Establishing secure connection…Loading editor…Preparing document…

HIPAA Business Associate Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HIPAA Business Associate Agreement

HIPAA Business Associate Agreement between Covered Entity and Business Associate

(Compliance with Privacy and Security Rules)

This HIPAA Business Associate Agreement (Agreement) is between of hereinafter referred to as the Covered Entity, and located at and includes all office locations and other business locations at which Business Associate data may be used or maintained.

1. Covered Entity acknowledges that it is subject to the Privacy and Security Rules (45 CFR Parts 160 and 164) promulgated by the United States Department of Health and Human Services pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191.

2. If Business Associate provides services to Covered Entity pursuant to one or more contractual relationships, said Agreements are hereinafter referred to as Service Agreements. A list of said agreements affected by this HIPAA Business Associate Agreement is attached hereto as Exhibit A.

3. In the course of executing Service requests, Business Associate may come into contact with, use, or disclose Protected Health Information (PHI).

4. In accordance with the federal privacy and security regulations set forth at 45 C.F.R. Part 160 and Part 164, Subparts A, C, and E, the Parties wish to establish satisfactory assurances that Business Associate will appropriately safeguard PHI.

5. Definitions

B. Breach of the Security of the Business Associate’s Information System shall mean ... under the terms of and this Agreement.

D. Confidential Information shall mean ... All confidential information shall not be subject to disclosure under the Public Records Act.

N. Required By Law shall have the same meaning as the term required by law in 45 CFR § 164.103.

6. Obligations and Activities of BUSINESS ASSOCIATE (Privacy Rule)

A. Compliance with the Privacy Rule.

B. Privacy Safeguards and Policies.

C. Business Associate Contracts.

D. Mitigation of Harmful Effect of Violations.

E. Reporting of Violations in Use and Disclosure of PHI.

F. Access of Individual to PHI and other Requests to Business Associate.

G. Requests to Covered Entity for Access to PHI.

1. The Parties understand that if either Party receives a request...

2. If Covered Entity does not have the requested PHI onsite...

3. If the Covered Entity receives a request and requires information...

4. If the Party designated above is unable to complete the response...

H. Individuals’ Request to Amend PHI.

I. Recording of Designated Disclosures of PHI.

J. Accounting for Disclosures of PHI.

1. If Covered Entity directs Business Associate to provide accounting ...

2. If the Covered Entity elects to provide the accounting ...

3. If either of the Parties is unable to complete the response ...

4. The accounting of disclosures shall include ...

5. The Parties shall provide one (1) accounting in any twelve (12) months ...

K. Minimum Necessary.

1. Business Associate represents to Covered Entity ...

2. Covered Entity may reasonably rely on any requested disclosure ...

3. Business Associate agrees to adequately and properly maintain all PHI ...

L. Privacy Compliance Review upon Request.

M. Cooperation in Privacy Compliance.

7. Obligations and Activities of Business Associate (Security Rule)

A. Compliance with Security Rule.

B. Security Safeguards and Policies.

C. Security Provisions in Business Associate Contracts.

D. Consumer Notice of System Breach.

E. Reporting of Security Incidents.

F. Contact for Security Event Notice.

Privacy Officer

Bureau of Covered Entity

Street Address or P.O. Box No.

City, State, Zip Code

G. Security Compliance Review upon Request.

H. Cooperation in Security Compliance.

8. Permitted Uses and Disclosures by Business Associate

A. Use of PHI for Operations on Behalf of Covered Entity.

B. Other Uses of PHI.

C. Third Party Disclosure Confidentiality.

D. Data Aggregation Services.

E. Other Uses Strictly Limited.

F. Covered Entity Authorization for Additional Uses.

G. Prohibition of Offshore Disclosure.

H. Data Use Agreement - Use and Disclosure of Limited Data Set.

I. Limitation on Permitted Uses and Disclosures.

9. Obligations of Covered Entity

A. Notice of Privacy Practices.

B. Notice of Changes in Individual’s Access or PHI.

C. Notice of Restriction in Individual’s Access or PHI.

D. Reciprocity for Requests Received by Business Associate.

10. Permissible Requests by Covered Entity

Requests Permissible under HIPAA.

11. Term and Termination

A. This Agreement shall be effective as of the date on which it has been signed by both parties...

B. Termination for Cause.

1. Upon Covered Entity’s knowledge of a material breach...

a. Provide notice of breach and an opportunity for Business Associate to cure...

b. Immediately terminate this BAA if cure is not possible.

c. If termination, cure, or end of violation is not feasible, Covered Entity shall report the violation to the Secretary.

C. Effect of Termination.

1. Business Associate shall consult with the Covered Entity as necessary...

2. This provision shall not prohibit the retention of a single separate archived file...

3. The Parties agree to anticipate the return and/or destruction of PHI...

4. PHI and other confidential information shall not be merged or aggregated...

5. Upon written mutual agreement ... Business Associate shall extend the protections of this Agreement...

12. Miscellaneous

A. Regulatory Reference.

B. Amendment.

C. Survival.

D. Interpretation.

E. Notices and Communications.

Covered Entity:

Department of

Bureau of

Business Associate:

Department of

G. Strict Compliance.

H. Severability.

I. Governing Law. State of Jurisdiction:

J. Compensation.

Witness our signatures this .

By:

Enter text✕

What a HIPAA Business Associate Agreement Is

A HIPAA Business Associate Agreement is a written contract between a covered entity and a business associate that creates permitted uses and disclosures of protected health information (PHI), imposes safeguards, and assigns responsibilities for breach notification and subcontractor compliance. The BAA documents how PHI will be used, the security measures required, and the requirement that the business associate will sign subcontracts requiring the same protections. It is required whenever a vendor or partner creates, receives, maintains, or transmits PHI on behalf of a covered entity.

