Table of Contents
The Short Answer
A business associate agreement is the written contract HIPAA requires between a covered entity and a business associate: an outside party that creates, receives, maintains, or transmits protected health information on the covered entity's behalf for regulated functions. Covered entities are health plans, health care clearinghouses, and health care providers that transmit health information electronically for covered transactions, which in practice includes most practices and clinics that bill electronically. The BAA binds the vendor to HIPAA's safeguards, restricts what it may do with PHI, and defines what happens when something goes wrong. The operating rule that follows: before a vendor handles PHI on your behalf, the written arrangement HIPAA requires must be in place, no matter what the vendor's marketing page says about compliance.
The concept is decades old. What changed is the vendor list. A typical practice now routes patient information through schedulers, transcription tools, chat widgets, analytics, and AI assistants, and every one of those that handles PHI on your behalf belongs on your BAA inventory. This guide covers what the agreement is, what the regulation actually requires it to say, and the verification habits that matter now that AI tools are in the mix. It is practical guidance, not legal advice; your BAA templates and edge cases belong with your counsel.
Who Is a Business Associate?
A business associate is any person or organization, outside your own workforce, that performs functions or services for you involving protected health information. The classic examples: billing companies, transcription services, IT providers with access to systems holding PHI, cloud hosts storing patient records, email providers carrying patient communications, and consultants who see charts.
The test is function and access, not industry. A software vendor becomes your business associate when its service creates, receives, maintains, or transmits PHI on your behalf, whether that service is a practice management system or an AI scribe listening to visits. Subcontractors inherit the obligation in the same shape: anyone who creates, receives, maintains, or transmits PHI on the business associate's behalf must agree to the same restrictions and conditions, which is why serious vendors maintain their own BAAs downstream with their cloud and AI providers.
Two common non-examples worth knowing, both grounded in the definitions at 45 CFR 160.103: a vendor whose service never touches PHI (a website host serving only your public marketing site, for instance) is not a business associate, and a health care provider receiving disclosures from a covered entity concerning the treatment of an individual is not acting as a business associate in that exchange.
What the Regulation Requires a BAA to Contain
The required contents are not folklore; they are enumerated in the regulation at 45 CFR 164.504(e). Among the provisions the contract must contain:
- Limit use and disclosure. The BAA may not authorize the business associate to use or disclose PHI in ways that would violate the Privacy Rule if you did them yourself.
- Require safeguards. The business associate must use appropriate safeguards and comply with the Security Rule for electronic PHI.
- Require reporting. Any use or disclosure not permitted by the contract, including breaches, must be reported to you.
- Bind subcontractors. Anyone downstream who creates, receives, maintains, or transmits PHI for the business associate must agree to the same restrictions and conditions.
- Handle termination. You must be able to terminate the contract for a material violation, and at termination the business associate must return or destroy PHI where feasible, with protections extending to any PHI that cannot feasibly be returned.
The full provision list runs longer: the contract must also address individuals' access to their PHI, amendment, accounting of disclosures, making records available to the Secretary of HHS, and compliance where the business associate carries out a covered entity's own Privacy Rule obligation. The regulation also permits narrow exceptions, such as uses for the business associate's proper management and administration and for data aggregation services. Your counsel's template should carry all of it; the summary above is the evaluation skeleton, not the whole contract.
Since the HITECH Act, business associates are directly liable for compliance with certain requirements of the HIPAA Rules, so the BAA is not merely you outsourcing risk; it is the legal frame in which both sides hold defined duties. When you read a vendor's BAA, the provisions above are the skeleton to check, and the interesting differences between vendors live in the specifics: breach notification timelines, data-return mechanics, and what "where feasible" means for deletion.
Why AI Tools Are the Most Missed BAA Category
Three patterns make AI tools the modern BAA blind spot.
Consumer tiers rarely include one. The free or standard tier of a general-purpose AI tool is typically not covered by a BAA, while a business or enterprise tier of the same product may be. Staff who paste clinical text into a personal AI account have moved PHI to a vendor with no BAA, no matter what tier the organization officially bought. We walk the tier-by-tier reality for the most common tools in is ChatGPT HIPAA compliant and is Otter.ai HIPAA compliant.
Training use needs its own answer. A BAA restricts use and disclosure, and what happens to your audio and text after processing (retention, model training, de-identification claims) deserves a written answer in or alongside the agreement. Our AI note-taker and scribe guide includes the verification questions we use.
The subcontractor chain got longer. An AI scribe may run on a cloud provider's models and infrastructure. Your BAA with the scribe vendor matters, and so does theirs downstream. You do not need to audit the whole chain yourself, but a vendor who cannot describe its own BAA coverage downstream is telling you something.
How to Verify a BAA Before PHI Moves
The working test we apply, and recommend, before any tool touches patient data:
- Get the BAA at your tier, in writing. Not a compliance page, the agreement itself, applicable to the exact plan you are buying.
- Check the core provisions. Use limits, safeguards, reporting, subcontractor flow-down, and termination, then the longer statutory list above. Read the breach-notification timeline and the data-return terms closely, because those are where vendors differ.
