Establishing secure connection…Loading editor…Preparing document…

Healthcare BAA Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS ASSOCIATE AGREEMENT (BAA)

This Business Associate Agreement ("Agreement") is entered into by and between the parties identified below for the purpose of ensuring compliance with applicable federal and state laws governing the privacy and security of Protected Health Information. The parties agree as follows.

Parties and Effective Date

     

     

Effective Date:     Term / Duration (months):     Agreement Expiration Date:

Definitions

For purposes of this Agreement: "Protected Health Information" or "PHI" means individually identifiable health information, whether oral, written, or electronic, that is created, received, maintained or transmitted by or on behalf of the Covered Entity and is protected under applicable law.

"Electronic PHI" or "ePHI" means PHI transmitted or maintained in electronic form. Terms used but not otherwise defined will have the meanings ascribed under governing privacy and security laws applicable to the Covered Entity.

Permitted Uses and Disclosures

Business Associate may use and disclose PHI only as necessary to perform the following services on behalf of the Covered Entity and as otherwise permitted by this Agreement:

        

Obligations of Business Associate

Business Associate shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of PHI, including measures to protect against any reasonably anticipated threats or hazards to the security of such information.

Business Associate will only create, receive, maintain or transmit PHI as required to perform services under this Agreement. Business Associate will not use or disclose PHI in any manner that would violate applicable law if done by the Covered Entity.

Breach Notification

Business Associate shall report to the Covered Entity any use or disclosure of PHI not permitted by this Agreement, including suspected or confirmed breaches of unsecured PHI. Notification shall include a description of the nature of the breach, the PHI involved, corrective actions taken, and steps to mitigate harm.

Required notification timeframe (from discovery):

Use of Subcontractors

Business Associate may engage subcontractors that create, receive, maintain or transmit PHI on its behalf only after obtaining satisfactory assurances, by written contract, that the subcontractor will appropriately safeguard PHI in accordance with this Agreement.

Individual Rights; Access and Amendment

To the extent Business Associate maintains PHI in a designated record set, Business Associate shall make PHI available to the Covered Entity to satisfy Covered Entity's obligations to provide access, copies, and amendment in accordance with applicable law. Business Associate shall cooperate with Covered Entity to respond to requests for accounting of disclosures.

Return or Destruction of PHI

Upon termination of this Agreement, Business Associate shall return to Covered Entity or securely destroy all PHI and retain no copies, unless retention is required by law. If destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible.

Indemnification; Remedies

Each party shall indemnify and hold harmless the other party from and against all losses, liabilities and expenses arising from a material breach of this Agreement by the indemnifying party, subject to limitations set forth in the parties' operative agreement.

The parties acknowledge that monetary damages may be inadequate for certain breaches and agree that equitable relief, including injunctive relief, may be appropriate in addition to any other remedies.

Governing Law; Amendment

This Agreement shall be governed by the laws of the state specified below, without regard to choice-of-law principles. The parties may amend this Agreement only by a written instrument signed by both parties that expressly states that it is an amendment to this Business Associate Agreement.

Notices

Any notice required under this Agreement shall be in writing and delivered to the addresses of the parties set forth below (or to such other address as either party designates in writing).

Miscellaneous Provisions

Survival: The respective rights and obligations of the parties with respect to PHI shall survive termination of this Agreement. Severability: If any provision of this Agreement is held invalid, the remainder shall continue in full force and effect. Headings are for convenience only and shall not affect interpretation.

The parties represent that they have the full right and authority to enter into this Agreement and that the person signing below is authorized to execute this Agreement on behalf of the respective party.

Covered Entity — Printed Name:

By (Signature):

Date:

Business Associate — Printed Name:

By (Signature):

Date:

Enter text✕

What the Healthcare BAA Agreement Is

A Healthcare Business Associate Agreement (BAA) is a written contract required under HIPAA that governs how a business associate may create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity. The BAA sets required administrative, physical, and technical safeguards, limits permitted uses and disclosures, defines breach notification obligations, and assigns responsibilities for subcontractors. It is a binding contract between the covered entity and the vendor, contractor, or partner handling PHI and is critical to meeting HIPAA compliance and privacy obligations under 45 CFR §164.502(e) and §164.530.

Why a Healthcare BAA Agreement Matters

A properly drafted BAA allocates responsibility for PHI protection, clarifies incident reporting timelines, and preserves the covered entity’s ability to enforce HIPAA safeguards. It reduces regulatory risk and documents the parties’ intent to comply with 45 CFR §164.502(e) and §164.530.

Why a Healthcare BAA Agreement Matters

Who Typically Completes a Healthcare BAA Agreement

Organizations that exchange PHI use BAAs to document obligations between covered entities and business associates before work begins.

  • Covered entities: hospitals, clinics, physician practices, health plans, and clearinghouses that must ensure vendor compliance with HIPAA.
  • Business associates: IT vendors, cloud hosts, billing companies, analytics providers, and consultants who create, receive, or transmit PHI.
  • Compliance or legal teams: counsel, privacy officers, and procurement professionals who negotiate terms and record retention rules.

Final signatures should be obtained from authorized representatives and documented prior to any PHI exchange.

