HIPAA Business Associate Agreement (BAA) guide for healthcare practices

What Is a HIPAA Business Associate Agreement (BAA)? A Guide

July 29, 2026

A HIPAA Business Associate Agreement, or BAA, is a written contract between a healthcare provider and any outside company that handles patient data on its behalf. It makes that company legally responsible for protecting the information and using it only in the ways the agreement allows. In plain terms, if a vendor can see, store, or send your patients' protected health information, you need a signed BAA with them before that data ever changes hands. No BAA, no compliant relationship, and that rule holds no matter how secure the vendor's software looks.

The BAA is the piece that quietly sits underneath every other compliance decision a practice makes. People obsess over whether a tool is encrypted or whether a text message is worded correctly, and those matter, but if the vendor behind the tool never signed a BAA, none of the rest counts. This guide explains what a BAA actually is, who needs one, what it has to contain, and what goes wrong without it.

What Is a Business Associate Agreement?

A BAA is a contract required by the HIPAA Privacy and Security Rules whenever a covered entity, such as a medical or wellness practice, hands protected health information to an outside party to do work on its behalf. That outside party is the business associate. The agreement binds them to safeguard the data, to use it only for the agreed purpose, and to report problems if they occur.

Think of it as the bridge that extends your compliance obligations to everyone who touches your patient data. HIPAA holds you responsible for that information even after it leaves your hands, so the BAA is how you pass the legal duty to protect it along to each vendor in the chain. The official framework, including sample contract language, lives on the HHS business associate contracts guidance.

Who Counts as a Business Associate?

A business associate is any person or company that creates, receives, stores, or transmits protected health information to perform a service for your practice. The label is about function, not industry, so it catches a lot of vendors that do not feel medical at all. Common examples include:

  • Your CRM or practice management system, which holds the patient records themselves.
  • Email and SMS providers, when messages involve patient data, the same concern behind HIPAA-compliant patient texting.
  • Cloud storage and file-sharing tools where patient documents live.
  • Billing and collections companies that process patient accounts.
  • IT providers, backup services, and anyone who can reach systems containing PHI.

Importantly, a business associate's own subcontractors count too. If your CRM vendor uses a third party that also touches the data, that chain needs to be covered as well. The obligation follows the data wherever it flows.

Do You Actually Need a BAA?

If a vendor can access protected health information in any form, then yes. The test is simple: does this company create, receive, store, or transmit PHI for us. If the answer is yes, a signed BAA is required before you share anything. If the vendor genuinely never touches patient data, no BAA is needed.

That line is easy to state and easy to get wrong, because plenty of everyday tools quietly hold patient data without anyone thinking of them as healthcare vendors. A booking widget, an email platform, a form tool, and a cloud drive can all end up holding PHI. The safe habit is to assume any system that stores contact records or messages tied to patients probably needs a BAA, then confirm.

Which of Your Vendors Need a BAA?

The quickest way to find your gaps is to list every tool that touches patient data and check each one. Here is how the common categories usually fall, and what to verify for each.

Vendor or toolDoes patient data flow through it?BAA needed?What to check
CRM / practice managementYes, it holds patient recordsYesWill they sign, and on which plan
Email and SMS providerYes, if messages touch PHIYesMost free tiers will not sign
Cloud storage / file sharingYes, if PHI is stored thereYesA healthcare or enterprise plan is usually required
Online booking / schedulingOften, appointments tie to a patientUsuallyWhether it stores a reason for visit
General website analyticsSometimes, if it captures identifiersIt dependsWhether tracking touches patient identity
Office snacks vendor, landlord, cleanersNoNoNo access to PHI means no BAA

The pattern is that anything holding patient records, messages, or documents almost always needs a BAA, while vendors with no path to patient data do not. When you are unsure, the deciding question is always whether protected health information could realistically pass through that tool, and if it could, treat it as needing an agreement.

What Must a BAA Include?

HIPAA sets out specific things a BAA has to cover, and the HHS sample provisions are a useful starting point. At a minimum, a solid agreement addresses:

  • Permitted uses and disclosures, spelling out exactly what the business associate may do with the data and nothing beyond that.
  • Required safeguards, committing the vendor to appropriate protections for the information they hold.
  • Breach and incident reporting, so the vendor must tell you promptly if something goes wrong.
  • Subcontractor obligations, ensuring anyone the vendor passes data to is bound by the same terms.
  • Return or destruction of data, defining what happens to the information when the relationship ends.

