Establishing secure connection…Loading editor…Preparing document…

Healthcare Business Associate Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE BUSINESS ASSOCIATE AGREEMENT

This Healthcare Business Associate Agreement (Agreement) is made effective as of Effective Date: by and between Covered Entity Name: and Business Associate Name: .

PARTIES AND CONTACT INFORMATION

RECITALS

WHEREAS, Covered Entity maintains protected health information created, received, maintained or transmitted in the course of its provision of health care and related activities; and

WHEREAS, Business Associate performs certain services for Covered Entity that require Business Associate to create, receive, maintain, or transmit protected health information on behalf of Covered Entity; and

NOW, THEREFORE, the parties agree as follows.

DEFINITIONS

For purposes of this Agreement, the following terms shall have the meanings set forth below. "Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form that relates to the past, present or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present or future payment for the provision of health care.

"Electronic PHI" or "ePHI" means PHI in electronic form. "Business Associate" means the party identified above that creates, receives, maintains, or transmits PHI on behalf of the Covered Entity. "Covered Entity" means the health care provider, health plan or health care clearinghouse identified above. "Security Incident" means an attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations.

PERMITTED USES AND DISCLOSURES OF PHI

Business Associate may use and disclose PHI only as necessary to perform the services set forth in the underlying service agreement between the parties and as specifically permitted below. Business Associate shall not use or disclose PHI in any manner that would violate applicable law if done by the Covered Entity.

Permitted uses (check all that apply):

BUSINESS ASSOCIATE OBLIGATIONS

Business Associate shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI in accordance with applicable law. Such safeguards shall include, at a minimum, the following documented controls and procedures:

Business Associate shall not use or disclose PHI except as permitted by this Agreement or as required by law. Business Associate shall ensure that any subcontractor or agent to whom it provides PHI agrees, in writing, to the same restrictions and conditions that apply to Business Associate under this Agreement.

Business Associate shall promptly report to Covered Entity any security incident or breach of unsecured PHI of which it becomes aware. Such report shall be provided without unreasonable delay and in no event later than after discovery, and shall include available details regarding the nature and scope of the breach, affected individuals, mitigation undertaken, and proposed corrective actions.

ACCESS, AMENDMENT, AND ACCOUNTING

To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make PHI available to Covered Entity and, as directed by Covered Entity, to individuals for access and amendment in accordance with applicable law. Business Associate shall timely provide information necessary for Covered Entity to respond to requests for accounting of disclosures.

RETURN OR DESTRUCTION OF INFORMATION

Upon termination of this Agreement, Business Associate shall, at the election of Covered Entity, return or destroy all PHI received from Covered Entity or created or received by Business Associate on behalf of Covered Entity. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to the PHI and not further use or disclose the PHI.

AUDIT, RECORDS AND INSPECTION

Covered Entity shall have the right to audit Business Associate's policies, procedures, and records to the extent necessary to verify Business Associate's compliance with this Agreement. Such audit shall be conducted on reasonable notice and in a manner that minimizes disruption to Business Associate's operations.

BREACH INVESTIGATION, MITIGATION AND NOTIFICATION

Business Associate shall investigate any Security Incident or breach, mitigate to the extent practicable any harmful effects resulting from such incident, and cooperate with Covered Entity in notifications to affected individuals and regulators as required by law. Business Associate shall document all incidents and corrective actions.

INDEMNIFICATION, INSURANCE AND LIMITATION OF LIABILITY

Each party shall indemnify, defend, and hold harmless the other party from and against claims, liabilities, losses, damages, and expenses arising from the indemnifying party's breach of this Agreement, willful misconduct, or gross negligence. Parties shall maintain commercially reasonable privacy and security liability insurance covering breaches of PHI.

Except where prohibited by law, neither party shall be liable to the other for punitive, incidental, consequential or special damages, except for damages resulting from willful misconduct or gross negligence.

TERM, TERMINATION AND REMEDIES

This Agreement shall commence on the Effective Date and shall continue until terminated. Either party may terminate this Agreement if the other party materially breaches any provision of this Agreement and fails to cure such breach within days after written notice.

Upon termination, Business Associate shall return or destroy PHI as set forth above. The obligations of Business Associate with respect to PHI shall survive termination to the extent necessary for Business Associate to comply with its obligations under this Agreement.

MISCELLANEOUS

This Agreement shall be interpreted and enforced in accordance with applicable law, including federal law governing the privacy and security of health information and any applicable state laws. Any amendment to this Agreement must be in writing and signed by authorized representatives of both parties.

Covered Entity - Printed Name:

By:

Date:

Business Associate - Printed Name:

By:

Date:

Enter text✕

What the Healthcare Business Associate Agreement Is

A Healthcare Business Associate Agreement (BAA) is a written contract between a HIPAA-covered entity and a business associate that creates, receives, maintains, or transmits protected health information (PHI) on behalf of the covered entity. The BAA specifies permitted uses and disclosures of PHI, requires safeguards to protect PHI, allocates responsibility for breach notification and mitigation, and sets obligations for return or destruction of PHI at termination. BAAs implement HIPAA privacy and security requirements contractually and are required when a vendor performs services involving PHI for a covered entity.

Why a BAA Matters for Healthcare Compliance

A valid BAA documents legal obligations under HIPAA, defines security and breach response duties, and reduces liability exposure for covered entities and business associates by clarifying responsibilities and expectations.

