Establishing secure connection…Loading editor…Preparing document…

Healthcare BAA Template

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE BUSINESS ASSOCIATE AGREEMENT (BAA)

This Business Associate Agreement ("Agreement") is entered into by and between Covered Entity: and Business Associate: . The parties agree that this Agreement is effective as of Effective Date: .

1. Definitions

1.1 "Protected Health Information" or "PHI" means individually identifiable health information that is created, received, maintained or transmitted by either party that is protected under applicable federal privacy and security law.

1.2 "Privacy Rule" and "Security Rule" refer to the applicable federal standards governing privacy and security of PHI. References to law include any successor statutes or implementing regulations.

2. Permitted Uses and Disclosures

2.1 Business Associate may use and disclose PHI only as necessary to perform the services described in the underlying Services Agreement and as otherwise permitted by this Agreement. Specific permitted purposes (check all that apply):

Treatment    Payment    Health Care Operations

2.2 Additional permitted uses or limitations:

3. Obligations of Business Associate

3.1 Business Associate shall not use or disclose PHI other than as permitted by this Agreement or required by law. Business Associate shall implement administrative, physical and technical safeguards to protect PHI in compliance with applicable law.

3.2 Business Associate will ensure that any subcontractor or agent to whom it provides PHI agrees in writing to the same restrictions and conditions that apply to Business Associate under this Agreement.

3.3 Business Associate shall report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, including breaches of unsecured PHI, within of discovery.

4. Covered Entity Obligations

4.1 Covered Entity shall provide Business Associate with the minimum necessary PHI to carry out the purposes of the Services Agreement and shall notify Business Associate of any known restrictions on the use or disclosure of PHI.

5. Access, Amendment and Accounting

5.1 To the extent Business Associate maintains PHI in a designated record set, Business Associate shall make PHI available to Covered Entity and, where applicable, to an individual as required by law for access or amendment and shall provide an accounting of disclosures as requested by Covered Entity.

6. Return or Destruction of PHI

6.1 Upon termination of the underlying Services Agreement or upon Covered Entity's request, Business Associate shall return or destroy all PHI in its possession in accordance with Covered Entity's instructions.

Select disposition:    Return PHI    Destroy PHI

7. Subcontractors and Agents

7.1 Business Associate may engage subcontractors that create, receive, maintain or transmit PHI only after obtaining reasonable written assurances that the subcontractor will safeguard PHI consistent with this Agreement.

8. Breach Response and Mitigation

8.1 Business Associate shall investigate any impermissible use or disclosure of PHI, mitigate harmful effects to the extent practicable and cooperate with Covered Entity's reasonable efforts to provide notifications to affected individuals and regulators as required by law.

9. Term and Termination

9.1 Term. This Agreement shall commence on the Effective Date and remain in effect until the later of termination of the Services Agreement or until all PHI is returned or destroyed as required by this Agreement.

9.2 Termination for Cause. Covered Entity may terminate this Agreement if Business Associate materially breaches a provision and fails to cure within after written notice.

10. Indemnification and Liability

10.1 Business Associate shall indemnify and hold harmless Covered Entity for losses, liabilities and expenses resulting from Business Associate's material breach of this Agreement or unauthorized use or disclosure of PHI caused by Business Associate.

11. Miscellaneous

11.1 Amendment. This Agreement may be amended only by written instrument signed by both parties. The parties shall promptly execute amendments necessary to comply with applicable law.

11.2 Governing Law. This Agreement shall be governed by the laws of the State of without regard to choice-of-law principles.

12. Certifications and Acknowledgements

Each party certifies that the signatory below is authorized to execute this Agreement on behalf of the party. Business Associate acknowledges its obligation to comply with the terms of this Agreement and applicable privacy and security law.

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What the Healthcare BAA Template Is

A Healthcare Business Associate Agreement (BAA) template is a written contract used when a HIPAA-covered entity shares protected health information (PHI) with a vendor or partner who will create, receive, maintain, or transmit PHI on the covered entity’s behalf. The template defines permitted uses and disclosures, required administrative, physical, and technical safeguards, breach notification responsibilities, and terms for return or destruction of PHI. A clear template reduces negotiation time, ensures consistent compliance language, and documents obligations needed to support a HIPAA-compliant relationship.

Why a Standardized Healthcare BAA Template Matters

A standardized Healthcare BAA Template ensures the minimum HIPAA safeguards are documented, clarifies responsibilities for breach reporting, and reduces legal and operational risk without recreating terms for each vendor.

Why a Standardized Healthcare BAA Template Matters

Who Typically Prepares and Signs This Template

Covered entities, business associates, compliance officers, and legal teams use the Healthcare BAA Template to set PHI handling expectations before work begins.

  • Covered entities (hospitals, clinics, physician groups) — legal or compliance staff use the template to bind vendors to HIPAA obligations.
  • Business associates (billing companies, cloud vendors, analytics providers) — contract teams review and sign to accept restricted PHI uses.
  • In-house counsel and privacy officers — negotiate clause scope, audit rights, and breach notification timing prior to execution.

Use the template as the starting point for negotiations; add organization-specific safeguards, encryption specifics, and contact points for incident response.

Step-by-Step: How to Complete the Healthcare BAA Template

Follow these steps to ensure the template is complete, consistent, and enforceable before any PHI exchange occurs.