HHS is clear that its sample language is a starting point rather than a mandatory script, and the wording can be adjusted to fit the real arrangement. The point is that these protections are present and agreed in writing, not that you use any particular template. The broader rules sit on the HHS HIPAA site, and because contract specifics carry legal weight, it is worth having a compliance advisor review your agreements.

What Happens If You Do Not Have One?

Two separate problems appear. First, sharing PHI with a vendor that has not signed a BAA is itself a HIPAA violation, independent of whether any data is ever exposed. The missing agreement is the breach. Second, if that uncovered vendor then loses or mishandles the data, your practice can be held responsible, because you handed protected information to a party you had not properly bound.

Regulators have treated missing BAAs as a serious failing, and penalties in this area can be substantial. The uncomfortable part is how avoidable it is. A BAA is usually free to put in place with a willing vendor, which means going without one is rarely a cost decision and almost always an oversight.

How to Get a BAA From a Vendor

For most reputable vendors that serve healthcare, the process is straightforward. Many provide their own BAA that you sign during onboarding, sometimes on a specific healthcare or higher-tier plan. Others accept a BAA you supply. The steps are simple: confirm the vendor will sign, get the agreement executed before you send any PHI, and keep a copy on file.

That last step matters more than people expect. In an audit, you have to be able to produce the signed agreements, so storing them somewhere organized rather than scattered across inboxes is part of doing this properly. A short register of which vendors have signed, and when, saves a lot of scrambling later.

Common BAA Mistakes

Most BAA failures are not dramatic, they are quiet oversights that pile up as a practice adds tools. The frequent ones:

  • Assuming a popular tool is covered. A well-known brand does not mean it signed a BAA with you, or that your plan includes one.
  • Using a free tier that excludes a BAA. Many tools only offer a BAA on paid healthcare plans, so the free version quietly puts you out of compliance.
  • Forgetting subcontractors. Covering your direct vendor but ignoring the third parties they rely on leaves a gap in the chain.
  • Never storing the signed agreements. If you cannot produce them, you cannot prove them.
  • Treating the BAA as the finish line. A signed agreement does not configure the software safely, it only sets the legal terms.

The BAA Is the Foundation, Not the Whole Building

A signed BAA is necessary, but on its own it does not make a system compliant. It sets the legal relationship. The technical work still has to happen: encryption, restricted access, messaging that keeps clinical detail out, and audit logging. A vendor can have a perfectly valid BAA and still be set up in a way that leaks data, because the agreement governs responsibility, not configuration.

This is why BAAs are best handled as one layer of a properly built system rather than a box ticked in isolation. When your CRM, your forms, and your messaging all sit on covered, correctly configured tools, the BAAs and the safeguards reinforce each other. That is the whole idea behind a HIPAA-compliant CRM setup, and it is the same discipline that runs through compliant intake forms, patient email, and specialized builds like a med spa CRM.

Frequently Asked Questions

What is a business associate agreement in simple terms?

It is a written contract between a healthcare provider and any outside company that handles patient data on its behalf. The agreement makes that company legally responsible for protecting the data and using it only as allowed. Without one, letting the vendor touch patient information is not compliant.

Who needs to sign a BAA?

Any vendor that creates, receives, stores, or transmits protected health information for your practice. That commonly includes your CRM, email and SMS providers, cloud storage, and billing services. Vendors with no access to patient data, like a cleaning company, do not need one.

What happens if I do not have a BAA?

Sharing protected health information with a vendor that has not signed a BAA is itself a HIPAA violation, separate from any breach. If that vendor then mishandles the data, your practice can be held liable, and penalties for missing agreements can run into significant fines.

Does a BAA make my software HIPAA compliant?

It is necessary but not sufficient. A signed BAA is one required piece, but the tool still has to be configured with encryption, access controls, safe messaging, and audit logging. A BAA covers the legal relationship, not the way you actually use the software.

Can I use my own BAA template?

You can, and HHS publishes sample provisions you can build from. Many vendors also provide their own BAA that you sign during setup. Whichever you use, it should cover the required safeguards, permitted uses, breach reporting, and what happens to data when the relationship ends.

Not Sure Which of Your Vendors Are Covered?

Mapping every tool that touches patient data, confirming which ones have a BAA, and building the whole system on covered, correctly configured software is exactly the kind of groundwork specialist teams like GHLStarboys handle for medical and wellness practices. If you would rather not audit your own vendor stack line by line, it is worth booking a free growth call with them to see what a properly covered setup looks like for your practice.

Book a Free Growth Call with GHLStarboys

Arham Abid

Arham Abid

Helping agency owners for 8 years. 1200 agency owners scaled with a team of 350 employees.

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog