Establishing secure connection…Loading editor…Preparing document…

Business Associate Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

SAMPLE BUSINESS ASSOCIATE CONTRACT PROVISIONS

Statement of Intent

These sample business associate contract provisions are provided in response to numerous requests for guidance. This is only sample language. These provisions are designed to help covered entities more easily comply with the business associate contract Requirements of the Privacy Rule. However, use of these sample provisions is not required for compliance with the Privacy Rule. The language may be amended to more accurately reflect business arrangements between the covered entity and the business associate.

These or similar provisions may be incorporated into an agreement for the provision of services between the entities or they may be incorporated into a separate business associate agreement. These provisions only address concepts and requirements set forth in the Privacy Rule and alone are not sufficient to result in a binding contract under state law. They do not include many formalities and substantive provisions that are required or typically included in a valid contract. Reliance on this sample is not sufficient for compliance with state law and does not replace consultation with a lawyer or negotiations between the parties to the contract.

Furthermore, a covered entity may want to include other provisions that are related to the Privacy Rule but that are not required by the Privacy Rule. For example, a covered entity may want to add provisions in a business associate contract in order for the covered entity to be able to rely on the business associate to help the covered entity meet its obligations under the Privacy Rule. In addition, there may be permissible uses or disclosures by a business associate that are not specifically addressed in these sample provisions, for example having a business associate create a limited data set. These and other types of issues will need to be worked out between the parties.

Sample Business Associate Contract Provisions

Definitions (alternative approaches)

Catch-all definition: Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms in the Privacy Rule.

Examples of specific definitions:

a. Business Associate. "Business Associate" shall mean

b. Covered Entity. "Covered Entity" shall mean

c. Individual. "Individual" shall have the same meaning as the term "individual" in 45 CFR § 164.501 and shall include a person who qualifies as a personal representative in accordance with 45 CFR § 164.502(g).

d. Privacy Rule. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 CFR Part 160 and Part 164, Subparts A and E.

e. Protected Health Information. "Protected Health Information" shall have the same meaning as the term "protected health information" in 45 CFR § 164.501, limited to the information created or received by Business Associate from or on behalf of Covered Entity.

f. Required By Law. "Required By Law" shall have the same meaning as the term "required by law" in 45 CFR § 164.501.

g. Secretary. "Secretary" shall mean the Secretary of the Department of Health and Human Services or his designee.

Obligations and Activities of Business Associate

a. Business Associate agrees to not use or disclose Protected Health Information other than as permitted or required by the Agreement or as Required By Law.

b. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of the Protected Health Information other than as provided for by this Agreement.

c. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement. [This provision may be included if it is appropriate for the Covered Entity to pass on its duty to mitigate damages to a Business Associate.]

d. Business Associate agrees to report to Covered Entity any use or disclosure of the Protected Health Information not provided for by this Agreement of which it becomes aware.

e. Business Associate agrees to ensure that any agent, including a subcontractor, to whom it provides Protected Health Information received from, or created or received by Business Associate on behalf of Covered Entity agrees to the same restrictions and conditions that apply through this Agreement to Business Associate with respect to such information.

f. Business Associate agrees to provide access, at the request of Covered Entity, and in the time and manner , to Protected Health Information in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 CFR § 164.524. [Not necessary if business associate does not have protected health information in a designated record set.]

g. Business Associate agrees to make any amendment(s) to Protected Health Information in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR § 164.526 at the request of Covered Entity or an Individual, and in the time and manner . [Not necessary if business associate does not have protected health information in a designated record set.]

h. Business Associate agrees to make internal practices, books, and records, including policies and procedures and Protected Health Information, relating to the use and disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary, in a time and manner or designated by the Secretary, for purposes of the Secretary determining Covered Entity's compliance with the Privacy Rule.

i. Business Associate agrees to document such disclosures of Protected Health Information and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528.

j. Business Associate agrees to provide to Covered Entity or an Individual, in time and manner , information collected in accordance with Section of this Agreement, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528.

Permitted Uses and Disclosures by Business Associate

General Use and Disclosure Provisions [(a) and (b) are alternative approaches]

a. Specify purposes:

Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information on behalf of, or to provide services to, Covered Entity for the following purposes, if such use or disclosure of Protected Health Information would not violate the Privacy Rule if done by Covered Entity or the minimum necessary policies and procedures of the Covered Entity:

b. Refer to underlying services agreement:

Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in , provided that such use or disclosure would not violate the Privacy Rule if done by Covered Entity or the minimum necessary policies and procedures of the Covered Entity.

Specific Use and Disclosure Provisions [only necessary if parties wish to allow Business Associate to engage in such activities]

a. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate.

b. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of the Business Associate, provided that disclosures are Required By Law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as Required By Law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

c. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information to provide Data Aggregation services to Covered Entity as permitted by 45 CFR § 164.504(e)(2)(i)(B).

d. Business Associate may use Protected Health Information to report violations of law to appropriate Federal and State authorities, consistent with § 164.502(j)(1).

