Establishing secure connection…Loading editor…Preparing document…

Business Associate Agreement for Contractors

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS ASSOCIATE AGREEMENT FOR CONTRACTORS

This Business Associate Agreement ("Agreement") is entered into as of by and between Covered Entity: , Address: (hereinafter "Covered Entity") and Business Associate (Contractor): , Address: (hereinafter "Business Associate").

RECITALS

WHEREAS, Covered Entity is a health care provider, health plan, or health care clearinghouse that creates, receives, maintains, or transmits Protected Health Information in the course of its provision of health care or related services; and

WHEREAS, Business Associate is retained by Covered Entity to perform certain services described herein that require Business Associate to create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity; and

WHEREAS, the parties wish to comply with applicable federal and state laws governing the privacy and security of Protected Health Information, and to set forth their respective rights and obligations with respect to Protected Health Information.

NOW, THEREFORE, in consideration of the mutual promises herein and other good and valuable consideration, the parties agree as follows:

1. DEFINITIONS

1.1 "Protected Health Information" or "PHI" means individually identifiable health information, whether oral or recorded in any form or medium, that relates to the past, present or future physical or mental health condition of an individual, the provision of health care to an individual, or the past, present or future payment for the provision of health care to an individual, which is created, received, maintained or transmitted by either party, and which is protected under applicable federal or state law.

1.2 Other capitalized terms used in this Agreement and not otherwise defined shall have the meanings set forth in applicable law.

2. PERMITTED USES AND DISCLOSURES

2.1 Business Associate may use and disclose PHI only as necessary to perform the specific services set forth in the description of services and only to the extent such use or disclosure would not violate applicable law if done by Covered Entity. Description of services:

2.2 Business Associate shall not use or disclose PHI in a manner that would constitute a violation of applicable law if done by Covered Entity, including uses or disclosures for marketing or sale of PHI, except as expressly permitted by this Agreement.

2.3 Business Associate shall limit uses and disclosures to the minimum necessary to accomplish the intended purpose, and shall implement administrative, physical and technical safeguards consistent with Section 3 below.

3. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE

3.1 Business Associate shall implement and maintain appropriate administrative, physical and technical safeguards to protect the confidentiality, integrity and availability of PHI, including written policies and procedures, workforce training, access controls, encryption where appropriate, and regular review of safeguards.

3.2 Business Associate shall ensure that any subcontractor or agent to whom it provides PHI agrees in writing to the same restrictions and conditions that apply to Business Associate under this Agreement and shall provide Covered Entity with a copy of such written agreement upon request.

3.3 Business Associate shall make available to Covered Entity, at Covered Entity's request, such information as is necessary to demonstrate compliance with this Agreement and applicable law, and shall cooperate in any audits, investigations or reviews conducted by Covered Entity or by a regulator with jurisdiction.

4. BREACH NOTIFICATION AND RESPONSE

4.1 Business Associate shall report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, including any security incident or breach of unsecured PHI, within calendar days of discovery. Such report shall identify the nature of the breach, the PHI involved, the steps Business Associate has taken to mitigate harmful effects, and recommended actions for Covered Entity, to the extent known.

4.2 Business Associate shall cooperate with Covered Entity in any investigation, mitigation, notice to affected individuals, or regulatory reporting related to a breach or unauthorized disclosure of PHI.

5. SUBCONTRACTORS AND AGENTS

5.1 Business Associate shall not provide PHI to any subcontractor or agent without first obtaining a written agreement from such subcontractor that imposes the same restrictions and conditions on the use and disclosure of PHI as are imposed upon Business Associate by this Agreement.

5.2 Business Associate shall remain fully liable to Covered Entity for any act or omission of a subcontractor or agent that would constitute a breach of this Agreement if committed by Business Associate.

6. ACCESS, AMENDMENT AND ACCOUNTING

6.1 To the extent Business Associate maintains Designated Record Sets, Business Associate shall provide access to PHI to Covered Entity or, at Covered Entity's direction, to an individual, to permit inspection and copying in accordance with applicable law.

6.2 Business Associate shall make amendments to PHI as directed by Covered Entity and shall document disclosures to allow for an accounting of disclosures as required by law.

7. RETURN OR DESTRUCTION OF PHI

7.1 Upon termination of this Agreement for any reason, Business Associate shall, at Covered Entity's election, return to Covered Entity or destroy all PHI received from Covered Entity that Business Associate still maintains in any form. If return or destruction is not feasible, Business Associate shall extend protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.

8. TERM, TERMINATION AND SURVIVAL

8.1 Term. This Agreement shall commence on the Effective Date set forth above and shall remain in effect until terminated in accordance with this Section.

8.2 Termination for Cause. Covered Entity may terminate this Agreement if it determines that Business Associate has committed a material breach of this Agreement and Business Associate fails to cure such breach within thirty (30) days of written notice; provided, however, that if cure is not feasible, Covered Entity may immediately terminate.

