Glossary · regulatory

What does “Business associate agreement” mean?

Short answer

A business associate agreement (BAA) is the contract HIPAA requires when a vendor handles patient health data for a provider. It sets the vendor's duties.

Also known as: BAA, HIPAA business associate contract

What it must say

Under 45 CFR 164.504(e), the contract must set how the vendor may use and share protected health information. The vendor, called the business associate, must agree to:

  • Use or share the data only as the contract allows or the law requires.
  • Use proper safeguards and follow the Security Rule for electronic data.
  • Report any misuse, including breaches of unsecured data.
  • Make sure subcontractors accept the same limits.
  • Support patient access, amendments and the list of disclosures, and open its records to HHS.
  • Return or destroy the data at the end, if feasible.

The covered entity, meaning the provider or health plan, must be able to end the contract for a material breach.

When you need one

A business associate creates, receives, keeps or sends protected health information for a covered entity. Examples are data analysis, quality assurance, patient safety work, billing and consulting. Subcontractors count too.

Example: a hospital adopts cloud software that stores patient names and details inside event reports. The vendor is a business associate, so a BAA must be in place before patient data flows. IncidentKit's Regulated plan includes a BAA.

Mix-up: a workplace injury report about an employee at a non-healthcare site holds no PHI, so it needs no BAA. A provider that receives treatment disclosures is not a business associate.

Frequently asked questions

Do we need a BAA for incident reporting software?

Yes, if the vendor handles protected health information for you, as it does when event reports hold patient names or details. With no patient data, a BAA is not the issue.

Does a business associate's subcontractor need an agreement?

Yes. The vendor must make sure any subcontractor that handles protected health information for it agrees to the same limits.

What happens to our data when the BAA ends?

If feasible, the vendor must return or destroy all protected health information it holds and keep no copies. If not, the contract's protections continue.

Sources

Reviewed against the sources above on Oct 5, 2026. Rules change: confirm current requirements with the issuing body or your counsel before relying on any summary.

Start free

Put the definition to work.

IncidentKit turns these terms into workflow: reports, investigations, corrective actions and packets.