Why a Proper BAA Matters for Compliance and Risk

A compliant HIPAA Business Associate Agreement reduces regulatory risk, clarifies liability for PHI handling, and documents required safeguards and breach procedures. It is a foundational control for HIPAA compliance and a contractual prerequisite before sharing PHI with vendors.

Why a Proper BAA Matters for Compliance and Risk

Organizations and Roles That Commonly Use a BAA

Each signer should confirm authority to bind their organization and ensure internal controls align with the BAA's obligations.

  • Covered entities — hospitals, clinics, health plans and other organizations that originate PHI and must ensure vendor compliance.
  • Business associates — cloud providers, billing vendors, analytics firms, and any service provider that creates, receives, or stores PHI.
  • Subcontractors and resellers — downstream vendors who handle PHI and must be bound by the same obligations.

Step-by-Step: Completing a HIPAA Business Associate Agreement

Follow these four core steps to prepare, review, execute, and store a BAA efficiently and defensibly.

  • 01
    Prepare: Gather party legal names and the PHI categories involved.
  • 02
    Define Scope: Specify permitted uses, disclosures, and subcontractor responsibilities.
  • 03
    Review: Legal and security teams confirm controls, breach processes, and indemnity language.
  • 04
    Execute: Obtain authorized signatures, record dates, and retain signed copies.

Core Contract Elements You Should Include

A professional HIPAA Business Associate Agreement states duties clearly, assigns responsibilities, and sets measurable security and reporting expectations.

Definitions

Define 'Protected Health Information', 'Business Associate', 'Covered Entity', 'Subcontractor', and other key terms to prevent interpretive gaps during enforcement or audit.

Permitted Uses

List specific, limited purposes for PHI use and disclosure; avoid sweeping clauses that permit unrelated processing or secondary uses without consent.

Safeguards

Require administrative, physical, and technical controls such as encryption in transit and at rest, role-based access, and regular security testing and monitoring.

Breach Notification

Set timelines and responsibilities for breach detection, notification to the covered entity, and cooperation in investigations and notifications to affected individuals and regulators.

Subcontractor Flow-Down

Obligate business associate to require equivalent protections from subcontractors and to provide proof of compliance on request by the covered entity.

Termination and Return

Specify end-of-contract obligations for PHI return or destruction, and conditions triggering termination for material noncompliance.

Security and Compliance Checklist

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3 required
BAA Required: Written agreement mandatory
Access Controls: Role-based access
Audit Trail: Comprehensive logging
Breach Reporting: Defined notification timeline

Penalties and Risks from an Incomplete or Missing BAA

Regulatory Fines: Civil monetary penalties
OCR Enforcement: Corrective action plans required
Contract Liability: Indemnity and damages exposure
Reputational Harm: Loss of trust and business
Data Exposure: Unauthorized PHI disclosure
Criminal Risk: Intentional wrongful disclosure

Common Preparation Mistakes to Avoid

  • Using vague permission language that leaves open broad or unintended PHI uses and disclosures.
  • Failing to include subcontractor flow-down clauses, leaving downstream processors uncontracted for PHI protection.
  • Neglecting to specify technical safeguards such as encryption or multifactor authentication for remote access.
  • Allowing unsigned or poorly authenticated electronic signings without clear evidence of signer identity and intent.

How Electronic Execution and Exchange Typically Work

Electronic completion and signing streamline execution while preserving the audit trail and evidence required under ESIGN and UETA.

  • Upload Document: Create the BAA template and upload to the e-sign platform.
  • Place Fields: Add signature, date, and checkbox fields as required.
  • Signers Authenticate: Signers confirm identity via email, SMS code, or stronger methods.
  • Audit Record: Platform captures IP, timestamp, and action log for proof.

Typical Digital Workflow Settings for BAAs

Configure these settings to align signing workflow with security and audit requirements.

Field Configuration
Authentication Level Email & optional SMS code
Document Template Locked fields and required signatures
Signer Order Sequential or parallel signing
Retention Setting Store signed copy and audit trail

Technical Capabilities to Check in an eSignature Platform

Ensure the platform supports a signed audit trail, strong encryption in transit and at rest, and a written BAA when PHI will be handled.

  • Integrations: Salesforce, NetSuite, Microsoft 365
  • File Formats: PDF, DOCX, HTML supported
  • Auth Methods: Email, SMS, SSO, MFA

Key Dates and Timing Expectations

Track effective dates, execution deadlines, and reporting timeframes to meet legal and contractual obligations.

Effective Date:

Enter MM/DD/YYYY; obligations begin on this date.

Execution Deadline:

Obtain signed BAA before sharing PHI with the associate.

Breach Notification:

HIPAA requires prompt notice; larger breaches often reported within 60 days.

Annual Review:

Review safeguards and subcontractor lists at least annually.

Record Retention:

Retain signed BAAs per applicable retention rules.

Typical Milestones from Draft to Operational PHI Access

Track milestones to prevent premature PHI transfer and to prove compliance during audits.

01

Drafting

Draft terms, scope, and security obligations for review.

02

Legal Review

Security and counsel verify obligations and liability language.

03

Execution

Authorized signers complete signatures and date the agreement.

04

Operational Access

Only after execution grant systems access to PHI.

Comparing eSignature Vendors for HIPAA Workflows

Platform pricing and HIPAA support vary; the table compares starting price, trial availability, bulk-send capability, audit trails, HIPAA compliance, and envelope caps.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial (no card) Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently Asked Questions About HIPAA Business Associate Agreements

Answers to common questions that arise during preparation, execution, and management of BAAs.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users