Compliance

Business associate agreements: what has to be in one

Most people looking for a BAA template are looking for the wrong artefact. The contents are not left to the parties to invent — 45 CFR 164.504(e) sets out what the contract must establish, and a document missing those terms is not a business associate agreement whatever it is titled.

So the useful thing is not a template. It is a list of what must be there, so you can read the paper a vendor has already sent you and tell whether it is real.

What the regulation requires.

Paraphrased in the order 45 CFR 164.504(e)(2) sets them out. This is the checklist to read a vendor's paper against.

  1. Establish the permitted and required uses and disclosures of PHI by the business associate, and no more than the covered entity could lawfully make itself.
  2. Provide that the business associate will not use or further disclose the information except as the contract permits or the law requires.
  3. Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
  4. Require the business associate to report uses and disclosures the contract did not provide for, including breaches of unsecured PHI.
  5. Require the business associate to bind its own subcontractors to the same restrictions and conditions.
  6. Require PHI to be made available so the covered entity can meet individual access requests.
  7. Require PHI to be made available for amendment, and amendments to be incorporated.
  8. Require the information needed to account for disclosures to be made available.
  9. Require the business associate to make its internal practices, books and records available to HHS, and — where it carries out an obligation of the covered entity — to comply with the rules applying to that obligation.
  10. Require return or destruction of all PHI at termination, if feasible, with no copies retained.
  11. Authorise the covered entity to terminate the contract if the business associate materially breaches it.

The operative sentence, from the regulation.

A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity.

45 CFR 164.504, Uses and disclosures: Organizational requirements, paragraph (e)(2) · checked August 31, 2026

The second half is the part that gets skipped: a BAA cannot authorise the vendor to do anything with PHI that you could not lawfully do yourself. So a clause granting a vendor broad rights to use “de-identified or aggregated” data is worth reading slowly, because de-identification is a technical standard rather than a description.

The four clauses that decide what happens when it goes wrong.

Every compliant BAA contains the required elements. These are the terms that differ between vendors, and they are the ones a template leaves generic.

The breach notification window

The regulation requires reporting; it does not set the vendor’s deadline for telling you. That number is negotiated, and it matters because your own sixty-day clock for notifying affected individuals starts when the breach is discovered — including discovery by your business associate. A BAA that says "without unreasonable delay" and nothing else has moved a hard obligation of yours onto a soft promise of theirs. Ask for a specific number of days.

The subcontractor list

A subcontractor that handles PHI on your vendor’s behalf is a business associate in its own right and needs its own agreement. In a messaging product that chain typically includes the cloud host, the push-notification service and possibly an SMS gateway. The contract will promise the chain is papered; the useful question in a call is who is actually in it, because that is the layer where PHI leaves through a service nobody at your clinic has heard of.

What "if feasible" is doing at termination

The return-or-destroy obligation is qualified: where return or destruction is not feasible, the protections simply extend to whatever remains. Backups are the usual reason it is not feasible. That is a reasonable engineering position and it means your data may persist after you leave, so the clause to read is the one describing retention windows rather than the one promising destruction.

Whether the agreement survives the sales conversation

A BAA presented as a click-through inside a self-serve signup is still a contract, but it is one you did not negotiate and can be amended by notice. For anything carrying a caseload, get a countersigned copy with a date on it and keep it where your compliance file is, not in an inbox. If a vendor cannot produce a countersigned BAA, they have not really signed one.

What HHS says about its own template.

This document includes sample business associate agreement provisions to help covered entities and business associates more easily comply with the business associate contract requirements. While these sample provisions are written for the purposes of the contract between a covered entity and its business associate, the language may be adapted for purposes of the contract between a business associate and subcontractor.

U.S. Department of Health and Human Services, Business Associate Contracts — Sample Business Associate Agreement Provisions · checked August 31, 2026

“Sample provisions” and “may be adapted” are doing real work in that sentence. The document contains bracketed alternatives to choose between, no commercial terms, and none of the numbers that matter operationally. It is a conformance check, not a contract, and it is worth downloading for exactly that.

Six questions worth more than the template.

A signed BAA answers one question. These are the ones a procurement call should actually spend its time on.

Will you sign our BAA, or do we sign yours?

Either is fine. A vendor with a standard BAA of its own is usually a vendor that has done this before. A vendor that will only accept its own paper with no redlines is telling you about its size, not its position.

When does it need to be signed?

Before PHI moves. Not during onboarding, not before go-live. There is no grace period and a BAA dated after the first import does not retroactively authorise it.

Who are your subcontractors for PHI?

Ask for the list, not the assurance. Hosting, push notifications, error monitoring and analytics are the four places PHI escapes in a mobile product.

How fast will you tell us about a breach?

A number. Your notification obligations run on a clock that starts at discovery, including theirs.

Show me the audit log.

This is a software question rather than a contract one, and a signed BAA does not answer it. If nobody can produce the screen in a demo, assume it does not exist.