Obligations of Covered Entity

Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions [provisions dependent on business arrangement]

a. Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices of Covered Entity in accordance with 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of Protected Health Information.

b. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by Individual to use or disclose Protected Health Information, to the extent that such changes may affect Business Associate's use or disclosure of Protected Health Information.

c. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of Protected Health Information that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of Protected Health Information.

Permissible Requests by Covered Entity

Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy Rule if done by Covered Entity. [Include an exception if the Business Associate will use or disclose protected health information for, and the contract includes provisions for, data aggregation or management and administrative activities of Business Associate].

Term and Termination

a. Term. The Term of this Agreement shall be effective as of , and shall terminate when all of the Protected Health Information provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy Protected Health Information, protections are extended to such information, in accordance with the termination provisions in this Section. [Term may differ.]

b. Termination for Cause. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall either:

1. Provide an opportunity for Business Associate to cure the breach or end the violation and terminate this Agreement if Business Associate does not cure the breach or end the violation within the time specified by Covered Entity;

2. Immediately terminate this Agreement if Business Associate has breached a material term of this Agreement and cure is not possible; or

3. If neither termination nor cure are feasible, Covered Entity shall report the violation to the Secretary.

[Bracketed language in this provision may be necessary if there is an underlying services agreement. Also, opportunity to cure is permitted, but not required by the Privacy Rule.]

c. Effect of Termination.

1. Except as provided in paragraph (2) of this section, upon termination of this Agreement, for any reason, Business Associate shall return or destroy all Protected Health Information received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity. This provision shall apply to Protected Health Information that is in the possession of subcontractors or agents of Business Associate. Business Associate shall retain no copies of the Protected Health Information.

2. In the event that Business Associate determines that returning or destroying the Protected Health Information is infeasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon that return or destruction of Protected Health Information is infeasible, Business Associate shall extend the protections of this Agreement to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such Protected Health Information.

Miscellaneous

a. Regulatory References. A reference in this Agreement to a section in the Privacy Rule means the section as in effect or as amended.

b. Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the Privacy Rule and the Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191.

c. Survival. The respective rights and obligations of Business Associate under Section of this Agreement shall survive the termination of this Agreement.

d. Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with the Privacy Rule.

Business Associate Signature

Covered Entity Signature

Business Associate Name

Covered Entity Name

Date

Date

Enter text✕

What a Business Associate Agreement Is and when it applies

A Business Associate Agreement (BAA) is a contract between a covered entity and a business associate that creates, receives, maintains, or transmits protected health information (PHI) on behalf of the covered entity. Under HIPAA, a BAA allocates responsibilities for safeguarding PHI, requires permitted uses and disclosures, and establishes breach notification duties. BAAs define security safeguards, permitted subcontractors, and term/termination provisions so both parties meet regulatory obligations under the HIPAA Privacy and Security Rules and related federal requirements.

Why a properly drafted BAA matters for compliance

A BAA documents legal responsibilities for PHI handling, reduces regulatory risk, and limits liability by specifying safeguards, breach procedures, and permitted uses. It is a HIPAA prerequisite when a vendor performs services involving PHI for a covered entity.

Why a properly drafted BAA matters for compliance

Who commonly needs a Business Associate Agreement

When in doubt, treat vendors that access, store, or transmit PHI as business associates and document responsibilities in a BAA prior to any PHI exchange.

  • Hospitals and clinics that hire third-party billing, cloud storage, or analytics vendors to process PHI.
  • Software and cloud vendors that store patient data, host electronic health records, or manage communications.
  • Practice management firms, labs, and subcontractors performing services on behalf of covered entities.

Step-by-step: completing a Business Associate Agreement

Follow these practical steps to prepare, sign, and implement a BAA so PHI handling begins under documented obligations.

  • 01
    Prepare: Identify the covered entity, business associate, and scope of PHI processing.
  • 02
    Define safeguards: Specify administrative, physical, and technical protections required.
  • 03
    Assign duties: Document breach notification, subcontractor flow-down, and reporting timelines.
  • 04
    Execute: Have authorized signatories sign and retain an executed copy before PHI transfer.

Core clauses to include in a professional BAA

A robust BAA contains clear, enforceable clauses that define obligations, limits, and remedies. Draft each clause with specific expectations and measurable standards where possible.

Permitted Uses

Specify exactly how PHI may be used and disclosed by the business associate, limiting use to performance of the contracted service and any allowed secondary uses.

Safeguards

Require administrative, physical, and technical safeguards (access controls, encryption, incident response) and state measurable benchmarks or standards to evaluate compliance.

Subcontractors

Mandate written agreements with subcontractors that mirror BAA obligations and require the business associate to obtain flow-down BAAs before sharing PHI.

Breach Notification

Define timing, content, and escalation for breach notices and responsibilities for mitigation, investigation, and supporting the covered entity’s required external reporting.

Audit Rights

Allow the covered entity to assess controls, receive audit results, and require remediation within stated timeframes following identified deficiencies.

Termination

Specify termination for material breach, obligations on termination (return or destruction of PHI), and procedures if return is infeasible.

