Establishing secure connection…Loading editor…Preparing document…

HIPAA Business Associate Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!
HIPAA Business Associate Agreement

What a HIPAA Business Associate Agreement Is

A HIPAA Business Associate Agreement is a written contract between a covered entity and a business associate that creates permitted uses and disclosures of protected health information (PHI), imposes safeguards, and assigns responsibilities for breach notification and subcontractor compliance. The BAA documents how PHI will be used, the security measures required, and the requirement that the business associate will sign subcontracts requiring the same protections. It is required whenever a vendor or partner creates, receives, maintains, or transmits PHI on behalf of a covered entity.

Why a Proper BAA Matters for Compliance and Risk

A compliant HIPAA Business Associate Agreement reduces regulatory risk, clarifies liability for PHI handling, and documents required safeguards and breach procedures. It is a foundational control for HIPAA compliance and a contractual prerequisite before sharing PHI with vendors.

Why a Proper BAA Matters for Compliance and Risk

Organizations and Roles That Commonly Use a BAA

Each signer should confirm authority to bind their organization and ensure internal controls align with the BAA's obligations.

  • Covered entities — hospitals, clinics, health plans and other organizations that originate PHI and must ensure vendor compliance.
  • Business associates — cloud providers, billing vendors, analytics firms, and any service provider that creates, receives, or stores PHI.
  • Subcontractors and resellers — downstream vendors who handle PHI and must be bound by the same obligations.

Step-by-Step: Completing a HIPAA Business Associate Agreement

Follow these four core steps to prepare, review, execute, and store a BAA efficiently and defensibly.

  • 01
    Prepare: Gather party legal names and the PHI categories involved.
  • 02
    Define Scope: Specify permitted uses, disclosures, and subcontractor responsibilities.
  • 03
    Review: Legal and security teams confirm controls, breach processes, and indemnity language.
  • 04
    Execute: Obtain authorized signatures, record dates, and retain signed copies.

Core Contract Elements You Should Include

A professional HIPAA Business Associate Agreement states duties clearly, assigns responsibilities, and sets measurable security and reporting expectations.

Definitions

Define 'Protected Health Information', 'Business Associate', 'Covered Entity', 'Subcontractor', and other key terms to prevent interpretive gaps during enforcement or audit.

Permitted Uses

List specific, limited purposes for PHI use and disclosure; avoid sweeping clauses that permit unrelated processing or secondary uses without consent.

Safeguards

Require administrative, physical, and technical controls such as encryption in transit and at rest, role-based access, and regular security testing and monitoring.

Breach Notification

Set timelines and responsibilities for breach detection, notification to the covered entity, and cooperation in investigations and notifications to affected individuals and regulators.

Subcontractor Flow-Down

Obligate business associate to require equivalent protections from subcontractors and to provide proof of compliance on request by the covered entity.

Termination and Return

Specify end-of-contract obligations for PHI return or destruction, and conditions triggering termination for material noncompliance.

Security and Compliance Checklist

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3 required
BAA Required: Written agreement mandatory
Access Controls: Role-based access
Audit Trail: Comprehensive logging
Breach Reporting: Defined notification timeline

Penalties and Risks from an Incomplete or Missing BAA

Regulatory Fines: Civil monetary penalties
OCR Enforcement: Corrective action plans required
Contract Liability: Indemnity and damages exposure
Reputational Harm: Loss of trust and business
Data Exposure: Unauthorized PHI disclosure
Criminal Risk: Intentional wrongful disclosure

Common Preparation Mistakes to Avoid

  • Using vague permission language that leaves open broad or unintended PHI uses and disclosures.
  • Failing to include subcontractor flow-down clauses, leaving downstream processors uncontracted for PHI protection.
  • Neglecting to specify technical safeguards such as encryption or multifactor authentication for remote access.
  • Allowing unsigned or poorly authenticated electronic signings without clear evidence of signer identity and intent.

How Electronic Execution and Exchange Typically Work

Electronic completion and signing streamline execution while preserving the audit trail and evidence required under ESIGN and UETA.

  • Upload Document: Create the BAA template and upload to the e-sign platform.
  • Place Fields: Add signature, date, and checkbox fields as required.
  • Signers Authenticate: Signers confirm identity via email, SMS code, or stronger methods.
  • Audit Record: Platform captures IP, timestamp, and action log for proof.

Typical Digital Workflow Settings for BAAs

Configure these settings to align signing workflow with security and audit requirements.

Field Configuration
Authentication Level Email & optional SMS code
Document Template Locked fields and required signatures
Signer Order Sequential or parallel signing
Retention Setting Store signed copy and audit trail

Technical Capabilities to Check in an eSignature Platform

Ensure the platform supports a signed audit trail, strong encryption in transit and at rest, and a written BAA when PHI will be handled.

  • Integrations: Salesforce, NetSuite, Microsoft 365
  • File Formats: PDF, DOCX, HTML supported
  • Auth Methods: Email, SMS, SSO, MFA

Key Dates and Timing Expectations

Track effective dates, execution deadlines, and reporting timeframes to meet legal and contractual obligations.

Effective Date:

Enter MM/DD/YYYY; obligations begin on this date.

Execution Deadline:

Obtain signed BAA before sharing PHI with the associate.

Breach Notification:

HIPAA requires prompt notice; larger breaches often reported within 60 days.

Annual Review:

Review safeguards and subcontractor lists at least annually.

Record Retention:

Retain signed BAAs per applicable retention rules.

Typical Milestones from Draft to Operational PHI Access

Track milestones to prevent premature PHI transfer and to prove compliance during audits.

01

Drafting

Draft terms, scope, and security obligations for review.

02

Legal Review

Security and counsel verify obligations and liability language.

03

Execution

Authorized signers complete signatures and date the agreement.

04

Operational Access

Only after execution grant systems access to PHI.

Comparing eSignature Vendors for HIPAA Workflows

Platform pricing and HIPAA support vary; the table compares starting price, trial availability, bulk-send capability, audit trails, HIPAA compliance, and envelope caps.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial (no card) Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently Asked Questions About HIPAA Business Associate Agreements

Answers to common questions that arise during preparation, execution, and management of BAAs.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users