Who Signs and Why

Covered Entity Signer

Chief Information Security Officer or authorized executive typically signs on behalf of the covered entity. That signer confirms the entity’s expectations for PHI handling, audit rights, breach notification timing, and termination triggers under HIPAA and internal policies.

Business Associate Signer

An officer or authorized contract signatory for the vendor signs to accept obligations including safeguards, subcontractor flow-downs, breach response, and cooperation with audits; signature confirms legal responsibility for PHI under the BAA terms.

Essential Data and Security Clauses to Include

Parties: Full legal names of covered entity and business associate
Scope: Specific services involving PHI
Safeguards: Administrative, physical, and technical controls
Breach Notice: Timing and contact for notifications
Subcontractors: Flow-down obligations to subcontractors
Termination: Data return, destruction, and disposition method

Key Components of a Professional Healthcare BAA Agreement

A comprehensive BAA covers responsibilities, permitted uses, required safeguards, breach procedures, audit rights, and data disposition. Each element should be explicit to avoid ambiguity and to satisfy HIPAA requirements.

Permitted Uses

Specify exactly which operations or functions the business associate may perform with PHI and prohibit any other uses or disclosures not expressly permitted by the covered entity.

Safeguards Required

Detail administrative, physical, and technical measures the business associate must implement, including access controls, encryption, logging, and vulnerability management practices.

Breach Notification

Define breach reporting timelines, evidence required for the report, cooperative investigation responsibilities, and obligations for notifying affected individuals and regulators.

Subcontractor Flow-Down

Require business associates to contractually bind subcontractors to the same BAA terms and to maintain oversight of their compliance and security practices.

Audit and Inspection Rights

Grant the covered entity the right to request documentation, security assessments, and access to records or to conduct audits consistent with HIPAA compliance needs.

Data Return and Destruction

Specify when PHI must be returned or securely destroyed at termination, including acceptable destruction methods and certification of destruction.

Step-by-Step: How to Complete the Healthcare BAA Agreement

Follow a consistent sequence: prepare, review, sign, and retain. Each step helps ensure the BAA is enforceable, addresses PHI handling, and aligns with HIPAA obligations.

  • 01
    Prepare: Gather vendor legal name, scope of services, and security contact information.
  • 02
    Review: Legal and compliance review for required HIPAA clauses and risk allocations.
  • 03
    Sign: Authorized representatives sign and date the agreement; preserve signature evidence.
  • 04
    Retain: Store the executed BAA with contract records and track retention deadlines.

How Electronic Completion and Routing Typically Work

Electronic workflows streamline execution while capturing an audit trail. Ensure the platform supports required authentication and retention for legal validity.

  • Upload: Sender uploads the BAA document to the eSignature platform.
  • Field Placement: Place signature, printed name, title, and date fields for each signer.
  • Authentication: Configure signer authentication such as email link, SMS code, or advanced methods.
  • Completion: Signers execute the document and receive a signed copy plus certificate of completion.

Recommended eSignature Workflow Settings

Use these settings to balance signer convenience with legal assurance and auditability for BAAs.

Field Configuration
Signature Type Visible signature + audit trail
Authentication Email plus SMS code where possible
Retention Retain signed PDF and audit trail for minimum federal period
Access Controls Role-based access and SSO for administrators

Platform Capabilities to Verify Before eSigning

Confirm technical and compliance features that matter for BAAs and PHI.

  • Security: AES-256 at rest; TLS 1.2/1.3 in transit
  • Compliance: HIPAA support with a BAA available
  • Integrations: Connectors for EHR, cloud storage, and identity providers

Retain audit trails, signed PDFs, and access logs to support audits and breach investigations.

Timelines, Deadlines, and Processing Expectations

Track key dates for execution, breach notifications, and retention to meet regulatory obligations and preserve enforcement rights.

Execution Before PHI Exchange:

Sign BAA before any PHI is shared; failure risks noncompliance

Breach Notification Timing:

Prompt reporting as defined by the BAA and HIPAA rules

Retention Start Date:

Retention begins on the effective date or creation of records

HIPAA Retention Minimum:

Maintain records for at least 6 years (45 CFR §164.530(j))

Contract Review Cycle:

Reassess BAA terms annually or when services change

Common Mistakes to Avoid When Preparing a BAA

  • Using vague service descriptions that fail to limit permitted uses of PHI and create enforcement gaps.
  • Failing to require subcontractor flow-downs, leaving secondary processors uncontracted and unmanaged.
  • Omitting specific breach response procedures or contact details, delaying notification and remediation.
  • Neglecting signature authority checks, resulting in agreements signed by unauthorized representatives.

Penalties and Legal Risks of an Incorrect or Missing BAA

HIPAA Violations: Civil penalties and corrective action plans
Breach Liability: Potential damages and remediation costs
Regulatory Fines: OCR enforcement and monetary penalties
Contract Disputes: Loss of contractual protections and indemnities
Reputational Harm: Loss of patient trust and business impact
Operational Risk: Service disruption from remediation and audits

Sample eSignature Pricing and Feature Comparison

Compare basic pricing and core features relevant to Healthcare BAA execution. signNow is listed first per vendor comparison conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (Business Premium) Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions About the Healthcare BAA Agreement

Answers to common questions about when a BAA is required, eSignature validity, and recordkeeping for healthcare contracts.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users