Establishing secure connection…Loading editor…Preparing document…

Business Associate Contract

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS ASSOCIATE CONTRACT

This Business Associate Contract (the Agreement) is entered into as of Effective Date: by and between Covered Entity: with principal place of business at and Business Associate: with principal place of business at (each a Party and collectively the Parties).

RECITALS

WHEREAS, Covered Entity creates, receives, maintains or transmits individually identifiable health information that is protected under applicable federal and state privacy and security laws (Protected Health Information); and

WHEREAS, Business Associate provides certain services to Covered Entity and, in connection with those services, will create, receive, maintain or transmit Protected Health Information on Covered Entity’s behalf; and

WHEREAS, the Parties intend to comply with applicable privacy and security requirements and to set forth the Parties’ respective rights and obligations with respect to Protected Health Information.

NOW, THEREFORE, in consideration of the mutual promises and covenants contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:

1. DEFINITIONS

1.1 "Protected Health Information" or "PHI" means individually identifiable health information that is created, received, maintained or transmitted by Business Associate on behalf of Covered Entity, as defined under applicable law.

1.2 "HIPAA Rules" means the standards and requirements of applicable privacy, security and breach notification laws and regulations, as they may be amended from time to time.

1.3 Terms used but not otherwise defined in this Agreement shall have the meanings given them in the HIPAA Rules.

2. PERMITTED USES AND DISCLOSURES

2.1 Business Associate may use or disclose PHI only as necessary to perform the services set forth in the underlying services agreement between the Parties (the Services) or as required by law. Business Associate shall not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity.

2.2 Business Associate may de-identify PHI in accordance with the HIPAA Rules and may use and disclose de-identified information without restriction; provided that Business Associate shall not attempt to re-identify de-identified information.

3. OBLIGATIONS OF BUSINESS ASSOCIATE

3.1 Business Associate shall implement and maintain administrative, physical and technical safeguards appropriate to the size and complexity of its operations and the nature of the PHI, to protect against reasonably anticipated threats to the security or integrity of PHI and to prevent unauthorized uses or disclosures.

3.2 Business Associate shall ensure that any agent, including a subcontractor, to whom it provides PHI agrees in writing to the same restrictions and conditions that apply to Business Associate under this Agreement.

3.3 Business Associate shall, without unreasonable delay and in no event later than days after discovery, report to Covered Entity any Security Incident, actual breach of Unsecured PHI, or other unauthorized use or disclosure of PHI. Such report shall include available details to enable Covered Entity to meet its obligations under applicable law.

4. OBLIGATIONS OF COVERED ENTITY

4.1 Covered Entity shall notify Business Associate of any limitations in the notice of privacy practices, restrictions on uses and disclosures of PHI, or revocation of authorization to the extent such limitations may affect Business Associate’s use or disclosure of PHI.

5. SUBCONTRACTORS

Business Associate shall require that any subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agree in writing to the same restrictions, terms and conditions that apply to Business Associate under this Agreement. Business Associate shall remain liable for the acts and omissions of its subcontractors to the same extent Business Associate would be liable for its own acts and omissions.

6. SECURITY AND RISK MANAGEMENT

Business Associate shall (a) implement reasonable and appropriate policies and procedures to address encryption, access controls, authentication, logging and audit trails; (b) conduct periodic risk assessments; and (c) mitigate, to the extent practicable, any harmful effect known to Business Associate resulting from a use or disclosure of PHI in violation of this Agreement.

7. BREACH RESPONSE AND COOPERATION

7.1 Upon discovery of any unauthorized use or disclosure of PHI, Business Associate shall: (a) take immediate steps to contain and mitigate the unauthorized use or disclosure; (b) conduct an investigation and provide Covered Entity with a written report of findings and corrective actions; and (c) reasonably cooperate with Covered Entity in fulfilling Covered Entity’s legal obligations to notify affected individuals and regulators.

8. TERM AND TERMINATION

8.1 Term. This Agreement shall commence on the Effective Date and shall continue for the duration of the Services or until terminated as provided herein.

8.2 Termination for Cause. Covered Entity may terminate this Agreement upon written notice if Covered Entity determines that Business Associate has materially breached a material provision of this Agreement and such breach is not cured within thirty (30) days of written notice.

8.3 Effect of Termination. Upon termination, Business Associate shall return or destroy all PHI received from Covered Entity that Business Associate still maintains in any form. If return or destruction is not feasible, Business Associate shall extend all protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible.

