Establishing secure connection…Loading editor…Preparing document…

GSA BAA Legal Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

GSA BAA LEGAL AGREEMENT

This GSA Broad Agency Announcement (BAA) Legal Agreement (the "Agreement") is entered into as of Effective Date: by and between Government Agency: with principal place of business at , and Contractor Name: with principal place of business at . Government Agency and Contractor are each a "Party" and together the "Parties."

RECITALS

WHEREAS, Government Agency issued or will issue a Broad Agency Announcement (BAA) referenced as BAA Number: , inviting proposals for research and development projects intended to advance the scientific, technical, or management knowledge in areas identified by the Government Agency; and

WHEREAS, Contractor submitted a proposal titled Project Title: (the "Proposal") in response to the BAA and the Parties desire to set forth their respective rights and obligations with respect to the proposed work and resulting deliverables; and

WHEREAS, funding and performance under this Agreement shall be subject to availability of appropriations and any express conditions set forth in this Agreement;

NOW, THEREFORE, in consideration of the mutual covenants and agreements contained herein, the Parties agree as follows:

1. DEFINITIONS

For purposes of this Agreement, the following terms shall have the meanings set forth below:

"Deliverables" means all reports, data, documentation, software, prototypes, inventions, and other tangible or intangible items to be delivered by Contractor to Government Agency pursuant to the Statement of Work.

"Background Intellectual Property" means intellectual property, including inventions, patents, copyrights, and trade secrets, owned or controlled by a Party prior to the Effective Date or independently developed outside the performance of this Agreement.

"Foreground Intellectual Property" means intellectual property conceived, developed or first reduced to practice in the performance of this Agreement.

2. SCOPE OF WORK

Contractor shall perform the work described in the Statement of Work attached as Attachment A and incorporated herein by reference. The Statement of Work shall identify specific tasks, milestones, and Deliverables. The Contractor shall perform the work in accordance with sound scientific and industry practices and the schedule set forth in Attachment A.

3. PERIOD OF PERFORMANCE

The performance period shall commence on Start Date: and end on End Date: , unless earlier terminated pursuant to the terms of this Agreement.

4. FUNDING AND PAYMENT

Subject to the availability of appropriated funds, Government Agency shall pay Contractor up to Funding Amount (Total): $ for performance of the work described in Attachment A. Payments shall be made in accordance with the payment schedule set forth in Attachment A and upon submission of properly prepared invoices and supporting documentation. Unless otherwise stated, invoices shall be paid within thirty (30) calendar days of the Government Agency's receipt and approval of an undisputed invoice.

5. INTELLECTUAL PROPERTY AND PATENT RIGHTS

Ownership of Foreground Intellectual Property shall vest in Contractor unless otherwise expressly agreed in writing. Contractor hereby grants Government Agency a nonexclusive, irrevocable, royalty-free license to use, reproduce, prepare derivative works of, distribute copies of, and publicly display Foreground Intellectual Property for Governmental Purposes. "Governmental Purposes" means use for any government activity, including research, demonstration, evaluation, or acquisition, but does not include commercial exploitation by third parties outside Government Agency absent a separate license.

If either Party elects to file for patent protection on a Foreground Invention, the electing Party shall provide written notice to the other Party within sixty (60) days of such election. The Parties shall cooperate in the protection and prosecution of patents, including executing necessary assignments and instruments, subject to allocation of costs as set forth in Attachment A.

6. DATA RIGHTS AND TECHNICAL DATA

Contractor shall identify and mark all technical data and software submitted to Government Agency that Contractor asserts to be limited rights data or contain proprietary restrictions. Except as expressly provided in this Agreement, Contractor grants Government Agency and its authorized representatives Government Purpose Rights in Deliverables, including the right to use, reproduce, perform, modify, release, disclose, or distribute the Deliverables within the Government. Use or disclosure outside the Government will be subject to Contractor's asserted restrictions and any applicable statutory or regulatory requirements.

7. CONFIDENTIALITY

Each Party shall maintain in confidence and shall not disclose to any third party Confidential Information received from the other Party. "Confidential Information" means information that is clearly identified as confidential at the time of disclosure or which, by its nature, should reasonably be considered confidential. Confidential Information shall be held in confidence for a period of five (5) years from the date of disclosure, except for trade secrets which shall be protected for as long as they qualify as trade secrets under applicable law.

8. PUBLICATION

Contractor may seek to publish results of the work performed under this Agreement. Contractor shall provide Government Agency with copies of proposed manuscripts or presentation materials at least sixty (60) calendar days prior to submission or public disclosure to permit review for confidential, proprietary, or Government-sensitive information and for identification of potential patentable subject matter. Neither Party shall unreasonably withhold authorization for publication; however, Government Agency may request redaction of specific information to protect confidentiality, national security, or patent interests.

