Establishing secure connection…Loading editor…Preparing document…

Healthcare BSA Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE BUSINESS SERVICES AGREEMENT

This Healthcare Business Services Agreement ("Agreement") is entered into by and between Covered Entity Name: and Business Associate Name: . Effective Date: .

RECITALS

WHEREAS, Covered Entity is a healthcare provider that creates, receives and maintains protected health information as defined by applicable law; and WHEREAS, Business Associate performs certain services for or on behalf of Covered Entity that involve the use or disclosure of protected health information; and WHEREAS, the parties intend this Agreement to satisfy applicable statutory and regulatory requirements governing the privacy and security of protected health information.

DEFINITIONS

Terms used in this Agreement shall have the meanings ascribed to them in applicable privacy and security laws. For purposes of this Agreement, "Protected Health Information" or "PHI" means individually identifiable health information created or received by Covered Entity that relates to the past, present or future physical or mental health condition of an individual, the provision of healthcare, or payment for healthcare.

SCOPE OF SERVICES / DESCRIPTION OF BUSINESS SERVICES

PATIENT DATA SCOPE

The PHI disclosed by Covered Entity to Business Associate under this Agreement is limited to the following identified patient or patient population and data elements.

Date of birth:

Medical record number:

Patient address:

INSURANCE INFORMATION

Policy number:

Group number:

MEDICAL HISTORY (RELEVANT TO DATA EXCHANGE)

PERMITTED USES AND DISCLOSURES OF PHI

Business Associate may use and disclose PHI only as necessary to perform the services described in this Agreement and as permitted below. Business Associate shall not use or disclose PHI in a manner that would violate applicable privacy laws if done by Covered Entity.

BUSINESS ASSOCIATE OBLIGATIONS

Business Associate shall: implement administrative, physical and technical safeguards to protect the confidentiality, integrity and availability of PHI; ensure that any subcontractor or agent who receives PHI agrees in writing to the same restrictions and conditions; report to Covered Entity any use or disclosure of PHI not permitted by this Agreement or any security incident or breach of unsecured PHI without unreasonable delay and in any event no later than 10 business days after discovery; mitigate, to the extent practicable, any harmful effect known to Business Associate resulting from such a breach or impermissible use or disclosure.

SECURITY AND AUDIT

Business Associate shall maintain reasonable and appropriate security measures, including encryption where appropriate, access controls, audit logging and workforce training. Covered Entity reserves the right to audit, inspect or otherwise review Business Associate's compliance with this Agreement upon reasonable notice and at reasonable intervals. Business Associate shall cooperate with Covered Entity in any investigation of a breach or complaint.

RETURN OR DESTRUCTION OF PHI

Upon termination or expiration of this Agreement, Business Associate shall, at Covered Entity's option, return or securely destroy all PHI received from Covered Entity or created or received on its behalf. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.

BREACH NOTIFICATION AND COOPERATION

Business Associate shall notify Covered Entity of any security incident, breach or potential breach affecting PHI, provide all available information concerning the incident, cooperate in risk assessments and notifications to individuals and regulatory authorities as required by law, and document actions taken in response to the incident.

INDEMNIFICATION, LIMITATION OF LIABILITY & INSURANCE

Each party shall indemnify, defend and hold harmless the other party from claims, losses or liabilities arising from its breach of this Agreement or violation of applicable privacy or security laws, except to the extent caused by the indemnitee's own negligence or willful misconduct. Business Associate shall maintain insurance coverage appropriate to the scope of services and risks, including cyber liability coverage where applicable.

AUDIT RIGHTS AND RECORDS

Business Associate shall make available to Covered Entity or its designee all internal practices, books and records relating to the use and disclosure of PHI for purposes of determining compliance with this Agreement, subject to confidentiality protections. Access requests shall be honored in a timely manner.

TERM, TERMINATION AND AMENDMENT

This Agreement shall commence on the Effective Date and remain in effect until terminated by either party with thirty (30) days' written notice, or immediately upon a material breach by the other party that is not cured within a reasonable period. The parties may amend this Agreement in writing to address changes in law or regulation.