9. AUDIT; ACCESS TO RECORDS

Business Associate shall make its internal practices, books and records relating to the use and disclosure of PHI available to Covered Entity and to any government authority for purposes of determining compliance with applicable law, subject to confidentiality protections for Business Associate’s proprietary information.

10. INDEMNIFICATION; INSURANCE

10.1 Indemnification. Business Associate shall indemnify, defend and hold harmless Covered Entity from and against any losses, liabilities, damages, costs and expenses (including reasonable attorneys' fees) arising out of Business Associate’s breach of this Agreement or its negligent or willful misconduct.

10.2 Insurance. Business Associate shall maintain, at its own expense, commercially reasonable liability insurance, including cyber liability coverage appropriate to its size and scope of services, and shall provide evidence of such insurance upon Covered Entity’s request.

11. LIMITATION OF LIABILITY

Except as provided in Section 10.1, neither Party shall be liable to the other for incidental, consequential, special or punitive damages arising out of or related to this Agreement, whether in contract, tort or otherwise, except to the extent such limitation is prohibited by applicable law.

12. NOTICES

Notices shall be in writing and delivered by personal delivery, nationally recognized overnight courier, or registered mail, and shall be effective upon receipt.

13. AMENDMENT; WAIVER; COUNTERPARTS

This Agreement may be amended only by a writing signed by both Parties. The failure of either Party to enforce any provision shall not constitute a waiver of future enforcement. This Agreement may be executed in counterparts, each of which shall be deemed an original.

14. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

This Agreement shall be governed by and construed in accordance with the laws of the State of without regard to its conflict of laws principles. This Agreement, together with any referenced exhibits or schedules, constitutes the entire agreement between the Parties with respect to the subject matter hereof. If any provision is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

15. MISCELLANEOUS

15.1 Interpretation. Headings are for convenience only and shall not affect interpretation. The singular includes the plural and vice versa.

15.2 Survival. The respective rights and obligations of the Parties under Sections 3, 7, 8.3, 9, 10 and 14 shall survive termination of this Agreement.

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What a Business Associate Contract Is and when it applies

A Business Associate Contract is a written agreement used when a covered entity shares protected health information (PHI) or other regulated data with a vendor or third party acting on its behalf. The contract defines permitted uses and disclosures, required administrative, physical, and technical safeguards, breach notification obligations, subcontractor obligations, and procedures for return or destruction of PHI at termination. It documents responsibilities required by federal privacy rules and helps demonstrate the covered entity’s compliance program and risk controls when outsourcing services that involve sensitive information.

Why a clear Business Associate Contract matters

A precise contract clarifies responsibilities, limits liability, and sets minimum security and reporting standards between parties.

Why a clear Business Associate Contract matters

Typical parties that prepare or sign this agreement

Who completes this contract depends on organizational role and whether PHI or other regulated data is exchanged.

  • Covered entities and their in-house compliance teams who retain vendors for health-related services.
  • Business associates such as billing firms, cloud providers, data processors, and subcontractors handling PHI.
  • Legal counsel and procurement teams responsible for vendor risk assessments and contract negotiation.

Use the contract as a standard template for vendors handling data, then customize per service, risk, and jurisdiction.

Who signs and their authority

Authorized Official

Typically a senior officer or compliance lead at the covered entity with authority to bind the organization. This signer certifies that the organization requires the vendor to meet privacy and security obligations and can approve termination for material breaches.

Business Associate

An executive or authorized representative of the vendor who can commit the company to required safeguards, subcontractor flow-downs, and breach notification timelines. Signing binds the vendor to contractual and regulatory duties.

Core clauses to include in a professional Business Associate Contract

A comprehensive contract groups legal duties, security controls, reporting obligations, permitted uses, subcontractor rules, and termination rights to reduce ambiguity and support compliance.

Permitted Uses

Define exactly how PHI may be used or disclosed, including any limited purposes and prohibitions on further disclosure beyond the contract.

Safeguards

Specify minimum administrative, physical, and technical safeguards required of the business associate to protect PHI and other regulated data.

Breach Notification

Detail the timeline, required content, and escalation path for reporting suspected breaches to the covered entity and regulators.

Subcontractors

Require flow-down obligations so subcontractors meet the same privacy and security standards and allow for vendor attestations or audits.

Return or Destruction

Obligate the business associate to return or securely destroy PHI at contract end, and specify exceptions for retention.

