Establishing secure connection…Loading editor…Preparing document…

Healthcare BAA Form

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS ASSOCIATE AGREEMENT (BAA)

Parties and Effective Date

Covered Entity Name:

Business Associate Name:

Effective Date:

Recitals and Definitions

This Agreement is entered into by and between the Covered Entity and the Business Associate identified above to ensure appropriate safeguards for protected health information. In consideration of the mutual promises below, the parties agree as follows.

Definitions: For purposes of this Agreement, the following terms shall have the meanings set forth below. "Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form that is created or received by the Business Associate from or on behalf of the Covered Entity. "Security Rule" and "Privacy Rule" refer to the applicable federal standards governing protection of PHI as they exist under applicable law.

Permitted Uses and Disclosures of PHI

The Business Associate may create, receive, maintain or transmit PHI on behalf of the Covered Entity only as reasonably necessary to perform the following services:

Treatment    Payment    Healthcare Operations    Administrative Services

The Business Associate shall not use or disclose PHI except as permitted by this Agreement or as required by law. Any use or disclosure not described herein requires prior written authorization from the Covered Entity.

Safeguards; Security Measures

The Business Associate shall implement and maintain administrative, physical and technical safeguards appropriate to the size and complexity of its operations and the nature of PHI handled, including without limitation:

- Access controls, authentication, and role-based access principles; encryption of PHI in transit and at rest where feasible; routine workforce training on privacy and security obligations; secure disposal and destruction procedures for PHI; and documented policies for incident response and business continuity.

Breach Notification and Cooperation

The Business Associate shall notify the Covered Entity of any security incident or unauthorized use or disclosure of PHI as soon as practicable, and in no event later than seventy-two (72) hours after the Business Associate becomes aware of such incident, unless a shorter time is required by applicable law. Notification shall include available details concerning the nature of the breach, the PHI involved, steps taken to mitigate harm, and contact information for further inquiries.

The Business Associate shall cooperate with the Covered Entity in any required notifications to affected individuals, regulators, or other third parties and shall provide documentation of corrective actions and remediation when requested.

Subcontractors and Agents

The Business Associate shall ensure that any subcontractor or agent that creates, receives, maintains or transmits PHI on behalf of the Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to the Business Associate under this Agreement. The Business Associate shall remain fully liable for any acts or omissions of such subcontractors or agents that would constitute a breach of the Business Associate's obligations if committed by the Business Associate.

Access, Amendment, and Accounting

The Business Associate shall make PHI available as necessary to satisfy Covered Entity obligations to provide access, amendment, or an accounting of disclosures to individuals as required by applicable law. The Business Associate shall cooperate with the Covered Entity and timely provide information or take actions requested by the Covered Entity to enable the Covered Entity to comply with such obligations.

Record Retention; Return or Destruction

Upon termination or expiration of this Agreement, the Business Associate shall, at the Covered Entity's option, return to the Covered Entity or destroy all PHI received from the Covered Entity. If return or destruction is not feasible, the Business Associate shall extend all protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible.

Term, Termination, and Expiration

This Agreement shall remain in effect from the Effective Date until the earlier of: (a) the date specified as the expiration date below; (b) termination by either party for cause upon thirty (30) days' written notice if the other party materially breaches any provision of this Agreement and fails to cure within such period; or (c) termination by mutual written agreement.

Expiration Date:

Audit, Inspection and Records

The Business Associate shall make its internal practices, books and records available to the Covered Entity and to regulatory authorities for purposes of determining compliance with this Agreement and applicable law. The Business Associate shall promptly provide copies of relevant records upon request by the Covered Entity.

Liability, Indemnity and Insurance

The Business Associate shall indemnify and hold harmless the Covered Entity from and against any losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from the Business Associate's breach of this Agreement or unauthorized use or disclosure of PHI, except to the extent caused by the Covered Entity's negligence or willful misconduct. The Business Associate shall maintain appropriate liability insurance covering privacy and security incidents.

