Establishing secure connection…Loading editor…Preparing document…

Healthcare BAA Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (Agreement) is made and entered into by and between Covered Entity Name: and Business Associate Name: . Effective Date: .

Parties and Contact Information

Recitals and Definitions

WHEREAS, Covered Entity possesses individually identifiable health information that is protected under applicable law, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended; and WHEREAS, Business Associate performs certain services for Covered Entity that require access to Protected Health Information (PHI).

For purposes of this Agreement, the following definitions apply:

PHI means Protected Health Information as defined by HIPAA, including but not limited to demographic information, medical history, treatment information, payment records, and any other information that identifies an individual or for which there is a reasonable basis to believe it can be used to identify an individual.

Permitted Uses and Disclosures

Business Associate may use or disclose PHI only as necessary to perform the services set forth in the underlying service agreement between the parties and as required by law. Business Associate shall not use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity.

For administration, billing, and operational functions on behalf of Covered Entity
For treatment, care coordination, or related healthcare operations
For data aggregation and analytics permitted under HIPAA
Other uses specified:

Business Associate Obligations

Business Associate agrees to:

1. Implement administrative, physical, and technical safeguards appropriate to the size and complexity of its operations and to the nature of PHI, to protect the confidentiality, integrity and availability of PHI, and to prevent impermissible uses or disclosures. Describe specific safeguards maintained:

2. Report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, including breaches of unsecured PHI as required by law, without unreasonable delay and no later than days after discovery.

3. Mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure in violation of this Agreement.

4. Ensure that any subcontractors or agents to whom Business Associate provides PHI agree in writing to the same restrictions and conditions that apply to Business Associate under this Agreement. Subcontractors list or description:

Individual Rights and Requests

Business Associate shall, to the extent it maintains PHI in a Designated Record Set, make PHI available to Covered Entity to satisfy Covered Entity's obligations under HIPAA with respect to access, amendment, and accounting of disclosures. Business Associate shall notify Covered Entity promptly of any request received directly from an individual for access, amendment, or accounting.

Term, Termination and Return or Destruction of PHI

This Agreement shall commence on the Effective Date and shall continue until the underlying services agreement terminates or until terminated as provided herein. Expiration or termination date: .

Upon termination, Business Associate shall, at Covered Entity's election, return or destroy all PHI received from Covered Entity that Business Associate still maintains in any form. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures.

Breach Notification and Cooperation

Business Associate shall cooperate with Covered Entity in any investigation, mitigation, and notification efforts required by law in the event of an unauthorized disclosure or breach. Business Associate shall provide Covered Entity with all information necessary for Covered Entity to comply with notice obligations.

Audit, Inspection and Recordkeeping

Business Associate shall maintain such records as necessary to permit Covered Entity to verify compliance with this Agreement and shall make such records and facilities available to Covered Entity or its designee upon reasonable request and during normal business hours.

Indemnification; Limitation of Liability

Each party shall be responsible for its own acts and omissions. Business Associate agrees to indemnify and hold harmless Covered Entity from liabilities, losses and expenses arising from Business Associate's negligent or willful failure to comply with this Agreement or applicable law, except to the extent such liabilities arise from Covered Entity's actions.

Miscellaneous

Governing Law: .

Notices shall be sent to the addresses set forth above or to any other address designated in writing by a party. Notice to Covered Entity attention: . Notice to Business Associate attention: .

Amendment: The parties agree to take such action as is necessary to amend this Agreement from time to time as required for Covered Entity to comply with the requirements of HIPAA and its implementing regulations.

Attestation

By signing below, the undersigned represent and warrant that they are authorized to execute this Agreement on behalf of their respective parties, and that both parties agree to comply with the terms set forth herein.

Covered Entity - Printed Name:

By:

Date:

Business Associate - Printed Name:

By:

Date:

Enter text✕

What the Healthcare BAA Document Is

The Healthcare BAA Document is a Business Associate Agreement that sets contractual terms between a HIPAA-covered entity and a vendor or partner (business associate) that creates, receives, maintains, or transmits protected health information (PHI). It allocates responsibilities for safeguarding PHI, requires administrative, physical, and technical safeguards, specifies breach notification procedures and timelines, and defines obligations for return or secure destruction of PHI. A clearly written BAA supports HIPAA compliance (45 CFR Part 164), documents liability and remediation steps, and is commonly executed alongside vendor service agreements when PHI access is needed.

Why a Healthcare BAA Document Matters for Compliance

A Healthcare BAA Document records commitments to protect PHI, clarifies each party’s duties, and demonstrates contractual safeguards required by HIPAA. It reduces regulatory risk, sets breach-response expectations, and supports audit readiness for covered entities and business associates.

Why a Healthcare BAA Document Matters for Compliance

Who Prepares and Signs a Healthcare BAA Document

Identify the organizations and roles that typically prepare, review, and execute a Healthcare BAA Document before PHI is shared with a third party.

  • Covered entities such as hospitals, clinics, and health plans that authorize vendors to access patient data.
  • Business associates including billing processors, IT vendors, cloud storage providers, and consultants handling PHI.
  • Legal, compliance, procurement, and IT security teams who review terms and verify vendor safeguards.

Confirm signatory authority and operational contacts up front to prevent delays and ensure PHI exchanges occur only after the BAA is fully executed.

Step-by-Step: Completing a Healthcare BAA Document

Follow a consistent sequence—prepare, populate, review, and sign—to ensure legal terms, security controls, and records are complete and auditable.