Term and Termination

Include termination for material breach, cure periods, and post-termination obligations such as data return and transition assistance.

Step-by-step: complete and execute the contract

Follow these sequential steps to prepare, review, and execute a compliant Business Associate Contract with electronic signatures.

  • 01
    Prepare draft: Insert party names, effective date, and service-specific terms.
  • 02
    Internal review: Have legal and security teams review obligations and controls.
  • 03
    Vendor acceptance: Send draft to vendor for review and mark negotiated changes.
  • 04
    Execute and retain: Sign, date, and store the fully executed contract with audit trail.

Typical eSignature workflow for the contract

Use a secure eSignature workflow to collect signatures, preserve an audit trail, and maintain a tamper-evident final copy for audits.

  • Upload document: Import the finalized agreement as PDF or DOCX to the eSignature platform.
  • Place fields: Add signature, date, and initial fields for each signer and any conditional items.
  • Authenticate signer: Use email link, SMS code, or stronger authentication as required.
  • Capture audit trail: Record timestamps, IP addresses, and actions for future verification.

Recommended eSignature settings for Business Associate Contracts

Configure workflow settings to strengthen identity, preserve evidence, and support compliance reporting.

Authentication method Email link with optional SMS OTP for added assurance
Field types and placement Signature, printed name, date, and checkbox for BAAs
Conditional logic Show additional clauses when vendor stores PHI offsite
Bulk send options Use bulk send for standard vendor onboards
Audit trail retention Retain full certificate with signed PDF

Platform and format considerations for secure execution

Prefer platforms that provide tamper-evident signed PDFs, detailed audit trails, and enterprise integrations to automate retention and access controls.

  • Integrations: Salesforce, NetSuite, Google Workspace supported
  • File formats: PDF and DOCX export with embedded audit trail
  • Authentication: SMS OTP, SSO, and advanced options

Security and compliance items to verify in the contract

PHI Handling: Define permitted processing and storage locations
BAA Requirement: Business associate agreement must be in place
Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Access Controls: Role-based access and least privilege
Audit Logs: Maintain comprehensive activity records
Incident Response: Defined notification and mitigation process

Common mistakes to avoid when preparing the contract

  • Using vague language for permitted uses, which can permit overbroad data processing and complicate compliance reviews.
  • Failing to require subcontractor flow-downs, leaving downstream processors unbound by the same privacy obligations.
  • Omitting a clear breach notification timeline, which delays incident response and increases regulatory risk and exposure.
  • Not aligning retention and return/destruction clauses with your records retention policy and applicable federal or state rules.

Potential penalties and risks from an inadequate contract

Regulatory Fines: Civil penalties and enforcement actions
Contract Liability: Indemnity and damages exposure
Data Breach Costs: Notification and remediation expenses
Operational Disruption: Forced suspension or remediation of services
Reputational Harm: Loss of customer trust and contracts
Termination Risk: Immediate contract termination for material breach

Typical timelines and notice periods to set in the agreement

Document clear timelines for effectiveness, notice, reporting, and termination so both parties understand response obligations and windows.

Effective Date:

Contract takes effect on the agreed MM/DD/YYYY execution date

Notice to Cure:

Allow typically 30–60 days to cure a material breach

Breach Reporting Window:

Require prompt reporting; many programs use a 60-day target

Record Retention Start:

Retention runs from creation or last effective date

Termination Notice Period:

Specify 30–90 days unless immediate termination is warranted

Real-world examples of Business Associate Contract use

These short case arcs illustrate why clear contract language and secure eSignature workflows are important in practice.

Fertility Centers of Illinois

A healthcare provider needed consistent vendor agreements to protect patient records and meet audits.

  • They required secure remote signing and detailed audit logs.
  • By standardizing the agreement and using an eSignature solution with strong audit trails, the center reduced turnaround times and improved compliance evidence for regulators and payers.

Martin Properties

A property management firm required vendor access to sensitive tenant records and medical accommodation forms.

  • They needed rapid signature collection across dispersed teams.
  • Implementing standardized contracts with clear PHI limits and secure electronic execution allowed the firm to onboard vendors faster while preserving record integrity and tenant privacy.

Baseline pricing and feature comparison for common eSignature vendors

Compare starting prices, trial availability, bulk send, audit trails, HIPAA alignment, and envelope caps across leading vendors.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day trial No No Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Common questions about Business Associate Contracts

Answers to frequent questions on necessity, signing, enforcement, eSign validity, and post-termination handling.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users