HIPAA business associate agreement: what it must include
Every vendor that handles patient information for your practice needs a signed business associate agreement before it touches that information. Small practices usually have more of these vendors than they think, and a missing agreement is a finding on its own, even if nothing ever goes wrong.
Free preview before you pay. Editable Word files. 14 day refund.
Who counts as a business associate
A business associate is a person or company that creates, receives, maintains, or transmits protected health information for your practice, or provides a service to it that involves that information. It is defined by what the vendor does, not by what the vendor calls itself. Typical examples in a small practice:
- Your EHR or practice management software vendor
- IT support, managed service providers, and anyone with remote access to your computers
- Cloud backup, cloud storage, and hosted email
- Billing companies, collection agencies, and clearinghouses acting for you
- Appointment reminder, texting, answering, and online intake services
- Shredding and records storage companies
- Transcription and coding services
- Attorneys, accountants, and consultants who see patient information in their work for you
Who usually does not
A cloud service that stores your patient data is a business associate even if the data is encrypted and the vendor holds no key. HHS guidance on cloud computing says so directly.
- Your own workforce. Employees, volunteers, and trainees under your direct control are workforce members, not business associates.
- Other providers treating the patient. Sending records to a specialist or a lab for treatment needs no business associate agreement.
- Pure conduits. The postal service and internet carriers that only transmit data, and do not store it beyond what transmission needs, are generally not business associates.
What the agreement must say
The required terms are in 45 CFR 164.504(e), and for electronic information in 164.314(a). In plain English, the agreement must:
- Describe what the business associate may and must do with the information, and nothing beyond what your practice itself could do
- Prohibit any other use or disclosure, except as the agreement allows or the law requires
- Require appropriate safeguards, including compliance with the HIPAA Security Rule for electronic information
- Require the business associate to report any use or disclosure the agreement does not allow, including breaches of unsecured information and security incidents
- Require the same restrictions to flow down to any subcontractor that handles the information
- Make information available so you can meet patient requests for access, amendment, and an accounting of disclosures
- Require compliance with the Privacy Rule for any of your obligations the business associate carries out for you
- Make its books and records available to HHS when HHS reviews your compliance
- Return or destroy the information when the agreement ends, where that is feasible
- Let you end the agreement if the business associate breaks a material term
Mistakes we see in small practices
- No agreement with the IT person, especially an informal one.
- A free consumer email or file sharing account whose provider will not sign a business associate agreement.
- Assuming a large vendor is covered automatically. Many offer an agreement, but you usually have to accept it, and sometimes only on a paid plan.
- Signed agreements nobody can find. Keep them for six years after they end.
- No list of vendors, so nobody knows which agreements are missing.
Your template or theirs?
Many large vendors insist on their own business associate agreement. That is fine, as long as it covers the required terms above. Your own template is for vendors who do not have one, usually smaller local businesses such as an IT contractor or a shredding company. HHS publishes sample business associate agreement provisions on its website, which are a useful reference.
The kit includes a business associate agreement with your practice details filled in, ready for vendors to sign, and its adoption checklist walks you through listing every vendor so you can see which agreements are missing.
Questions
Is a business associate agreement required by law?
Yes. HIPAA lets a covered entity share protected health information with a business associate only after getting satisfactory written assurance, in a contract, that the business associate will safeguard it.
Does my IT contractor need to sign a BAA?
Almost always. Anyone who can access computers or systems holding patient information in the course of their work for you is a business associate.
Do I need a BAA with my EHR vendor?
Yes. Most EHR vendors provide their own agreement. Make sure it is accepted or signed and kept on file.
How long do I keep BAAs?
HIPAA documentation must be kept for six years from the date it was created or the date it was last in effect, whichever is later.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance for dental offices: what auditors actually check
- HIPAA compliance checklist for small medical practices in California
- The HIPAA security risk assessment, explained for small practices
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
- HIPAA compliance checklist for small practices, 2026
- HIPAA breach notification deadline calculator
- Free HIPAA policy templates: where to get them, and what they leave out
- HIPAA training requirements for small practices
- HIPAA policies for podiatry practices
- HIPAA policies for dermatology practices
- HIPAA policies for pediatric practices
- HIPAA for acupuncture practices
- HIPAA policies for speech therapy practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.