Security and compliance items to reference in the BAA

Encryption: AES-256 at rest
Transport Security: TLS 1.2 / 1.3 in transit
Audit Trail: Timestamped activity logs
Certifications: SOC 2 Type II
Regulatory Coverage: HIPAA (BAA required)
eSignature Law: ESIGN and UETA compliant

Key penalties and legal risks tied to BAAs and PHI mishandling

HIPAA Fines: Civil monetary penalties
Criminal Liability: Possible for knowing violations
Contractual Liability: Indemnity and damages clauses
Regulatory Action: OCR enforcement and corrective actions
Data Breach Costs: Notification and remediation expenses
Reputational Harm: Loss of patient trust

Common mistakes to avoid when preparing a BAA

  • Using generic, one-size-fits-all language that fails to describe specific services or PHI flows increases enforcement and compliance risk.
  • Delaying execution until after PHI exchange: BAAs must be in place before PHI is shared to meet HIPAA obligations.
  • Failing to require subcontractor flow-down agreements leaves gaps in the PHI protection chain and may create liability exposure.
  • Not specifying technical controls or measurement criteria prevents meaningful audits and effective remediation after incidents.

How electronic signing and execution typically work for a BAA

Electronic execution follows a standard workflow. The process should capture intent, consent, attribution, and retention to meet ESIGN and UETA criteria.

  • Upload: Sender uploads the BAA document to the signing platform.
  • Assign Fields: Place signature, initial, and date fields for each signer.
  • Authenticate: Signers verify identity via email, SMS code, or stronger methods.
  • Complete: Signed copies and an audit trail are stored and distributed.

Configuring an electronic BAA workflow

Set up a signing workflow that enforces signer order, required fields, authentication, and document retention before distributing the BAA.

Field Configuration
Signer Order Set required signing sequence for parties
Authentication Email/SMS code, or MFA for higher assurance
Required Fields Signature, printed name, title, date
Retention Auto-store signed copy and audit trail

Technical requirements and integrations for e-executing BAAs

Ensure the platform provides encryption in transit and at rest and captures attribution data (IP, timestamp, signer identity) for enforceability.

  • Integrations: Salesforce, NetSuite, Microsoft 365, Google Workspace
  • Formats: PDF, DOCX, and secure archival formats
  • Authentication: Support for SMS, email, and advanced methods

Timing and periodic review expectations for BAAs

While BAAs have no fixed federal filing deadline, timely execution and scheduled reviews are best practice to maintain compliance and respond to regulatory changes.

Initial Execution:

Execute before any PHI is exchanged between parties

Review Cycle:

Conduct annual or trigger-based reviews of BAA terms and controls

Subcontractor Updates:

Require prompt notice and executed flow-down BAAs when subcontractors change

Breach Timelines:

Notify covered entity immediately per contractual terms and HIPAA requirements

Termination Actions:

Complete return/destruction of PHI within the timeframe specified in the BAA

Typical lifecycle milestones for a Business Associate Agreement

Track key milestones from negotiation through post-termination to ensure obligations are met and records are preserved.

01

Negotiation

Agree scope, safeguards, and liability allocation before signature.

02

Execution

Obtain authorized signatures and distribute executed copies to stakeholders.

03

Operational Compliance

Implement technical and administrative controls described in the BAA.

04

Termination and Disposition

Return or securely destroy PHI and document disposition actions.

Comparing eSignature vendor pricing and key capabilities

Cost and capability vary by vendor and plan. The table below shows starting price and common capability checkpoints; review plan details for bulk usage and enterprise needs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Available (Business Premium) Depends on plan Depends on plan Depends on plan Depends on plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Depends on plan Depends on plan Depends on plan

Real-world examples of BAAs in practice

Two customer examples illustrate typical BAA uses and outcomes in operational settings.

Optica Ventures — COO

Optica adopted an eSignature workflow to handle vendor agreements and BAAs efficiently.

  • The team emphasized usability and secure access controls.
  • The result was faster execution and consistent recordkeeping, supporting rapid onboarding of new vendors while preserving required audit trails.

Fertility Centers of Illinois — Founder

The clinic standardized BAAs and related consent forms for third-party lab services.

  • They prioritized HIPAA compliance and API-based storage.
  • Standardization improved internal policies and reduced administrative time spent locating executed agreements during audits and vendor reviews.

Practical tips for accurate and efficient BAA completion

Apply consistent controls and clear language to reduce negotiation time and strengthen enforceability.

Execute before PHI exchange
Do not transfer PHI until a signed BAA is in place. This prevents regulatory exposure and clarifies responsibilities from day one.
Be specific about scope
Define permitted uses, data elements, and subprocessors explicitly to avoid mission creep and disputes about permitted processing.
Require flow-downs
Mandate that subcontractors sign equivalent BAAs to maintain the chain of custody and limit compliance gaps.
Use secure eSignature
Capture signer attribution, timestamp, and an immutable audit trail to support ESIGN/UETA validity and facilitate audits.

Frequently asked questions about Business Associate Agreements

Answers to common questions about when a BAA is required, what to include, and how electronic execution affects enforceability.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users