A Business Associate Agreement is the written contract HIPAA requires whenever a covered entity, or another business associate, hands protected health information to an outside party that will handle it. The rules on Business Associate Agreements under HIPAA come from 45 CFR 164.504(e), and they set out ten specific provisions the contract must contain, plus a set of situations where no agreement is needed at all. Get the agreement wrong, or skip it entirely, and both sides can face federal penalties reaching $2,190,294 per identical violation in a calendar year.
When You Need a BAA
The requirement is triggered by two things happening together: a HIPAA-covered entity (or an existing business associate) is sharing PHI, and the recipient is outside the workforce and will perform a service that involves that PHI.
Covered entities fall into three categories: healthcare providers who transmit information electronically, health plans, and healthcare clearinghouses.1HHS.gov. Covered Entities and Business Associates The outside parties they hire are business associates. Medical billing companies, IT and cloud vendors, document shredding services, and accounting or law firms that touch patient records are typical examples.2U.S. Department of Health & Human Services. Sample Business Associate Agreement Provisions
The chain doesn’t stop at the first outside vendor. If a business associate hires its own subcontractor that will handle PHI, the business associate must put a BAA in place with that subcontractor containing the same restrictions that flowed down from the covered entity.2U.S. Department of Health & Human Services. Sample Business Associate Agreement Provisions
One point that trips people up: a covered entity’s own employees are not business associates. A nurse or billing clerk on the payroll handles PHI daily without needing a BAA. The requirement applies only when PHI leaves the workforce.3HHS.gov. Business Associates
When You Don’t Need One
Several categories of PHI sharing sit outside the BAA requirement, and knowing them keeps compliance effort focused on the relationships that actually create exposure.
Provider-to-provider treatment disclosures. When one covered entity sends PHI to another covered entity for treatment, no BAA is needed. A hospital referring a patient to a specialist and sending the chart is the standard example. Both sides are already bound by HIPAA on their own.3HHS.gov. Business Associates
Conduits. Entities that only transport PHI without routinely accessing or storing it are not business associates. HHS specifically names the U.S. Postal Service, certain private couriers, and their electronic equivalents such as telecommunications companies that transmit data without interacting with its contents.3HHS.gov. Business Associates The line is transient access. A courier carrying sealed records qualifies. A cloud storage vendor that hosts PHI on its servers does not.
Disclosures required by law. When a covered entity discloses PHI because a law requires it, such as mandatory disease reporting to public health authorities, the recipient is not a business associate.
Research under certain conditions. A covered entity can share PHI with a researcher without a BAA when the disclosure is made under patient authorization, an approved waiver, or as a limited data set. The researcher is not performing a HIPAA-regulated function for the covered entity in those situations.3HHS.gov. Business Associates
De-identified data. Data that has been properly de-identified under HIPAA’s standards is no longer PHI. A vendor that only receives de-identified data needs no BAA because there is nothing to protect.4eCFR. 45 CFR 164.514
Limited data sets. A limited data set strips direct identifiers like names, addresses, and Social Security numbers, but may still include dates and zip codes. Sharing one requires a separate data use agreement, not a BAA, and the two contracts have different required terms.4eCFR. 45 CFR 164.514
The Ten Required Provisions
HHS lists ten elements that a compliant BAA must contain. Skipping any one of them can make the whole agreement legally deficient.2U.S. Department of Health & Human Services. Sample Business Associate Agreement Provisions
- Define permitted uses and disclosures of PHI. The contract cannot authorize anything that would violate HIPAA if the covered entity did it directly.
- Prohibit the business associate from using or further disclosing PHI beyond what the contract permits or the law requires.
- Require appropriate administrative, physical, and technical safeguards, including Security Rule compliance for electronic PHI.
- Require the business associate to report any unauthorized use or disclosure, including breaches of unsecured PHI.
- Require the business associate to make PHI available so patients can exercise their access, amendment, and accounting-of-disclosures rights.
- Require the business associate to open its internal practices, books, and records to HHS for compliance review.
- Require return or destruction of all PHI at contract termination, where feasible.
- Require the same restrictions to flow down to any subcontractor that handles PHI.
- Give the covered entity the right to terminate the agreement for material violations.
Parties often add clauses on top of these minimums, such as indemnification, insurance requirements, or audit rights over the business associate’s security practices. Those extras are negotiable. The items above are not.
Breach Notification Inside the BAA
A business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery.5eCFR. 45 CFR 164.410 That’s the regulatory backstop. In practice, many covered entities negotiate a shorter window into the BAA itself, often 10 or 30 days, because the covered entity has its own 60-day clock running for notifying affected individuals and HHS.6HHS.gov. Submitting Notice of a Breach to the Secretary A business associate that waits the full 60 days can leave the covered entity with no time to meet its own obligations. This is often the most contentious clause in a BAA negotiation.
Direct Liability and Penalties
Before 2009, HHS could only enforce HIPAA against covered entities. The HITECH Act, passed that year and implemented by regulations finalized in 2013, made business associates directly liable for Security Rule compliance and breach notification.7HHS.gov. Direct Liability of Business Associates A business associate can now be fined by HHS’s Office for Civil Rights on its own, independent of any breach-of-contract claim from the covered entity. A well-drafted BAA does not shield either side from these direct penalties.
Civil penalties are tiered by fault and adjusted annually for inflation. As published by HHS in January 2026:8Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
- No knowledge of the violation: $145 to $73,011 per violation.
- Reasonable cause, not willful neglect: $1,461 to $73,011 per violation.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation.
- Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation.
Each tier carries a calendar-year cap of $2,190,294 for all violations of an identical provision. Because most breaches involve multiple violations, often one per affected record, penalties can stack.
Criminal penalties also apply when someone knowingly obtains or discloses PHI in violation of HIPAA. The base offense carries up to $50,000 in fines and one year in prison. False pretenses push the ceiling to $100,000 and five years. Violations committed with intent to sell, transfer, or use health information for commercial gain or malicious purposes can reach $250,000 and ten years.9Office of the Law Revision Counsel. 42 USC 1320d-6
OCR investigates through both complaints and periodic audits authorized by the HITECH Act. Missing or deficient BAAs are among the most common findings.10HHS.gov. OCR’s HIPAA Audit Program The fix is straightforward: get the agreement in place before the relationship starts. Organizations routinely fail to do so with vendors they’ve worked with informally for years.
State Law on Top of HIPAA
HIPAA sets a federal floor. When a state law offers greater privacy protection, by restricting disclosures more tightly, expanding patient access, or requiring more detailed consent, the state law controls. Some states impose additional restrictions on specific categories of information, such as mental health records, substance abuse treatment data, or reproductive health information. A BAA that only tracks HIPAA’s minimums may be insufficient for operations in those states, and language typically has to be tailored jurisdiction by jurisdiction.
Proposed Security Rule Changes That Would Affect BAAs
HHS published a proposed rule in December 2024 that, if finalized, would reshape two BAA-related obligations:11HHS.gov. HIPAA Security Rule Notice of Proposed Rulemaking
- Business associates would have to verify at least once every 12 months, through a written analysis by a subject matter expert, that they have deployed the required Security Rule technical safeguards. The certification would flow up to the covered entity.
- Business associates would have to notify covered entities within 24 hours of activating a contingency plan, a far tighter window than the current 60-day breach notification deadline.
The proposal would also require encryption of electronic PHI at rest and in transit, with limited exceptions, and expand risk assessment obligations. As of early 2026 these remain proposals. Organizations signing new BAAs now may want to build in room for these requirements rather than reopen the contract later.