9. COMPLIANCE WITH LAWS AND REGULATIONS

Contractor shall comply with all applicable federal statutes and regulations in the performance of this Agreement, including those relating to export controls, human subjects research, privacy, conflict of interest, and procurement integrity. Contractor shall obtain all permits, approvals, and licenses required to perform the work and shall notify Government Agency promptly of any compliance investigations or enforcement actions related to performance under this Agreement.

10. REPRESENTATIONS AND WARRANTIES

Contractor represents and warrants that: (a) it has full power and authority to enter into this Agreement; (b) the performance of the work and the Deliverables will not knowingly infringe third-party intellectual property rights; and (c) Deliverables will conform to the specifications set forth in Attachment A and be free from material defects in workmanship or design for a period of ninety (90) days following acceptance, unless otherwise stated.

11. INDEMNIFICATION AND LIMITATION OF LIABILITY

Contractor shall defend, indemnify and hold harmless Government Agency from and against any third-party claims arising out of Contractor's negligent acts, willful misconduct, or breach of this Agreement, provided Government Agency gives prompt written notice of any claim and cooperates in the defense. Neither Party shall be liable to the other for incidental, consequential, special, or punitive damages except in cases of gross negligence or willful misconduct.

12. INSURANCE

Contractor shall maintain insurance coverage customary for the performance of the work, including commercial general liability and, where applicable, professional liability and workers' compensation. Specific insurance types and minimum limits, if required by Government Agency, shall be set forth in Attachment A.

13. TERMINATION

Government Agency may terminate this Agreement for convenience upon thirty (30) calendar days' prior written notice. Either Party may terminate for material breach if such breach is not cured within thirty (30) calendar days after written notice. Upon termination, Contractor shall deliver all completed Deliverables and invoices for costs incurred through the effective date of termination. Payment for work performed prior to termination shall be limited to that portion of the work satisfactorily performed and documented.

14. NOTICES

All notices under this Agreement shall be in writing and shall be delivered by hand, certified mail (return receipt requested), or nationally recognized overnight courier to the addresses set forth below or such other address as a Party designates in writing.

15. AMENDMENTS; WAIVER

This Agreement may be amended only by a written instrument signed by authorized representatives of both Parties. No failure or delay by either Party in exercising any right shall operate as a waiver of that right, and no waiver shall be effective unless in writing and signed by the Party granting the waiver.

16. COUNTERPARTS AND ELECTRONIC SIGNATURES

This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument. The Parties agree that electronic signatures shall have the same force and effect as original signatures.

17. GOVERNING LAW; SEVERABILITY; ENTIRE AGREEMENT

This Agreement shall be governed by and construed in accordance with the laws of the State of , without regard to conflict of laws principles. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect. This Agreement, including all Attachments, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior discussions, understandings, or agreements.

18. MISCELLANEOUS

Contractor shall not assign or subcontract performance of this Agreement in whole or in part without the prior written consent of Government Agency. Any permitted subcontracting shall not relieve Contractor of its obligations under this Agreement. The Parties shall cooperate in good faith to effectuate the purpose of this Agreement.

Government Agency:

By:

Date:

Contractor:

By:

Date:

Enter text✕

What the GSA BAA Legal Agreement Covers

A GSA BAA Legal Agreement is a written contract used when a vendor or subcontractor will create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity associated with General Services Administration (GSA) work. The agreement defines permitted uses, required safeguards, breach notification obligations, and flow-down duties for subcontractors. When PHI is involved, the Business Associate Agreement must align with HIPAA requirements and be kept with contract records; where electronic execution is used, ESIGN (15 U.S.C. ch. 96) and applicable state e-signature law validate electronic signatures.

Why a GSA BAA Legal Agreement Matters

The GSA BAA clarifies responsibilities for PHI handling, reduces legal and contractual ambiguity, and documents required safeguards and breach procedures to meet HIPAA obligations while enabling federal procurement workflows.

Why a GSA BAA Legal Agreement Matters

Who typically completes a GSA BAA

Typical parties and users involved in preparing and signing a GSA BAA include procurement, legal, and privacy teams on both sides.

  • Healthcare organizations and clinics that subcontract services tied to federal programs.
  • Cloud and IT vendors storing or processing PHI under a GSA contract.
  • Contracting officers, privacy officers, and procurement specialists managing GSA acquisitions.

Final execution usually requires an authorized contracting officer or designated signatory for the government party and an officer or authorized representative for the vendor.

Core elements to include in a professional GSA BAA

A robust GSA BAA is explicit about PHI scope, permitted uses, security obligations, breach response, data return/destruction, audit rights, and subcontractor flow-down requirements to protect individuals and meet federal privacy standards.