8.3 Survival. The respective rights and obligations of Business Associate under Sections 4, 7, 8.3 (Survival), 9 (Indemnification and Liability), and all other provisions that by their nature should survive, shall survive termination or expiration of this Agreement.

9. INDEMNIFICATION AND LIMITATION OF LIABILITY

9.1 Business Associate shall indemnify, defend and hold harmless Covered Entity and its officers, directors and employees from and against any and all claims, liabilities, losses, damages, costs and expenses (including reasonable attorneys' fees) arising out of Business Associate's breach of this Agreement, negligent acts or omissions, or willful misconduct in connection with the use, disclosure or safeguarding of PHI.

9.2 Nothing in this Agreement shall be construed to waive any defenses, immunities or limitations of liability available to either party under applicable law.

10. NOTICES

Notices shall be in writing and shall be deemed received upon personal delivery, one business day after delivery to an overnight courier, or three business days after deposit in the United States mail, postage prepaid, addressed to the party's notice address set forth above or as otherwise specified in writing.

11. AMENDMENT; WAIVER; ASSIGNMENT

11.1 This Agreement may be amended only by a written instrument signed by both parties. If federal or state law or regulations promulgated after the Effective Date impose additional obligations on the parties, the parties shall promptly negotiate in good faith any amendments necessary to ensure compliance.

11.2 No failure or delay by either party in exercising any right under this Agreement shall operate as a waiver of that right, and no single or partial exercise of a right shall preclude other or further exercise of that right.

11.3 Neither party may assign this Agreement without the prior written consent of the other party, except that Business Associate may assign this Agreement in connection with a merger, acquisition or sale of substantially all of its assets provided the assignee agrees in writing to be bound by the terms of this Agreement.

12. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY; COUNTERPARTS

12.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of without regard to conflicts of law principles.

12.2 Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings, whether written or oral.

12.3 Severability. If any provision of this Agreement is held invalid or unenforceable, the remainder of this Agreement shall continue in full force and effect and the parties shall negotiate in good faith to replace any invalid provision with a valid provision that most nearly effectuates the original intent.

12.4 Counterparts. This Agreement may be executed in counterparts, each of which shall be an original and all of which together shall constitute one instrument. Signatures transmitted by electronic means shall be deemed original signatures.

13. MISCELLANEOUS PROVISIONS

13.1 Business Associate represents and warrants that it will comply with all applicable privacy and security laws in the course of performing its obligations hereunder and that it will maintain policies, procedures and documentation necessary to demonstrate such compliance.

13.2 The parties acknowledge that monetary damages alone may be inadequate to remedy certain breaches of this Agreement and that the non-breaching party may seek injunctive or equitable relief in addition to any other remedies available at law or in equity.

SIGNATURES

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What a Business Associate Agreement for Contractors Is and When it Applies

A Business Associate Agreement for Contractors is a written contract between a covered entity and a contractor (business associate) that creates specific obligations when the contractor will create, receive, maintain, or transmit protected health information (PHI). The agreement defines permitted uses and disclosures of PHI, requires administrative, physical, and technical safeguards, mandates breach notification procedures, sets subcontractor obligations, and addresses return or destruction of PHI at termination. For contractors engaged by healthcare providers, payers, or other covered entities, a signed BAA is a regulatory prerequisite to avoid HIPAA compliance gaps and to document allocation of risk and duties between parties.

Why a Contractor BAA Matters for Compliance and Risk Management

A clear, signed BAA reduces regulatory exposure, documents required safeguards, and establishes breach response obligations. It creates enforceable contractual obligations that align with HIPAA duties and supports audits, risk assessments, and vendor oversight.

Why a Contractor BAA Matters for Compliance and Risk Management

Who Typically Prepares and Signs a Contractor BAA

The agreement is used by covered entities and contractors who handle PHI; different stakeholders have distinct responsibilities before and after execution.

  • Covered entities and compliance teams ensuring vendor onboarding and regulatory documentation are complete.
  • Contractors, vendors, and subcontractors that receive, process, or store PHI under contract.
  • Legal counsel and privacy officers who negotiate terms and confirm security controls are adequate.

Each party should confirm authorized signatories, review technical safeguards, and document evidence of execution and distribution to relevant operational teams.

Core Provisions to Include in a Professional Contractor BAA

A compliant BAA should be explicit about uses, safeguards, breach obligations, subcontractor flow-downs, termination, and liability allocation to meet HIPAA expectations and operational needs.

Permitted Uses

Specify exact services and purposes for which the contractor may access PHI, and prohibit other uses such as marketing or resale without express consent.

Safeguards

Mandate administrative, physical, and technical protections such as access controls, encryption at rest and in transit, and regular security assessments.

