Establishing secure connection…Loading editor…Preparing document…

Business Associate Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!
Business Associate Agreement

What a Business Associate Agreement Is and when it applies

A Business Associate Agreement (BAA) is a contract between a covered entity and a business associate that creates, receives, maintains, or transmits protected health information (PHI) on behalf of the covered entity. Under HIPAA, a BAA allocates responsibilities for safeguarding PHI, requires permitted uses and disclosures, and establishes breach notification duties. BAAs define security safeguards, permitted subcontractors, and term/termination provisions so both parties meet regulatory obligations under the HIPAA Privacy and Security Rules and related federal requirements.

Why a properly drafted BAA matters for compliance

A BAA documents legal responsibilities for PHI handling, reduces regulatory risk, and limits liability by specifying safeguards, breach procedures, and permitted uses. It is a HIPAA prerequisite when a vendor performs services involving PHI for a covered entity.

Why a properly drafted BAA matters for compliance

Who commonly needs a Business Associate Agreement

When in doubt, treat vendors that access, store, or transmit PHI as business associates and document responsibilities in a BAA prior to any PHI exchange.

  • Hospitals and clinics that hire third-party billing, cloud storage, or analytics vendors to process PHI.
  • Software and cloud vendors that store patient data, host electronic health records, or manage communications.
  • Practice management firms, labs, and subcontractors performing services on behalf of covered entities.

Step-by-step: completing a Business Associate Agreement

Follow these practical steps to prepare, sign, and implement a BAA so PHI handling begins under documented obligations.

  • 01
    Prepare: Identify the covered entity, business associate, and scope of PHI processing.
  • 02
    Define safeguards: Specify administrative, physical, and technical protections required.
  • 03
    Assign duties: Document breach notification, subcontractor flow-down, and reporting timelines.
  • 04
    Execute: Have authorized signatories sign and retain an executed copy before PHI transfer.

Core clauses to include in a professional BAA

A robust BAA contains clear, enforceable clauses that define obligations, limits, and remedies. Draft each clause with specific expectations and measurable standards where possible.

Permitted Uses

Specify exactly how PHI may be used and disclosed by the business associate, limiting use to performance of the contracted service and any allowed secondary uses.

Safeguards

Require administrative, physical, and technical safeguards (access controls, encryption, incident response) and state measurable benchmarks or standards to evaluate compliance.

Subcontractors

Mandate written agreements with subcontractors that mirror BAA obligations and require the business associate to obtain flow-down BAAs before sharing PHI.

Breach Notification

Define timing, content, and escalation for breach notices and responsibilities for mitigation, investigation, and supporting the covered entity’s required external reporting.

Audit Rights

Allow the covered entity to assess controls, receive audit results, and require remediation within stated timeframes following identified deficiencies.

Termination

Specify termination for material breach, obligations on termination (return or destruction of PHI), and procedures if return is infeasible.

Security and compliance items to reference in the BAA

Encryption: AES-256 at rest
Transport Security: TLS 1.2 / 1.3 in transit
Audit Trail: Timestamped activity logs
Certifications: SOC 2 Type II
Regulatory Coverage: HIPAA (BAA required)
eSignature Law: ESIGN and UETA compliant

Key penalties and legal risks tied to BAAs and PHI mishandling

HIPAA Fines: Civil monetary penalties
Criminal Liability: Possible for knowing violations
Contractual Liability: Indemnity and damages clauses
Regulatory Action: OCR enforcement and corrective actions
Data Breach Costs: Notification and remediation expenses
Reputational Harm: Loss of patient trust

Common mistakes to avoid when preparing a BAA

  • Using generic, one-size-fits-all language that fails to describe specific services or PHI flows increases enforcement and compliance risk.
  • Delaying execution until after PHI exchange: BAAs must be in place before PHI is shared to meet HIPAA obligations.
  • Failing to require subcontractor flow-down agreements leaves gaps in the PHI protection chain and may create liability exposure.
  • Not specifying technical controls or measurement criteria prevents meaningful audits and effective remediation after incidents.