- Ask the training and retention questions. What is stored, for how long, whether anything feeds model training, and whether you can opt out in writing.
- Inventory it. Your risk analysis should list every business associate and the date of its BAA. An agreement nobody can find during an audit or a breach is close to no agreement at all.
For AI systems we build, this is architecture rather than paperwork alone: HIPAA compliant AI means the BAA chain, the access controls, the logging, and the retention rules are designed together, which is what an implementation for a medical practice actually involves.
The Cloud Layer: Platform BAAs
One more layer completes the modern picture: the infrastructure under your vendors. The major cloud providers formalized this years ago; AWS, for example, presents a standard Business Associate Addendum to customers and restricts PHI to its HIPAA-eligible services, and its peers run equivalent programs. That matters to you in two ways.
First, when your AI or software vendor runs on a cloud provider, the vendor's downstream BAA with that provider is part of the subcontractor chain the regulation requires. A vendor who can say "we hold a BAA with our cloud provider and PHI only touches eligible services" is describing a real, checkable control.
Second, when a system is built for you rather than bought, the platform BAA becomes your direct concern: the build should be architected onto HIPAA-eligible services under your own or your builder's BAA coverage, with the data path documented. This is a design input, not an afterthought, and it is one of the first questions we resolve when scoping a healthcare build.
Common BAA Mistakes
- Treating "HIPAA compliant" marketing as a BAA. The phrase on a website is not a contract. The signed agreement is.
- Buying the right tool at the wrong tier. The enterprise plan has a BAA; the tier your team actually uses does not.
- Forgetting the tools nobody procured. Shadow AI usage by staff is frequently a BAA gap, whenever PHI reaches a tool with no agreement behind it, and it is an organizational problem before it is a legal one. That is governance work, the kind our Fractional AI Office exists to run down for organizations where usage outran policy.
- Signing and shelving. Vendors change models, subcontractors, and retention practices. A BAA inventory with review dates beats a drawer of PDFs.
- Assuming a BAA equals compliance. The agreement is one required control. Your own risk analysis, safeguards, and training remain your obligations regardless of what any vendor signed.
FAQs
What is a business associate agreement in plain terms? The contract HIPAA requires between a healthcare organization and any outside vendor that handles patient information on its behalf. It restricts what the vendor can do with the data, requires safeguards and breach reporting, and extends the same duties to the vendor's subcontractors.
Who needs to sign a BAA? Any vendor that creates, receives, maintains, or transmits PHI for a covered entity: billing services, transcription and AI scribe vendors, cloud hosts storing patient data, email providers carrying patient communications, and IT or consulting firms with access to systems containing PHI.
Is a BAA required for AI tools? Yes, whenever the AI tool processes identifiable patient information on your behalf. The common failure is tier mismatch: the vendor offers a BAA on business plans while staff use free accounts that have none.
What must a BAA include? The regulation at 45 CFR 164.504(e) requires limits on use and disclosure, safeguards, reporting of violations and breaches, equivalent obligations for subcontractors, termination rights for material violations, and return or destruction of PHI at the end of the relationship.
Does a signed BAA make a vendor HIPAA compliant? No. It satisfies the written-arrangement requirement and binds the vendor to defined duties; it does not authorize otherwise impermissible uses or prove the vendor's actual practices match the paper. Your organization keeps its own compliance obligations, and the vendor's actual practices still need to match what it signed, which is why verification questions about storage, training use, and retention matter.
Who enforces BAAs? The HHS Office for Civil Rights enforces the HIPAA Rules, and since the HITECH Act business associates are directly liable for compliance with certain requirements of those Rules, alongside covered entities' own obligations. Separately, the FTC has warned companies against misleading claims about HIPAA compliance in their marketing.
---
Sources
- Legal Information Institute, "45 CFR 164.504 - Uses and disclosures: Organizational requirements," Cornell Law School. The regulation enumerating required business associate contract provisions: limits on use and disclosure, safeguards, reporting, subcontractor flow-down, and termination with return or destruction of PHI.
- Legal Information Institute, "45 CFR 160.103 - Definitions," Cornell Law School. Defines business associate (creates, receives, maintains, or transmits PHI on behalf of a covered entity for regulated functions), defines covered entity, and carries the treatment-disclosure exception for health care providers.
- U.S. Department of Health and Human Services, "Direct Liability of Business Associates". Documents that since the HITECH Act, business associates are directly liable for compliance with certain requirements of the HIPAA Rules.
- Legal Information Institute, "45 CFR 164.308 - Administrative safeguards," Cornell Law School. The Security Rule's administrative safeguards, including the requirement for written contracts before a business associate touches electronic PHI.
- Amazon Web Services, "HIPAA Compliance". Documents the platform-BAA pattern: AWS presents a standard Business Associate Addendum to customers and limits PHI to HIPAA-eligible services.
- Federal Trade Commission, "Collecting, Using, or Sharing Consumer Health Information?". The FTC's warning that false or misleading "HIPAA Compliant" claims can violate federal law, the enforcement backdrop for vendor marketing.