Miscellaneous

Amendment: This Agreement may be amended only by written agreement signed by both parties. Governing Law: This Agreement shall be governed by the laws of the state specified below without regard to conflict of laws principles. Severability: If any provision is held invalid, the remaining provisions shall remain in effect. No Third-Party Beneficiaries: This Agreement does not create any third-party beneficiary rights.

Acknowledgments and Certifications

Each party certifies that it shall comply with the terms of this Agreement and the requirements of applicable law governing the use, disclosure and safeguarding of PHI. Each party further certifies that its signatory is authorized to execute this Agreement on behalf of the respective party.

Representations

The Business Associate represents that it will comply with all applicable privacy and security requirements and will only access, use or disclose PHI in the manner and to the extent necessary to perform the services set forth in this Agreement. The Business Associate further represents that it maintains policies and procedures reasonably designed to ensure compliance.

Covered Entity Printed Name:

By:

Date:

Business Associate Printed Name:

By:

Date:

Enter text✕

What the Healthcare BAA Form Is and when it applies

A Healthcare BAA Form (Business Associate Agreement) is a written contract between a HIPAA-covered entity and a business associate that creates, receives, maintains, or transmits protected health information (PHI). The BAA defines permitted uses and disclosures of PHI, requires safeguards to protect PHI, and allocates responsibilities for breach notification, reporting, and mitigation. Federal HIPAA regulations require covered entities to have a BAA with any vendor who handles PHI on their behalf; absent a valid BAA, a covered entity can face regulatory and contractual exposure.

Why a clear, compliant BAA matters

A properly completed Healthcare BAA Form documents legal duties for PHI protection, supports HIPAA compliance, clarifies breach responsibilities, and provides contractual proof for regulators and auditors.

Why a clear, compliant BAA matters

Who needs to complete or sign a Healthcare BAA Form

The BAA is used when a covered entity delegates PHI handling to a vendor or partner.

  • Covered entities and providers — hospitals, clinics, physician practices, and health plans that outsource services involving PHI.
  • Business associates — vendors such as billing companies, cloud service providers, IT support, and medical record processors handling PHI.
  • Downstream subcontractors — third parties of business associates who will access PHI under a subcontract requiring flow-down BAA terms.

All parties should ensure authorized signatories and effective dates are recorded to create an enforceable agreement.

Typical signatories and their roles

Covered Entity Executive

A chief privacy officer, general counsel, or authorized executive signs on behalf of the covered entity and confirms the organization will only disclose PHI as permitted and will require the business associate to implement required safeguards.

Business Associate Officer

A chief compliance officer, general counsel, or authorized company officer signs for the vendor, accepting obligations to implement administrative, physical, and technical safeguards and to notify the covered entity of breaches.

Security and compliance elements to include

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3
Certifications: SOC 2 Type II
HIPAA Status: BAA required
Audit Trail: Immutable logs
Access Controls: Role-based authentication

Primary legal and operational risks of an incomplete BAA

HIPAA Violations: Civil and criminal penalties
Breach Liability: Notification and remediation costs
Contract Risk: Indemnity gaps
Regulatory Fines: OCR enforcement actions
Reputational Harm: Loss of trust
Operational Disruption: Service interruption

Common preparation and execution pitfalls

  • Failing to identify all subcontractors who access PHI, leaving downstream obligations unenforceable and creating compliance gaps.
  • Using boilerplate language that omits breach notification timelines or specific security controls required for the type of PHI processed.
  • Mismatched effective dates or missing authorized signatory names, which can undermine enforceability during audits or breach investigations.
  • Relying on unsigned or unstamped digital copies without a robust audit trail demonstrating intent, attribution, and retention for legal validity.

Step-by-step: how to complete a Healthcare BAA Form

Follow these sequential actions to prepare, review, and execute a compliant BAA with clear responsibilities and documentation.

  • 01
    Identify parties: Record full legal names and entity types.
  • 02
    Describe services: Specify functions involving PHI and permitted uses.
  • 03
    Assign obligations: Include security, breach notice, and return/destruction clauses.
  • 04
    Sign and retain: Obtain authorized signatures and preserve audit records.

