# Business associate agreement

> A business associate agreement (BAA) is the contract HIPAA requires when a vendor handles patient health data for a provider. It sets the vendor's duties.

Source: https://incidentkit.ai/glossary/business-associate-agreement · Updated Oct 5, 2026

Also known as: BAA, HIPAA business associate contract

## What it must say

Under 45 CFR 164.504(e), the contract must set how the vendor may use and share protected health information. The vendor, called the business associate, must agree to:

- Use or share the data only as the contract allows or the law requires.
- Use proper safeguards and follow the Security Rule for electronic data.
- Report any misuse, including breaches of unsecured data.
- Make sure subcontractors accept the same limits.
- Support patient access, amendments and the list of disclosures, and open its records to HHS.
- Return or destroy the data at the end, if feasible.

The covered entity, meaning the provider or health plan, must be able to end the contract for a material breach.

## When you need one

A business associate creates, receives, keeps or sends [protected health information](https://incidentkit.ai/glossary/phi) for a covered entity. Examples are data analysis, quality assurance, patient safety work, billing and consulting. Subcontractors count too.

Example: a hospital adopts cloud software that stores patient names and details inside event reports. The vendor is a business associate, so a BAA must be in place before patient data flows. IncidentKit's Regulated plan includes a BAA.

Mix-up: a workplace injury report about an employee at a non-healthcare site holds no PHI, so it needs no BAA. A provider that receives treatment disclosures is not a business associate.

## Frequently asked questions

### Do we need a BAA for incident reporting software?

Yes, if the vendor handles protected health information for you, as it does when event reports hold patient names or details. With no patient data, a BAA is not the issue.

### Does a business associate's subcontractor need an agreement?

Yes. The vendor must make sure any subcontractor that handles protected health information for it agrees to the same limits.

### What happens to our data when the BAA ends?

If feasible, the vendor must return or destroy all protected health information it holds and keep no copies. If not, the contract's protections continue.

## Sources

- [45 CFR 164.504(e): Business associate contracts](https://www.ecfr.gov/current/title-45/section-164.504)
- [45 CFR 160.103: HIPAA definitions (protected health information, business associate)](https://www.ecfr.gov/current/title-45/section-160.103)

## Related terms

- [Protected health information (PHI)](https://incidentkit.ai/glossary/phi)
- [Patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization)
- [Incident report](https://incidentkit.ai/glossary/incident-report)
- [Variance report](https://incidentkit.ai/glossary/variance-report)

## Related

- [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa)
- [IncidentKit security overview](https://incidentkit.ai/security)
- [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing)
- [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting)
- [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals)