  • 01
    Prepare: Gather vendor assessments, scope details, and contact information.
  • 02
    Draft: Populate parties, scope, safeguards, and breach language.
  • 03
    Review: Legal and compliance verify obligations and any state-specific provisions.
  • 04
    Sign: Authorized signatories execute and record the effective date with an audit trail.

How BAA Execution Typically Flows

Execution produces a clear record: drafting with required clauses, review for controls, signer authentication, and archival with audit metadata for later inspections.

  • Draft: Create the BAA including HIPAA-required clauses.
  • Review: Compliance and IT confirm security and scope.
  • Authenticate: Verify signer identity consistent with ESIGN/UETA.
  • Archive: Store final agreement with audit trail and retention tags.

Recommended Online Workflow Settings for BAAs

Configure your digital workflow to capture signer consent, provide adequate authentication, and retain a tamper-evident audit trail suitable for HIPAA and ESIGN compliance.

Field Configuration
Signature Type Typed, drawn, or PKI-based
Authentication Email link, SMS code, or KBA per risk
Audit Trail Store timestamps, IPs, and action logs
Routing Order Sequential or parallel signer order

Platform Capabilities to Verify Before eSigning

Confirm the eSignature provider supports strong transport and storage encryption, a signed HIPAA BAA, and reliable audit trails before executing Healthcare BAAs.

  • Formats: PDF, DOCX supported
  • Integrations: EMR and cloud storage options
  • Authentication: SMS, email, or SSO available

Key Dates to Track for the Healthcare BAA Document

Maintain a schedule for execution, breach reporting, regular reviews, termination processes, and the retention start date to ensure ongoing compliance.

Agreement execution effective date in MM/DD/YYYY format:

Determines when HIPAA obligations and reporting windows begin.

Breach notification trigger and reporting deadline under HIPAA:

Follow HIPAA timelines for notification to affected parties and HHS as required.

Annual vendor review date or periodic reassessment schedule:

Reassess security controls and update contractual terms on material change.

Termination notice period and data return or destruction window:

Specify timeframes to return or securely destroy PHI after termination.

Record retention start date and duration for compliance:

Retention often begins on creation or last effective date per law.

Milestones in the BAA Lifecycle

Track milestone stages from initial drafting through final archival so that responsibilities, approvals, and records are complete and auditable.

01

Drafting and Internal Review

Legal and security teams complete the initial BAA draft and risk assessment.

02

Executive Approval

Authorized approver reviews and signs off on terms and liabilities.

03

Execution and Signature

Parties execute electronically or in writing and record the effective date.

04

Secure Archival

Store executed agreement and certificate of completion for audits.

How a Healthcare BAA Compares with a Data Processing Agreement

BAAs and DPAs overlap but serve different legal frameworks; compare purpose, HIPAA focus, and typical signatories when selecting or drafting templates.

Document Healthcare BAA DPA
Primary purpose protect phi process data
HIPAA focus
Signatories covered entity & ba vendor & controller
Required clauses breach notice, safeguards security, liability

Baseline eSignature Pricing and Compliance Features

Compare basic per-user pricing and essential compliance features that organizations commonly evaluate when selecting an eSignature provider for Healthcare BAAs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (Business Premium) Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Essential Clauses to Include in a Professional Healthcare BAA Document

A complete BAA addresses parties, PHI scope, security safeguards, breach response, permitted uses, and termination to meet HIPAA obligations and reduce ambiguity.

Parties

Identify the covered entity and business associate by full legal name, address, and contact information so responsibilities are unambiguous.

Definitions

Define PHI, permitted disclosures, subcontractor, and breach to ensure consistent interpretation and reduce disputes.

Permitted Uses

Specify exactly what PHI uses are allowed, any permitted disclosures, and limitations to prevent unauthorized processing.

Safeguards

List administrative, physical, and technical safeguards required, including encryption, access controls, and incident response expectations.

Breach Notification

Require prompt notification timelines, content of notices, remediation obligations, and cooperation for investigations.

Termination

Set termination triggers, data return or destruction processes, and surviving obligations for auditing and liability.

Security and Compliance Features to Verify in a BAA Workflow

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3 in transit
Audit Trail: Comprehensive timestamps and IP
Authentication: Email, SMS, SSO options
Certifications: SOC 2 Type II available
HIPAA Support: BAA required and available

Penalties and Risks of an Incorrect or Missing BAA

HIPAA Penalties: Civil fines and corrective actions
Contractual Liability: Indemnity and damages exposure
Breach Costs: Notification, remediation, and forensic fees
Regulatory Audit: HHS investigation and oversight
Service Termination: Vendor or client relationship loss
Reputation: Loss of patient and partner trust

Common Pitfalls When Preparing a Healthcare BAA Document

  • Leaving the scope vague — failing to list specific services and PHI categories can expand liability and enable disputes about permitted uses.
  • Missing required clauses — omitting breach notification, subcontractor flow-down, or data return/destruction provisions undermines HIPAA obligations and audit readiness.
  • Using inconsistent signatory names — mismatched legal entity names or signatory titles can invalidate enforcement and complicate tax or vendor records.
  • Failing to verify platform controls — executing a BAA without confirming encryption, authentication, and a signed BAA from the vendor increases regulatory risk.

Frequently Asked Questions About the Healthcare BAA Document

Answers to common questions on when a BAA is required, what it must contain, electronic signature admissibility, and how to handle vendor changes.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users