AUTHORIZATION AND EXPIRATION

This Agreement constitutes the authorization for the exchanges of PHI described herein. Authorization Expiration Date:

MISCELLANEOUS

Governing law, notice provisions, assignment limitations and other standard contract provisions shall apply as set forth below. Any notice required under this Agreement shall be given in writing to the contact person identified by each party.

ACKNOWLEDGMENT

By signing below, each party certifies that it has the authority to enter into this Agreement; that it will comply with the obligations set forth herein; and that it understands its responsibilities with respect to the privacy and security of PHI.

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What the Healthcare BSA Agreement Is and When It Applies

A Healthcare BSA Agreement is a written contract that defines the scope, responsibilities, and data handling commitments between a healthcare organization and a third-party service provider that accesses, processes, or stores protected health information (PHI) or other regulated patient data. The agreement should set out permitted uses of data, required security controls, reporting and breach notification obligations, subcontractor rules, audit rights, liability allocation, and retention expectations to meet HIPAA and related federal requirements while preserving operational clarity for both parties.

Why a Clear BSA Agreement Matters for Healthcare Organizations

A precise Healthcare BSA Agreement allocates risk, establishes HIPAA safeguards, documents permitted PHI uses, and creates measurable compliance steps. It reduces ambiguity that can lead to regulatory exposure, contractual disputes, or gaps in breach response protocols.

Why a Clear BSA Agreement Matters for Healthcare Organizations

Who Typically Prepares and Signs a Healthcare BSA Agreement

Several organizational roles are commonly involved in preparing, reviewing, and executing Healthcare BSA Agreements.

  • Covered entities and providers — legal, compliance, or privacy leads who must protect PHI and authorize vendor access.
  • Business associates and vendors — security, operations, or vendor management teams responsible for implementing contractual controls.
  • Third-party intermediaries — cloud, billing, analytics, or IT support teams who require clear operational and security standards.

Coordination among legal, privacy, procurement, and technical teams helps ensure the agreement is operationally implementable and auditable.

Key Signatory Roles and Representative Profiles

Chief Privacy Officer

Responsible for approving data-sharing terms, confirming HIPAA compliance clauses, and coordinating breach notification and risk mitigation steps with legal counsel and IT security teams.

Vendor Contract Lead

Signs on behalf of the service provider, confirms implementation of security controls, and accepts operational obligations for subcontractors and incident reporting under the agreement.

Essential Security and Compliance Elements to Include

HIPAA BAA: Include a Business Associate Addendum when PHI is handled.
Encryption: TLS 1.2/1.3 in transit; AES-256 at rest.
Audit Trail: Log access, changes, timestamps, and user identity.
Access Controls: Role-based access and strong authenticator requirements.
Subcontractors: Require flow-down obligations and written approvals.
Breach Response: Defined notification windows and remediation steps.

Primary Legal and Operational Risks of a Weak Agreement

HIPAA Fines: Civil penalties and corrective action plans.
Contract Liability: Indemnity claims and litigation exposure.
Regulatory Enforcement: OCR investigations and mandatory audits.
Data Breach Costs: Notification, remediation, and remediation expenses.
Operational Disruption: Service outages or lost access to critical data.
Reputational Harm: Patient trust erosion and business loss.

Common Mistakes When Drafting or Reviewing a Healthcare BSA Agreement

  • Using vague data-use language that permits broader PHI processing than intended, leaving the covered entity exposed to compliance risk.
  • Failing to require written subcontractor flow-downs and audits, which can create blind spots when third parties access PHI.
  • Omitting specific breach notification timelines and responsibilities, delaying regulatory reporting and mitigation steps.
  • Not aligning technical controls with contractual promises (for example, promising encryption but not specifying required standards).

Core Sections to Include in a Professional Healthcare BSA Agreement

A complete Healthcare BSA Agreement organizes responsibilities, security expectations, compliance obligations, and remedies into clear, auditable sections so both parties can implement and verify compliance.