  • 01
    Identify Parties: Enter legal names and addresses for covered entity and business associate.
  • 02
    Define Scope: Specify permitted PHI uses and systems involved.
  • 03
    Set Safeguards: List technical, administrative, and physical protections required.
  • 04
    Sign and Retain: Obtain authorized signatures and preserve the executed agreement with audit trail.

How to Customize and Complete the Template Online

Configure the digital workflow to match approval steps, authentication requirements, and archival rules before sending the BAA for signature.

Field Configuration
Signature Authentication Require email plus optional SMS code or SSO for higher assurance.
Template Reuse Lock core clauses to prevent accidental edits; allow metadata updates.
Conditional Clauses Show additional clauses when selected services involve PHI transfer to subcontractors.
Audit Trail Enable complete event logging (timestamps, IPs) for compliance review.

Distribution and Platform Considerations for Electronic BAAs

Choose a platform that supports secure delivery, authentication, and long-term retention compatible with HIPAA recordkeeping needs.

  • Supported Formats: PDF, Word DOCX, and tagged PDFs for accessibility.
  • Integrations: Connectors for Google Workspace, Microsoft 365, Salesforce, NetSuite, Box, and AWS simplify routing.
  • Authentication Options: Email link, SMS code, SSO, or advanced signer verification.

Confirm the platform meets HIPAA BAA needs, provides AES-256 encryption at rest, TLS 1.2/1.3 in transit, and preserves an unalterable audit trail for each execution event.

Where to Send and How to Route the Executed BAA

Route the executed BAA to internal teams and external parties to ensure legal, compliance, and operational access.

  • Legal Department: Retain a fully executed copy and approval metadata in contract repository.
  • Privacy Officer: Store notice contacts and breach escalation procedures for compliance.
  • Business Unit: Deliver a copy to the operational lead to enforce access controls.
  • Business Associate: Provide the final executed agreement and confirm receipt and acceptance.

Timelines and Key Deadlines to Watch

BAAs include effective dates and operational deadlines; track reporting windows and retention triggers to stay compliant.

Execution Deadline:

Sign the BAA before any PHI is disclosed to the business associate.

Breach Notification:

Report potential breaches without unreasonable delay and generally within 60 days of discovery under HHS guidance.

Periodic Review:

Review and renew BAAs when services, systems, or PHI scope changes.

Termination Actions:

Specify time to return or destroy PHI after contract termination.

Record Retention Triggers:

Retention periods often measured from effective date or last action; align with policy.

Required Information and Core BAA Elements

Parties: Full legal names
Effective Date: MM/DD/YYYY
PHI Scope: Specific systems or datasets
Permitted Uses: Approved activities only
Safeguards: Encryption, access controls
Breach Terms: Notification procedures

Penalties and Main Legal Risks

HIPAA Fines: Civil and enforcement penalties
Contract Liability: Indemnity and damages
Regulatory Action: OCR investigations
Data Breach Costs: Notification and remediation
Termination Risk: Loss of contract rights
Reputational Harm: Public trust erosion

Common Mistakes When Preparing a Healthcare BAA

  • Using generic 'business operations' language that fails to limit PHI uses; overly broad clauses increase exposure and make audits difficult.
  • Omitting specific security controls such as encryption at rest or multifactor authentication, which leaves expectations unclear during assessments.
  • Failing to include subcontractor flow-down language that requires business associates to bind downstream vendors to the same PHI safeguards.
  • Not documenting breach reporting timelines and contacts precisely, which can delay notifications and worsen regulatory outcomes.

Real-world Examples of BAAs in Use

The examples below illustrate how organizations document PHI responsibilities and enforce requirements with third parties.

Fertility Centers of Illinois

A clinical network standardized agreements across vendors to centralize PHI controls and audits.

  • The organization required vendor-side encryption and audit logs.
  • The executed BAAs improved oversight of subcontractors and ensured consistent breach notification procedures while preserving patient privacy and operational continuity.

Optica Ventures LLC

A health-adjacent services firm adopted a reusable BAA template for recurring vendor onboarding.

  • They embedded required clauses for permitted uses only.
  • Standardizing the template reduced legal review cycles and ensured each vendor accepted the same security requirements before receiving PHI.

Practical Tips for Accurate and Efficient Completion

Apply consistent controls and versioning so each executed BAA matches the organization’s current policy and audit expectations.

Lock standard clauses
Keep core HIPAA-related provisions read-only in the template and allow only metadata edits to prevent inadvertent removal of required safeguards during negotiations.
Use clear scope language
Limit PHI access by system, dataset, and purpose; narrow scopes reduce incidental use and simplify audits.
Require subcontractor flow-down
Add explicit obligations for subcontractors and a right to audit to ensure downstream compliance with the same PHI protections.
Preserve audit trails
Capture signer identity, timestamps, and IP addresses for each execution event and keep those records for the retention period required by HIPAA and internal policy.

eSignature Pricing and Feature Snapshot for BAAs

Summary of common vendor price points and feature availability relevant to Healthcare BAAs and high-volume signing workflows.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently Asked Questions About Healthcare BAAs

Answers to common questions about enforceability, essential clauses, e-signing, and incident response for BAAs used with PHI.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users