Date: MM/DD/YYYY
Services Covered: Brief service description
PHI Types: Specify categories
Security Controls: High-level safeguards

How to Complete a Business Associate Agreement Document — Step by Step

Follow these steps to prepare, review, sign, and store a compliant BAA efficiently.

  • 01
    Gather details: Collect party names, service descriptions, and PHI categories.
  • 02
    Draft terms: Include permitted uses, safeguards, breach procedures, and termination.
  • 03
    Legal review: Have counsel confirm HIPAA alignment and liability language.
  • 04
    Sign and retain: Execute signatures and archive signed copy with audit trail.

How to Configure an Online BAA Workflow

Set up fields and routing to ensure each signer receives the correct document version with an audit trail.

Field Configuration
Signature Field Place signature and date fields for each party
Authentication Use email link or SMS code for signer verification
Attachments Attach technical addenda or security exhibits
Audit Trail Enable timestamps, IP logging, and completion certificate

Where to Send and Store the Executed Agreement

Routing and storage steps ensure both parties have enforceable copies and an evidentiary audit trail.

  • Send to Legal: Deliver signed copy to each party's legal contact
  • Store Securely: Archive in encrypted records with access controls
  • Share Internally: Provide compliance and IT teams with executed copy
  • Retain Audit Trail: Keep signature metadata and certificates

Digital Signing and File Format Considerations

Choose a platform that supports legally compliant e-signatures, audit trails, and secure storage for PHI-related agreements.

  • Document Formats: PDF and DOCX supported
  • Integrations: Connects with NetSuite and Microsoft 365
  • Authentication: Email, SMS, or advanced verification

Ensure the provider supports HIPAA Business Associate Agreements (BAA availability) and preserves cryptographic or audit evidence for legal reproducibility.

Key Dates and Timing to Track for a BAA

Monitor effective dates, review cycles, breach timelines, and retention milestones to maintain compliance.

Effective Date:

Date the agreement starts; governs obligations immediately

Annual Review:

Recommend periodic review of controls and subcontractors

Breach Notification Deadline:

Notify covered entity without unreasonable delay; see 45 C.F.R. §164.404

Termination Notice:

Define notice period required to terminate for cause

Record Retention Start:

Retention clock begins on effective or last-modified date

Common Preparation Mistakes to Avoid

  • Using vague or overly broad permitted-use language that unintentionally allows secondary data uses.
  • Failing to require subcontractor flow-down obligations, leaving gaps when vendors engage third parties.
  • Neglecting to document technical safeguards such as encryption and access logging in the agreement.
  • Not ensuring the signer has authority to bind the organization and keeping no proof of that authority.

Penalties and Risks of an Incomplete or Incorrect BAA

HIPAA Liability: Civil and criminal enforcement risk
Breach Costs: Notification and remediation expenses
Contractual Exposure: Indemnity and damages obligations
Regulatory Scrutiny: HHS OCR investigations
Operational Disruption: Loss of vendor services pending remediation
Reputational Harm: Trust erosion with patients and partners

Real-World Examples of BAAs in Use

These short examples show how organizations frame BAA needs and what they highlight when choosing a signing workflow.

Fertility Centers Example

A midsize clinic centralized its vendor agreements to reduce delays

  • streamlined signature routing for clinical vendors
  • "The airSlate SignNow team has been exceptional, responsive, the API has been great, and we're extremely happy that we chose airSlate SignNow as a company."

Managed Services Vendor

An IT provider required documented safeguards and SOC 2 evidence

  • negotiated flow-down obligations for subcontractors
  • "We felt most comfortable with airSlate SignNow given their SOC 2 certification and strict focus on ESIGN and UETA act compliance."

eSignature Pricing and Feature Snapshot for BAAs

Compare common eSignature providers on price and core capabilities relevant to executing BAAs; signNow is listed first per vendor conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

FAQs: Common Questions About Business Associate Agreements

Answers to common questions about when a BAA is required, electronic execution, and what to watch for in vendor language.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users