Parties

Identify the covered entity and business associate by legal name, address, and contact points for privacy, security, and legal notices.

Scope of Services

Describe specific services, data elements accessed or processed, permitted uses, and any processing limitations or excluded activities.

PHI Handling

Define PHI categories, minimum necessary rules, de-identification standards, and permitted redisclosure scenarios.

Security Controls

List required administrative, physical, and technical safeguards, encryption standards, authentication, logging, and vulnerability management.

Subcontractors

Require prior written approval, identical flow-down obligations, and audit or inspection rights for subcontractor relationships.

Termination & Liability

Set termination triggers, data return or destruction instructions, indemnity, limitation of liability, and transition support obligations.

Step-by-Step: How to Complete a Healthcare BSA Agreement

Follow these sequential steps to assemble, review, and finalize a Healthcare BSA Agreement that aligns legal, privacy, and technical requirements.

  • 01
    Gather Information: Collect legal names, contacts, services, and data categories.
  • 02
    Draft Scope: Specify permitted uses, data elements, and exclusions.
  • 03
    Add Security Terms: Include encryption, access control, logging, and breach obligations.
  • 04
    Execute and Retain: Obtain signatures, store executed copy, and enable audit logs.

How to Configure an Online Workflow for the BSA Agreement

Set up a digital workflow that enforces required fields, audit logging, and signer authentication to reduce errors and create defensible execution records.

Field Configuration
Signature Type ESIGN-compliant electronic signature with audit trail
Authentication Email link plus optional SMS or MFA for critical signers
Template Use a standard BSA template with required conditional fields
Retention Enable secure storage and 6-year retention for PHI-related records

Where to Send and How to Route an Executed Agreement

Define a clear routing plan so executed agreements reach legal, compliance, and operational teams and are stored in a secure, auditable system.

  • To the Vendor: Deliver an executed copy to the service provider for their records.
  • Internal Legal: Send to in-house counsel for contract management and audit.
  • Privacy Office: Provide the privacy or compliance office with the executed agreement.
  • Secure Archive: Store in a secure repository with access controls and audit logging.

Digital Signing and Technical Requirements for eSubmission

Ensure the platform you choose supports the authentication, audit, and retention features required for PHI-related agreements.

  • Integrations: Common integrations: Salesforce, Microsoft 365, NetSuite, Google Workspace
  • Formats Supported: PDF, Word (.docx), and exportable audit logs
  • Authentication Options: Email link, SMS OTP, or stronger MFA where needed

Choose a platform that can produce a tamper-evident execution record, support a HIPAA BAA where required, and integrate with your contract repository for ongoing access and audits.

Key Dates and Timeline Expectations for a Healthcare BSA Agreement

Track critical dates related to effectiveness, periodic reviews, and incident timelines to maintain compliance and contractual performance.

Effective Date:

Document the MM/DD/YYYY when obligations commence.

Annual Review:

Schedule yearly reviews of security and scope.

BAA Re-evaluation:

Reassess BAA when vendor or processing changes occur.

Retention Start:

Retention begins on creation or last effective date.

Breach Notification:

Large breach notifications typically filed within 60 days.

How the Healthcare BSA Agreement Differs From a Business Associate Addendum (BAA)

Compare the BSA Agreement with a BAA and related documents to choose the correct contract structure for PHI handling and vendor accountability.

Criteria Healthcare BSA Agreement Business Associate Addendum
Primary Purpose comprehensive services contract hipaa-specific obligations
Typical Length multiple pages with exhibits shorter, attachment-style
Includes Pricing
Audit Rights

eSignature Vendor Pricing and Feature Snapshot for PHI-Related Contracts

Compare basic pricing and feature availability across common eSignature vendors. signNow is listed first per standard comparison conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions About the Healthcare BSA Agreement

Answers to common questions about execution, eSigning, notarization, and compliance for Healthcare BSA Agreements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users