Why a BAA Matters for Healthcare Compliance

Who Typically Prepares and Signs a BAA

A BAA is prepared when a covered entity engages a vendor that will handle PHI; the agreement is reviewed by legal or compliance teams before execution.

  • Covered entities (hospitals, clinics, health plans) that must protect PHI and require written assurances.
  • Business associates (cloud providers, billing vendors, transcription services) that create, receive, or manage PHI.
  • Third-party contractors (IT firms, SaaS vendors) providing services where access to PHI is necessary.

Execution is normally signed by an authorized official at each organization; legal counsel often reviews BAAs for scope and adequacy of safeguards.

Key Roles Who Sign or Approve a BAA

Compliance Officer

The covered entity's compliance or privacy officer typically reviews the BAA language for HIPAA alignment and approves risk allocation, reporting, and audit provisions.

Vendor Executive

A business associate's authorized representative (VP, legal counsel, or contract officer) signs to accept operational, security, and breach-notification obligations on behalf of the vendor.

Core Elements to Include in a Professional BAA

A compliant BAA contains clear, enforceable terms that limit PHI use, require safeguards, and define breach responsibilities to meet HIPAA and related standards.

Permitted Uses

Precise scope describing how the business associate may use and disclose PHI, limited to the services contracted and any required de-identification rules.

Safeguards

Specific administrative, physical, and technical safeguards the business associate must maintain, including encryption, access controls, and security testing obligations.

Breach Notification

Timelines and procedures for detecting, reporting, investigating, and mitigating breaches; include short notification windows and escalation paths.

Subcontractors

Requirement that subcontractors handling PHI sign flow-down BAAs and meet the same privacy and security obligations as the primary business associate.

Term and Termination

Effective date, termination rights for material breaches, and post-termination obligations for return or destruction of PHI.

Audit Rights

Rights for the covered entity to inspect, audit, or obtain evidence of the business associate's compliance with the BAA and HIPAA safeguards.

Security and Compliance Requirements to Specify

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3
BAA Requirement: Written BAA executed
Access Controls: Role-based access
Audit Trail: Detailed logging
Retention: Retention schedule

Primary Risks if a BAA Is Missing or Deficient

Civil Fines: Potential HHS OCR penalties
Breach Liability: Vendor and entity exposure
Contract Termination: Loss of services
Regulatory Audits: Increased oversight risk
Reputational Harm: Patient trust erosion
Indemnity Costs: Defense and settlement

Common Preparation Mistakes to Avoid

  • Using vague or overly broad permitted-use language that allows PHI use beyond the contracted service creates compliance gaps and potential liability.
  • Failing to require subcontractor BAAs or to verify downstream vendors' security practices exposes PHI to uncontrolled parties and increases breach risk.
  • Omitting concrete breach-notification timelines and criteria can delay response, worsen impact, and complicate regulatory reporting obligations.
  • Assuming off-the-shelf vendor statements suffice without legal review; BAAs must be tailored to the service, data elements, and technical environment.

Step-by-Step: How to Complete a Healthcare Business Associate Agreement

Follow a documented sequence to prepare, review, sign, and store the BAA to ensure legal validity and operational readiness.

  • 01
    Prepare draft: Identify PHI scope and required safeguards.
  • 02
    Legal review: Have counsel confirm HIPAA alignment and risk allocation.
  • 03
    Negotiate terms: Agree on breach, indemnity, and audit clauses.
  • 04
    Execute: Authorized signers sign and date the agreement.

Typical BAA Execution and Routing Workflow

A clear signing workflow reduces friction and preserves an auditable record of consent and authority.

  • Upload Document: Place signature and date fields for each party.
  • Assign Signers: Specify authorized signatories and signer order.
  • Authenticate: Use email link, SMS code, or stronger methods.
  • Complete and Store: Capture audit trail and archive encrypted copy.

Configure an Electronic BAA Workflow

Set up fields, authentication, and retention rules before sending the BAA for signatures.

Field Configuration
Authentication Email link plus optional SMS code
Document Type Breach-notice capable BAA template
Routing Sequential signer order with reminders
Retention Encrypted storage for six years

eSignature Vendor Comparison for Executing BAAs

Comparison of common vendor features and starting prices relevant when selecting an eSignature provider for BAA execution.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes Yes Yes Yes Varies by plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Varies by plan Varies by plan Varies by plan Varies by plan
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Practical Tips for Accurate and Efficient BAA Completion

Adopt consistent procedures to reduce errors, speed approvals, and preserve enforceability when using electronic workflows for BAAs.

Standardize Templates
Maintain an approved BAA template with fillable fields and mandatory clauses to minimize negotiation and ensure compliance.
Limit PHI Scope
Specify the minimal PHI elements required for the service to reduce exposure and simplify compliance controls.
Enforce Subcontractor Flow-Down
Require written BAAs with subcontractors and periodically verify compliance and controls through audits or attestations.
Record Audit Trails
Capture signer identity, timestamps, IP addresses, and access logs to support attribution and demonstrate intent under ESIGN.

Frequently Asked Questions About Healthcare Business Associate Agreements

Answers to common questions about BAAs, enforceability, electronic execution, and retention to help navigate compliance and operational issues.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users