Parties

Identify the covered entity, the business associate, and any subcontractors; include full legal names and addresses for contracting and notice purposes.

PHI Scope

Define types of PHI covered, sources of PHI, and the specific services that require access so responsibilities and limits are unambiguous.

Permitted Uses

List expressly permitted and prohibited uses and disclosures of PHI, including any uses required to perform GSA tasks or fulfill contractual obligations.

Security Requirements

Specify administrative, physical, and technical safeguards required (encryption, access controls, audit logs) and any NIST or agency standards to follow.

Breach Obligations

State notification timing and content, investigation duties, cooperation with the covered entity, and reporting to HHS or other authorities as applicable.

Subcontractors

Require BAAs or flow-down provisions with subcontractors and set audit/monitoring rights to ensure downstream compliance.

Required security and compliance data points

Encryption: TLS 1.2/1.3; AES-256 at rest
Certifications: SOC 2 Type II; ISO 27001
HIPAA Status: BAA required for PHI processing
eSignature Law: ESIGN and UETA compliance
Audit Trail: Timestamp, IP, action log
21 CFR: 21 CFR Part 11 where applicable

Step-by-step: completing a GSA BAA

Follow a concise sequence to prepare, review, and execute the BAA so it aligns with the GSA contract and HIPAA obligations.

  • 01
    Gather documents: Collect contract, statement of work, and vendor security documentation.
  • 02
    Draft terms: Define PHI scope, permitted uses, and safeguards.
  • 03
    Legal review: Have counsel verify HIPAA alignment and government clause compatibility.
  • 04
    Execute: Obtain signatures from authorized officials and distribute copies to stakeholders.

How to configure an online BAA workflow

Configure document fields and authentication to match contract rules, signer authority, and PHI-protection needs before sending for signature.

Field Configuration
Signer Authentication Use email+SMS code or higher for vendor and contracting officer
Access Control Limit document visibility to named signers and reviewers
Audit Trail Enable full timestamp and IP logging
Retention Setting Retain executed copy per agency recordkeeping rules

Where to send a completed GSA BAA

After execution, route the signed BAA to both contracting and privacy stakeholders and store the final copy where contract records are kept.

  • Contracting Officer: Deliver executed copy to the GSA contracting officer on file
  • Privacy Office: Send a copy to the agency privacy or HIPAA compliance office
  • Vendor Records: Retain executed BAA in vendor contract repository
  • Shared Archive: Store a copy in the contract management system with restricted access

Distribution and technical delivery options

Choose distribution channels that preserve audit trails and control access to PHI.

  • File formats: PDF and DOCX are standard for signed BAAs
  • Integrations: CRM and contract systems: Salesforce, NetSuite, Microsoft 365, Google Workspace
  • Authentication: Email, SMS, KBA or advanced signer verification

Key timelines and notification expectations

Understand statutory and contract timelines for execution, breach notification, and record retention to avoid compliance gaps.

Execution Window:

Execute BAA before starting PHI-related work

Breach Notice:

Notify covered entity without unreasonable delay; HHS reporting often within 60 days

Audit Access:

Allow covered-entity audits per contract terms and reasonable notice

Record Retention:

Retain executed BAA per agency and HIPAA retention rules

Subcontractor Flow-down:

Require BAAs with subcontractors before subcontracted PHI processing

Common mistakes to avoid when preparing a GSA BAA

  • Failing to define the exact categories of PHI that will be accessed or processed, creating ambiguity about permitted uses and safeguards.
  • Using an unauthorized signatory or failing to confirm contracting officer approval, which can render execution invalid under government rules.
  • Omitting subcontractor flow-down terms or failing to obtain BAAs from downstream vendors, leaving gaps in PHI protection obligations.
  • Not aligning the BAA with the underlying GSA statement of work and security annex, causing conflicts between contract and privacy obligations.

Penalties and operational risks of an incorrect or missing BAA

HIPAA Penalties: Civil monetary penalties and enforcement actions for HIPAA violations
Contract Termination: Risk of government contract suspension or termination
Indemnity Exposure: Vendor may bear loss allocation and defense costs
Data Breach Costs: Breach response and remediation expenses
Debarment Risk: Serious noncompliance can affect federal procurement eligibility
Reputational Harm: Loss of trust with agency stakeholders and partners

Estimated eSignature vendor comparison for BAAs and PHI workflows

Compare basic pricing and core capabilities when choosing an eSignature solution for BAA execution, noting HIPAA support and envelope or session limits.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day free trial Yes Yes Yes Yes
Bulk Send Yes Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Common questions about GSA BAAs and electronic execution

Answers to frequent questions covering enforceability, HIPAA obligations, signature authority, and handling updates to an executed BAA.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users