Breach Notification

Require prompt notification to the covered entity upon discovery of a breach, investigate root cause, and cooperate with required notifications and mitigation.

Subcontractor Flow-Down

Obligate the contractor to require compliant written agreements with subcontractors that mirror the BAA obligations and permit audits.

Return or Destruction

Define procedures for returning or securely destroying PHI upon termination, and exceptions for retained backups or legal holds.

Liability and Indemnity

Allocate responsibility for damages, regulatory fines, and costs for breach response, and state any limits on liability or insurance requirements.

Essential Data Elements the BAA Must Contain

Parties: Legal names of Covered Entity and Contractor
Effective Date: MM/DD/YYYY
PHI Description: Types of PHI covered
Permitted Uses: Authorized processing purposes
Security Controls: Required safeguards summary
Breach Contact: Designated incident reporting contact

Step-by-Step: How to Complete and Execute the Contractor BAA

Follow these steps before granting contractors access to PHI to reduce compliance gaps and operational delays.

  • 01
    Assess Need: Confirm why contractor requires PHI and limit scope.
  • 02
    Populate Agreement: Enter accurate party details, services, and effective date.
  • 03
    Review Security: Verify encryption, access controls, and audit capabilities.
  • 04
    Execute & Distribute: Obtain authorized signatures and circulate executed copy to stakeholders.

Where to Send and How to Route the Executed BAA

After execution, distribute copies to legal, compliance, and operational teams and ensure secure storage and access controls.

  • Legal Counsel: Store the signed original for contract audit and dispute purposes.
  • Compliance Officer: Provide copy for vendor risk records and monitoring.
  • Operational Teams: Share relevant redacted terms with system owners.
  • Contractor Records: Ensure contractor retains executed BAA and subcontractor agreements.

Configuring an Online Workflow for BAAs

Set standard fields and authentication options to streamline execution and preserve an auditable trail.

Field Configuration
Authentication Email plus optional SMS or KBA
Audit Trail Enable full timestamps and IP logging
Template Create reusable BAA template with locked clauses
Retention Set automatic archival and export settings

Digital Signing and Technical Requirements for BAAs

Choose a signing platform that supports audit trails, secure storage, and integrations needed for vendor management.

  • Document Formats: PDF, DOCX supported
  • Integrations: Salesforce, NetSuite, Google Workspace
  • Security: TLS 1.2/1.3; AES-256 at rest

Ensure the provider offers HIPAA BAA support, configurable authentication (SMS, KBA, SSO), and preserves machine-readable audit logs for compliance reviews and incident investigations.

Key Timelines and Notification Expectations

Track execution, notification, and review deadlines carefully to maintain compliance and evidence of due diligence.

Execution Before Access:

Execute BAA before contractor accesses PHI

Breach Notification:

Notify covered entity without unreasonable delay; no later than 60 days (HIPAA Breach Notification expectations)

Annual Review:

Perform yearly contract and security control reviews

Subcontractor Flow-Down:

Obtain downstream agreements before subcontractor begins PHI work

Retention Schedule:

Apply retention rules per written records policy

Common Preparation Mistakes to Avoid

  • Leaving PHI scope undefined, which permits broad access and increases exposure during audits and incidents.
  • Failing to include subcontractor flow-down terms, allowing downstream vendors to access PHI without contractual safeguards.
  • Not specifying technical safeguards (encryption, MFA), which can create noncompliance during security reviews.
  • Delaying execution until after access begins, removing the primary documented evidence of consent and obligations.

Consequences of an Incorrect or Missing Contractor BAA

Regulatory Penalties: HIPAA investigations and potential monetary penalties
Contract Damages: Civil liability and indemnity claims
Operational Disruption: Removal of vendor access and remediation costs
Notification Costs: Expenses for breach notifications and monitoring
Loss of Trust: Damage to reputation and client relationships
Criminal Exposure: Potential criminal liability for willful violations

eSignature Vendor Comparison for Executing BAAs

Compare common plan features and compliance posture when choosing an eSignature provider to execute and store BAAs securely.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day trial Yes Yes Yes Yes
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Real-World Examples: BAAs and Compliance in Practice

How organizations used compliant signing platforms to execute contracts and maintain audit evidence across operations.

Fertility Centers of Illinois

Fertility Centers relied on digital execution to ensure compliance and speed.

  • John Butler said the team found the API and support helpful.
  • The result was consistent documentation, easier audits, and timely execution across multiple clinics and devices.

Xerox (NetSuite Operations)

Xerox integrated eSigning with enterprise systems to manage vendor agreements at scale.

  • Kodi-Marie Evans highlighted flexibility and integration benefits.
  • This reduced manual routing, centralized signed BAAs in NetSuite, and improved record retrieval for compliance reviews.

Frequently Asked Questions About Contractor BAAs

Answers to common questions on when a BAA is required, how electronic execution works, and how to manage subcontractors.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users