HIPAA·10 min read

Business Associate Agreement: What a HIPAA BAA Is and Who Needs One

A business associate agreement is the contract HIPAA requires before protected health information can be shared with an outside vendor. If your SaaS platform stores, processes, or transmits patient data on behalf of a healthcare customer, you cannot legally receive that data until this agreement is signed.

This guide explains what a business associate agreement is, who has to sign one, what it must contain, and how it differs from the NDAs and DPAs it often gets confused with. For the full compliance program behind it, see the HIPAA service page.


What a business associate agreement is

A business associate agreement (BAA) is a contract required by the HIPAA Privacy and Security Rules. It governs the relationship between a covered entity and a business associate whenever protected health information (PHI) is involved. HIPAA does not treat this as optional or as a best practice; it is a legal precondition for sharing PHI.

The BAA exists to extend HIPAA's protections beyond the healthcare organization itself. When a hospital hands patient data to a billing vendor or a scheduling platform, HIPAA needs assurance that the vendor will protect that data to the same standard. The BAA is how that assurance becomes legally binding, and it makes the vendor directly accountable for compliance.

Since the HIPAA Omnibus Rule took effect, business associates have direct liability under HIPAA. That means a vendor handling PHI can be investigated and fined by regulators on its own, not just indirectly through its healthcare customer. The BAA is the document that formalizes those obligations.

Who needs a business associate agreement

To know whether you need a BAA, you first need the three roles HIPAA defines.

  • Covered entity: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically. These are the organizations HIPAA directly regulates.
  • Business associate: a person or company that performs a function or service for a covered entity that involves access to PHI. This is where most SaaS platforms land.
  • Subcontractor: a company a business associate hires that also handles the PHI. Under HIPAA, a subcontractor is itself treated as a business associate.

A BAA is required at every link in this chain. The covered entity signs a BAA with each business associate, and each business associate signs a BAA with each subcontractor that will touch the data. If your SaaS platform stores PHI and you use a cloud host, a subprocessor for email, or an analytics vendor that can see PHI, you need BAAs flowing down to each of them.

The practical rule: PHI cannot move to a new party until a signed business associate agreement is in place between the party sending it and the party receiving it.

What a business associate agreement must include

HIPAA specifies the required contents of a BAA. A generic contract that simply promises confidentiality does not meet the standard. At a minimum, a compliant BAA must:

  • Describe the permitted and required uses and disclosures of PHI by the business associate.
  • Prohibit the business associate from using or disclosing PHI beyond what the contract or law allows.
  • Require the business associate to use appropriate safeguards, and for electronic PHI, to comply with the HIPAA Security Rule.
  • Require the business associate to report any use or disclosure not permitted by the contract, including security incidents and breaches, within defined timelines.
  • Require the business associate to ensure that any subcontractors handling PHI agree to the same restrictions through their own BAAs.
  • Require the business associate to make PHI available to support individuals' rights of access, amendment, and an accounting of disclosures.
  • Require the business associate to make its internal records available to the Department of Health and Human Services for compliance review.
  • Require the business associate to return or destroy all PHI at the end of the relationship, where feasible.
  • Authorize the covered entity to terminate the contract if the business associate violates a material term.

These elements are what separate a BAA from an ordinary contract. Each one assigns a specific HIPAA obligation, which is why legal review matters and why a downloaded template should be checked against your actual data flows.

BAA vs NDA vs DPA

These three agreements get treated as interchangeable, and they are not.

An NDA (non-disclosure agreement) is a general promise not to share confidential information. It is useful, but it imposes none of HIPAA's specific duties. A business associate agreement is not the same as an NDA, and signing an NDA in place of a BAA leaves both parties non-compliant. The moment PHI is disclosed without a BAA, the covered entity has violated HIPAA regardless of how strong the NDA is.

A DPA (Data Processing Agreement) is the GDPR equivalent for EU personal data, required under Article 28. It covers similar ground, safeguards, breach reporting, subprocessors, but under a different law with different specifics. A DPA does not automatically satisfy HIPAA, and a BAA does not automatically satisfy GDPR. A company subject to both can use a single combined agreement, but only if it contains every required element of each. We cover that combined-template pattern in running GDPR and HIPAA together.

When your SaaS is a business associate

Many SaaS founders assume HIPAA only applies to hospitals. It applies to their vendors too. If your platform creates, receives, maintains, or transmits PHI on behalf of a healthcare customer, you are a business associate and you need a BAA with that customer.

A common point of confusion is the conduit exception. HIPAA exempts pure transmission services, the way a postal service or an internet provider is exempt, because they only move data and do not store it. This exception is narrow. Federal guidance is explicit that a cloud provider storing ePHI is a business associate even if the data is encrypted and the provider never looks at it. Storage is not transmission, so cloud hosting, backups, and databases holding PHI all require BAAs.

If you are figuring out whether HIPAA applies to your platform at all, start with the HIPAA compliance checklist for HealthTech. And if your buyers are asking for SOC 2 alongside HIPAA, SOC 2 and HIPAA compliance explains how the two fit together.

What happens without a business associate agreement

Missing BAAs are one of the most common and most avoidable HIPAA violations. Regulators have repeatedly penalized covered entities that disclosed PHI to a vendor without a signed agreement, sometimes for substantial settlements, even when no breach actually occurred. The violation is the disclosure without the contract, not just the harm.

For a business associate, the risk is now direct. A vendor that handles PHI without proper BAAs, or that fails to flow agreements down to its own subcontractors, can be investigated and fined on its own. And when a breach does happen, the absence of a BAA turns a manageable incident into a clear regulatory failure for every party in the chain.

The fix is inexpensive relative to the risk: identify every party that touches PHI, put a compliant BAA in place before any data moves, and keep the chain current as you add vendors.


For the surrounding program, see the HIPAA service page and the HIPAA compliance checklist. If you handle EU data too, GDPR and HIPAA compliance together covers the combined DPA/BAA approach, and SOC 2 and HIPAA compliance covers the framework most HealthTech buyers ask for first.


Frequently Asked Questions

Who is required to have a BAA? Any covered entity sharing PHI with a vendor that works on its behalf, and any business associate sharing that PHI with a subcontractor. The requirement flows down the whole chain, so every party that touches PHI on behalf of another needs a signed BAA before the data moves.

Is a BAA the same as an NDA? No. An NDA is a general confidentiality contract; a BAA is a HIPAA-mandated agreement imposing Security Rule safeguards, breach reporting, subcontractor flow-down, and return or destruction of PHI. An NDA does not satisfy HIPAA.

What is the difference between a DPA and a BAA? A DPA governs EU personal data under GDPR Article 28; a BAA governs US protected health information under HIPAA. They are parallel documents under different laws, and a single combined agreement can satisfy both only if it includes every required element of each.

Why would you use a business associate agreement? Because HIPAA legally requires it before PHI can be shared, and because it defines what the vendor may do with the data and obligates them to safeguard it and report breaches. Without it, the covered entity is in violation the moment PHI is disclosed.

Does a cloud provider like AWS need a BAA? Yes, if it stores or processes PHI. Guidance is clear that a cloud provider maintaining ePHI is a business associate even if the data is encrypted and it never accesses it, because the conduit exception covers only pure transmission, not storage.


Ready to Get Your BAAs in Order?

ShieldKey Solutions helps HealthTech SaaS companies map their PHI flows, identify every business associate relationship, and put compliant business associate agreements in place across the full subcontractor chain. We make sure no data moves before the paperwork does.

Schedule a scoping call →