{"@context":"https://schema.org","@type":"Article","headline":"Business associate agreement","description":"Learn when HIPAA requires a business associate agreement, how roles and exceptions work, which terms matter, and why a BAA alone does not establish compliance.","url":"https://finnihealth.com/resources/glossary/business-associate-agreement","datePublished":"2026-08-15T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Business associate agreement","item":"https://finnihealth.com/resources/glossary/business-associate-agreement"}]}}
Glossary term

Business associate agreement

Learn when HIPAA requires a business associate agreement, how roles and exceptions work, which terms matter, and why a BAA alone does not establish compliance.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

BAA business associate contract

When is a business associate agreement required? A business associate agreement, or BAA, is generally required when a HIPAA covered entity or business associate engages another person or organization to create, receive, maintain, or transmit protected health information on its behalf in a business-associate role. Classify the parties, function, information, and exceptions before signing, then verify the contract and actual workflow.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Start by classifying the covered entity

The HIPAA Rules apply to covered entities and business associates. HHS identifies covered entities as health plans, health care clearinghouses, and health care providers that transmit information electronically in connection with a transaction for which HHS adopted a standard.

An ABA provider is not a HIPAA covered entity solely because it delivers healthcare. Confirm the practice's actual transaction activity, organizational structure, hybrid status, and role. Other privacy and contract rules can apply even when HIPAA does not.

Identify the function performed on behalf of the practice

Current 45 CFR 160.103 generally defines a business associate as a person outside the covered entity's workforce that handles PHI on its behalf for regulated functions or provides a listed service involving PHI. Examples can include billing, claims processing, practice management, data analysis, quality assurance, consulting, accounting, legal, or administrative services.

A business associate's subcontractor can also be a business associate when it creates, receives, maintains, or transmits PHI on the business associate's behalf. The business associate obtains the subcontractor's required written assurances.

Use a role-and-data worksheet

For each relationship, write the covered entity, business associate, subcontractor, workforce, or independent provider role being evaluated. Describe the function, whose behalf it serves, the PHI involved, how access occurs, and whether an exception applies. Then name the required agreement and the parties that sign it.

Avoid classifying a company once for every service it offers. The same organization may act as a business associate for hosted billing, as an independent provider for treatment, and outside HIPAA for a separate consumer product. Keep each activity and contract distinct. Revisit the worksheet after a product feature, subprocessor, data use, corporate party, or service scope changes.

Record help-desk hours and emergency contacts for each agreement.

A BAA is not required for every recipient

Role and purpose matter. HHS business-associate guidance describes exceptions including a covered entity's disclosure to another healthcare provider for treatment and ordinary financial transactions that only move funds. A workforce member is not a business associate.

Selling software alone does not automatically create business-associate status when the vendor lacks PHI access. A cloud vendor that maintains ePHI on behalf of a covered entity can be a business associate even when it cannot decrypt the data. Route uncertain facts to the privacy or legal owner rather than using a blanket vendor label.

Put the required assurances in writing

HHS explains that the written agreement must describe permitted and required PHI uses and disclosures, restrict other use or disclosure, and require appropriate safeguards. Depending on the relationship, it also addresses incident and breach reporting, subcontractors, access and amendment support, accounting obligations, HHS access, return or destruction, and termination.

The HHS sample provisions offer a starting structure. Tailor the agreement to the actual service, data, parties, law, and operational responsibilities. Preserve duties that cannot be shifted away by contract.

A fictional relationship review

Farah's practice locks 14 vendor relationships for renewal. Eleven have a documented entity classification, function, PHI flow, exception analysis, correct contracting parties, required agreement, and deployed-control owner: 11 of 14, or 78.6%.

One vendor may be ordinary banking. One provides treatment in its own provider role. One uses a new subprocessor. The privacy owner and counsel review those facts. All three stay open in the denominator. The ratio measures completed classification, not HIPAA compliance.

The contract is one control

A signed BAA cannot establish that the underlying use is permitted, the data is minimum necessary, access is limited, encryption works, the vendor follows the terms, or the product is accurate. Review the deployed workflow, configuration, user access, support tools, logs, retention, subprocessors, and deletion.

The HHS Privacy Rule page provides the broader federal framework for PHI uses, disclosures, and individual rights. Map state health, consumer-health, minor, biometric, breach, and record laws separately.

Manage the complete relationship

Before access begins, confirm the agreement, security review, permitted use, configuration, account owners, incident route, and data inventory. During service, monitor material changes, incidents, control evidence, and subcontractors. At exit, remove access, reconcile open work, return required data, preserve records, and obtain deletion evidence where applicable.

Keep the BAA linked to the master agreement, product, environment, vendor legal entity, data flow, effective dates, and owner. A BAA with the wrong corporate party or a service omitted from scope can create false confidence.

At renewal, make a fresh continue, narrow, remediate, or exit decision from the current service and evidence. A signed agreement should never turn an unresolved subprocessor, unsupported deletion claim, or changed data use into automatic approval.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Explore clinical roles at Finni practices