Typical electronic workflow for a Healthcare BAA

A standard eSigning flow reduces turnaround while preserving evidence of intent and consent required under ESIGN and UETA.

  • Upload the form: Start with a finalized PDF or Word document.
  • Position fields: Add signature, initial, and date fields where required.
  • Set signer order: Define signers and authentication strength.
  • Capture audit trail: Record timestamps, IP, and verification steps.

Key clauses a professional Healthcare BAA Form should contain

A thorough BAA addresses access, safeguards, breach response, subcontractors, audit rights, and termination to meet HIPAA obligations and practical risk management needs.

Permitted Uses

Clear description of allowed PHI uses and disclosures, limiting processing to functions the business associate performs on behalf of the covered entity and prohibiting unrelated uses.

Safeguards

Specific technical, administrative, and physical safeguards the business associate must maintain, including encryption, access controls, logging, and incident response procedures.

Breach Notification

Breach reporting timeframe and required content, specifying who notifies affected individuals, regulatory bodies, and steps for mitigation and investigation.

Subcontractors

Requirement that the business associate obtain written agreements from all subcontractors imposing the same BAA obligations and permitting audits.

Audit and Access

Covered entity rights to audit, inspect security policies, and require corrective actions, including cooperation for HIPAA compliance reviews and investigations.

Termination and Return

Procedures for termination, return or destruction of PHI, and steps to address residual copies or legal retention obligations.

Practical tips for preparing a compliant BAA

Adopt consistent templates and document controls to lower risk and speed review cycles across vendor relationships.

Use a single, approved BAA template
Maintain a template vetted by legal and privacy teams that includes required HIPAA provisions, breach timelines, and standard security requirements to avoid ad hoc variations during vendor onboarding.
Document authority to sign
Confirm and record the title and authority of signatories to avoid disputes; attach a board resolution or delegation of authority when appropriate to verify signing authority.
Apply minimum necessary principle
Limit PHI exchanged to the minimum necessary for the business function and document permitted data elements explicitly to reduce exposure and simplify compliance oversight.
Track and review subcontractors
Require business associates to provide an up-to-date subcontractor list and evidence of flow-down BAAs; perform periodic risk-based reviews of high-risk vendors.

Timing considerations and key deadlines

Certain timing and retention requirements affect when the BAA takes effect and how long related records must be kept.

Effective date:

Record clearly as MM/DD/YYYY when obligations begin.

Breach notification timeframe:

Report breaches promptly per internal SLAs and regulatory expectations.

Contract review cadence:

Review BAAs annually or upon material service changes.

Record retention:

Maintain execution evidence for regulatory retention periods.

Audit notice period:

Define reasonable notice for audits and inspection access.

eSignature vendor comparison for Healthcare BAAs (overview)

Key vendor differences include starting price, free trial availability, bulk send support, audit trail, and HIPAA compatibility; signNow is listed first per comparison rules.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no credit card Varies Varies Varies Varies
Bulk Send Yes (Business Premium) Varies by plan Varies by plan Varies by plan Varies by plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA required) Yes Yes No No

Configuring an online BAA signing workflow

Set up the workflow to capture intent, authentication, and retain a complete audit trail for legal validity under ESIGN and UETA.

Field Configuration
Upload Document Use final PDF or DOCX format.
Place Signature Fields Add signature, date, and checkbox fields.
Signer Authentication Email + optional SMS or ID verification.
Audit Settings Enable full event logging and certificate of completion.

Technology and integration considerations

Ensure the eSignature platform supports HIPAA BAAs, robust audit trails, and integrations your organization requires.

  • Integrations: Salesforce, NetSuite, Google Workspace and more
  • File formats: PDF, Word DOCX, HTML, Excel supported
  • Authentication: Email, SMS, KBA, advanced options on enterprise plans

Confirm contractual terms for data residency, BAA availability, and support levels before selecting a provider for PHI workflows.

Frequently asked questions about Healthcare BAA Forms and eSigning

Answers address common legal, technical, and operational questions encountered when preparing and executing BAAs electronically.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users