How electronic signing and execution typically work for a BAA

Electronic execution follows a standard workflow. The process should capture intent, consent, attribution, and retention to meet ESIGN and UETA criteria.

  • Upload: Sender uploads the BAA document to the signing platform.
  • Assign Fields: Place signature, initial, and date fields for each signer.
  • Authenticate: Signers verify identity via email, SMS code, or stronger methods.
  • Complete: Signed copies and an audit trail are stored and distributed.

Configuring an electronic BAA workflow

Set up a signing workflow that enforces signer order, required fields, authentication, and document retention before distributing the BAA.

Field Configuration
Signer Order Set required signing sequence for parties
Authentication Email/SMS code, or MFA for higher assurance
Required Fields Signature, printed name, title, date
Retention Auto-store signed copy and audit trail

Technical requirements and integrations for e-executing BAAs

Ensure the platform provides encryption in transit and at rest and captures attribution data (IP, timestamp, signer identity) for enforceability.

  • Integrations: Salesforce, NetSuite, Microsoft 365, Google Workspace
  • Formats: PDF, DOCX, and secure archival formats
  • Authentication: Support for SMS, email, and advanced methods

Timing and periodic review expectations for BAAs

While BAAs have no fixed federal filing deadline, timely execution and scheduled reviews are best practice to maintain compliance and respond to regulatory changes.

Initial Execution:

Execute before any PHI is exchanged between parties

Review Cycle:

Conduct annual or trigger-based reviews of BAA terms and controls

Subcontractor Updates:

Require prompt notice and executed flow-down BAAs when subcontractors change

Breach Timelines:

Notify covered entity immediately per contractual terms and HIPAA requirements

Termination Actions:

Complete return/destruction of PHI within the timeframe specified in the BAA

Typical lifecycle milestones for a Business Associate Agreement

Track key milestones from negotiation through post-termination to ensure obligations are met and records are preserved.

01

Negotiation

Agree scope, safeguards, and liability allocation before signature.

02

Execution

Obtain authorized signatures and distribute executed copies to stakeholders.

03

Operational Compliance

Implement technical and administrative controls described in the BAA.

04

Termination and Disposition

Return or securely destroy PHI and document disposition actions.

Comparing eSignature vendor pricing and key capabilities

Cost and capability vary by vendor and plan. The table below shows starting price and common capability checkpoints; review plan details for bulk usage and enterprise needs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Available (Business Premium) Depends on plan Depends on plan Depends on plan Depends on plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Depends on plan Depends on plan Depends on plan

Real-world examples of BAAs in practice

Two customer examples illustrate typical BAA uses and outcomes in operational settings.

Optica Ventures — COO

Optica adopted an eSignature workflow to handle vendor agreements and BAAs efficiently.

  • The team emphasized usability and secure access controls.
  • The result was faster execution and consistent recordkeeping, supporting rapid onboarding of new vendors while preserving required audit trails.

Fertility Centers of Illinois — Founder

The clinic standardized BAAs and related consent forms for third-party lab services.

  • They prioritized HIPAA compliance and API-based storage.
  • Standardization improved internal policies and reduced administrative time spent locating executed agreements during audits and vendor reviews.

Practical tips for accurate and efficient BAA completion

Apply consistent controls and clear language to reduce negotiation time and strengthen enforceability.

Execute before PHI exchange
Do not transfer PHI until a signed BAA is in place. This prevents regulatory exposure and clarifies responsibilities from day one.
Be specific about scope
Define permitted uses, data elements, and subprocessors explicitly to avoid mission creep and disputes about permitted processing.
Require flow-downs
Mandate that subcontractors sign equivalent BAAs to maintain the chain of custody and limit compliance gaps.
Use secure eSignature
Capture signer attribution, timestamp, and an immutable audit trail to support ESIGN/UETA validity and facilitate audits.

Frequently asked questions about Business Associate Agreements

Answers to common questions about when a BAA is required, what to include, and how electronic execution affects enforceability.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users