Glossary

What is a BAA?

A Business Associate Agreement is a written contract between a healthcare provider and a vendor that handles protected health information on its behalf, setting out how that vendor may use, safeguard and disclose the information.

HIPAA does not only bind healthcare providers. It reaches the companies they hand data to, and the mechanism it uses is a contract. If a vendor stores, transmits or processes protected health information for your clinic, that vendor is a business associate, and the relationship has to be papered before the data moves.

The practical consequence is that a BAA is a gate rather than a formality. A vendor with excellent security who will not sign one is not an option for PHI, and a vendor who will sign one has accepted defined obligations around safeguarding the data, reporting breaches, limiting subcontractors and returning or destroying information at the end of the relationship.

This is why "is it encrypted?" is the wrong opening question in a procurement call. Encryption is a control. A BAA is permission. Plenty of well-engineered products decline to sign because healthcare is not a market they want, and that is a legitimate business decision that simply removes them from your shortlist.

The contents are not left to the parties to invent. 45 CFR 164.504(e) sets out what the contract must establish, and a BAA that omits those terms is not a BAA no matter what it is titled. The obligations run downstream too: a subcontractor that handles PHI on the business associate’s behalf is itself a business associate and needs its own agreement, which is the layer clinics almost never ask about.

In an ABA clinic specifically.

Ask for the BAA before any child is loaded into a system, not during onboarding. The commonest failure in ABA is not a vendor refusing to sign — it is a tool that was adopted informally by a site, for free, so nobody ever reached the point of asking.

Questions people ask about BAAs.

What is the purpose of a business associate agreement?

To make a vendor contractually accountable for protected health information before it reaches them. It establishes exactly what the vendor may do with the data, obliges them to safeguard it, to report breaches, to bind their own subcontractors to the same terms, to make the information available for access and amendment requests, and to return or destroy it when the relationship ends. It also gives the covered entity the right to terminate for a material breach.

What must a business associate contract include?

The permitted and required uses and disclosures of PHI; a prohibition on any other use; appropriate safeguards, including Security Rule compliance for ePHI; breach and incident reporting; the obligation to bind subcontractors to the same conditions; cooperation with individual access, amendment and accounting-of-disclosures requests; availability of the business associate’s books and records to HHS; return or destruction of PHI at termination; and the covered entity’s right to terminate for material breach.

Who needs to sign a business associate agreement?

The covered entity and the business associate. In practice that means your clinic and any vendor that creates, receives, maintains or transmits PHI for you: your practice management system, your parent communication app, your billing service, your cloud backup provider, your IT contractor with access to systems holding PHI, your shredding company. A business associate must in turn sign one with each of its own subcontractors that touches the data.

When is a business associate agreement required?

Before PHI is disclosed to the vendor, not afterwards. There is no grace period during onboarding, and a signed agreement dated after the data moved does not retroactively authorise the disclosure. It is required whenever the vendor performs a function or service for you that involves PHI — and not required for a provider you disclose to for treatment purposes, for a plan sponsor in the narrow circumstances the rule describes, or for a conduit that merely transports data without routine access to it.

Do I need a BAA with a subcontractor?

Your business associate does. The regulation makes a subcontractor that creates, receives, maintains or transmits PHI on a business associate’s behalf a business associate in its own right, and the chain has to be papered at every link. You contract with your vendor; your vendor contracts with its hosting provider, its push-notification service and anyone else in the path. It is a fair question to ask a vendor how far down that chain they have actually done it.

Is there a business associate agreement template?

HHS publishes sample business associate agreement provisions, and most vendors that handle PHI at scale will present their own paper. A template is a starting point rather than an answer: the sample provisions are explicitly not a complete contract, and the terms that matter in practice — breach notification timelines, subcontractor disclosure, what happens to your data at termination — are the ones a template leaves generic. Have counsel read whichever paper you end up signing.

What happens to our data when a BAA ends?

The contract has to require the business associate to return or destroy all PHI it still holds and retain no copies, if that is feasible; where it is not feasible, the protections of the agreement extend to whatever remains and further use is limited accordingly. This is the clause worth reading before you sign rather than at the point you want to leave, because "feasible" is doing a lot of work in that sentence.

Does ClassDojo sign a business associate agreement?

Not for healthcare use, on the evidence of its own published compliance position: ClassDojo describes itself as fully compliant with COPPA, FERPA and GDPR, which are the statutes that govern schools and consumer services rather than covered entities. The same pattern holds across the school communication category. Ask the vendor directly and in writing, and treat the absence of a HIPAA claim on a compliance page as the answer until they say otherwise.

Written by Abdihafid, a behavior technician working in an in-person ABA clinic. This is a plain-language explanation for people evaluating software, not legal advice, and it is not a substitute for your own compliance counsel.

Other terms

Sources

Claims about another product on this page are quotes from that product’s own documentation. Claims about what the law says are quotes from the regulation itself, not from anybody’s summary of it. Both are linked below with the date we last read them there.

  1. [1] 45 CFR 160.103Definitions — “Business associate”, paragraph (1)(i) · checked August 31, 2026
  2. [2] 45 CFR 164.504Uses and disclosures: Organizational requirements, paragraph (e)(2) · checked August 31, 2026
  3. [3] 45 CFR 160.103Definitions — “Business associate”, paragraph (3)(iii) · checked August 31, 2026
  4. [4] 45 CFR 164.504Uses and disclosures: Organizational requirements, paragraph (e)(2)(ii)(J) · checked August 31, 2026
  5. [5] ClassDojoPrivacy and Security · checked August 26, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.