What happens to our data if we leave?

Export format, retention window, and what "if feasible" covers in their environment. Ask before signing, not at the point you want it back.

None of this is legal advice, and a BAA is a contract your clinic is signing. The point of the list is to make the conversation with your own counsel a short one, by arriving at it already knowing which clauses you care about.

Where this goes wrong in ABA specifically.

Almost never at the practice management system. That was bought deliberately, by someone senior, and it came with a BAA — CentralReach, Motivity and Theralytics all state plainly that they act as business associates. The exposure is the free tool one site adopted on a Tuesday because a parent asked for photos, which never reached a procurement conversation and therefore never reached the question.

Which is why the audit worth running is not of your contracts but of your channels: list every route by which something about a named child currently leaves the building, and check each one against a signed agreement. The list is always longer than the contract file. See HIPAA-compliant parent communication for ABA clinics for what each of those tools says about itself, and the BAA definition for the short version of this page.

Questions clinics ask about this.

Is there an official business associate agreement template?

HHS publishes sample business associate agreement provisions, which is the closest thing to an official template and the only one with any authority behind it. It is explicitly a set of provisions to adapt rather than a complete contract — it contains bracketed choices, omits the commercial terms entirely, and leaves the numbers that matter in practice, such as breach notification timelines, for the parties to set. Use it to check what you have been sent, and have counsel read whatever you actually sign.

What must a business associate agreement include?

The elements at 45 CFR 164.504(e): the permitted and required uses and disclosures; a prohibition on any other use; appropriate safeguards including Security Rule compliance for ePHI; reporting of unauthorised uses, disclosures and breaches; an obligation to bind subcontractors to the same terms; cooperation with individual access, amendment and accounting-of-disclosures requests; availability of the business associate’s books and records to HHS; return or destruction of PHI at termination; and the covered entity’s right to terminate for material breach. A document missing these is not a BAA whatever it is titled.

What is the purpose of a business associate agreement?

To make a vendor contractually accountable for protected health information before it reaches them. HIPAA reaches vendors as well as providers, and a contract is the mechanism it uses: the BAA is what converts a supplier relationship into one with defined obligations around safeguarding, breach reporting, subcontractors and the fate of the data at the end.

Who signs a business associate agreement?

The covered entity and the business associate. For an ABA clinic that means you and every vendor that creates, receives, maintains or transmits PHI on your behalf: practice management system, parent communication app, billing service, cloud backup, an IT contractor with access to systems holding PHI, a shredding company. Your business associate must in turn have one with each of its own subcontractors that touches the data.

When is a business associate agreement required?

Before PHI is disclosed to the vendor. It is required whenever a person or company performs a function or service for you involving PHI, and it is not required for disclosures to another provider for treatment purposes, for a plan sponsor in the narrow circumstances the rule describes, or for a true conduit that transports data without routine access to it. The conduit exception is much narrower than vendors sometimes claim.

Do business associate agreements accomplish anything on their own?

They allocate responsibility and create a contractual and regulatory hook — since 2013 a business associate has direct liability under much of HIPAA, not merely liability to you. What a BAA does not do is verify anything: it does not tell you whether the product has audit controls, whether access can be scoped to a caseload, or whether a departing employee can be locked out. It is a floor, not a verdict.

Do we need a BAA with our landlord, cleaner or shredding company?

Shredding, yes — a document destruction company handles PHI on your behalf. A cleaner or landlord who may incidentally see PHI while doing something unrelated is generally not a business associate, because the exposure is incidental rather than a function you engaged them to perform. Physical safeguards are the right control there, not a contract.

Does a free tool need a BAA?

Yes. Nothing in the rule turns on price, and the free tool is where this fails most often in ABA — not because a vendor refused to sign, but because a single site adopted something at no cost, so nobody ever reached the point of asking. If PHI is in it, it needs a signed agreement or it needs to stop.

Related

Sources

The definitions on this page are quoted from the regulation itself rather than from a summary of it, linked below with the date we last read them there. This is a plain-language explanation for people evaluating software, not legal advice.

  1. [1] 45 CFR 164.504Uses and disclosures: Organizational requirements, paragraph (e)(2) · checked August 31, 2026
  2. [2] 45 CFR 164.504Uses and disclosures: Organizational requirements, paragraph (e)(2)(ii)(J) · checked August 31, 2026
  3. [3] 45 CFR 160.103Definitions — “Business associate”, paragraph (1)(i) · checked August 31, 2026
  4. [4] 45 CFR 160.103Definitions — “Business associate”, paragraph (3)(iii) · checked August 31, 2026
  5. [5] U.S. Department of Health and Human ServicesBusiness Associate Contracts — Sample Business Associate Agreement Provisions · checked August 31, 2026

We sign your BAA before anything goes in.

Not at go-live, not during onboarding. Before a single child is loaded. Fifteen minutes with the founder if you want to see the rest.