HIPAA Business Associate Agreements: when you need one and what it must contain
By Sam Rivera, Founder, SentinelPanda · May 15, 2026 · 4 min read · HIPAA
If your software touches PHI on behalf of a covered entity, you are a business associate. A signed BAA is the price of doing the work — and the obligations that come with it are not just contractual.
Who counts as a business associate
A business associate is anyone who performs functions on behalf of a covered entity that involve the use or disclosure of PHI, beyond merely transmitting it through. That includes SaaS hosting clinical or claims data, third-party analytics platforms operating on PHI, transcription services, document storage providers, payment processors handling claims data, and most cloud infrastructure providers whose customers store PHI on them.
A conduit — pure transmission with no persistent access — is not a business associate. The classic examples are the postal service and ISPs. The conduit exception is narrow; "we just route the traffic" rarely qualifies a SaaS company. If your system reads, stores, or processes PHI on behalf of a covered entity, you are a business associate.
Why the BAA exists
The Privacy Rule prohibits a covered entity from disclosing PHI to a third party without patient authorisation, except for permitted purposes — and only when the third party will protect the PHI to the standard the covered entity itself owes. The BAA is the written instrument that extends those obligations contractually. Without a signed BAA, the disclosure itself is a Privacy Rule violation, regardless of how well you secure the data afterwards.
What the BAA must contain
- A description of the permitted and required uses and disclosures of PHI by the business associate — what the business associate may do with the data.
- A prohibition on uses and disclosures outside those permitted by the agreement or required by law.
- A requirement that the business associate implement appropriate safeguards (the Security Rule baseline at minimum) to protect PHI.
- A reporting obligation: the business associate must report to the covered entity any use or disclosure not permitted by the agreement, any security incident, and any breach of unsecured PHI within defined timelines.
- A flow-down obligation: any subcontractor of the business associate that touches PHI must agree, in writing, to the same restrictions and conditions (a downstream BAA).
- A requirement to make PHI available to support the covered entity's obligations to provide individual access, amendment, and accounting of disclosures.
- A termination clause, including the return or destruction of PHI at the end of the relationship.
- Authorisation for the covered entity to terminate the agreement if the business associate has materially breached it.
Downstream BAAs (subcontractors)
A business associate that uses subcontractors must execute its own BAAs with those subcontractors. The cloud provider hosting your database, the email service relaying patient notifications, the error monitoring tool that captures stack traces from your application — each of them needs a downstream BAA if they have access to PHI.
Most major cloud providers and SaaS infrastructure tools publish standard BAAs that customers can opt into for an upgraded plan. A common mistake is signing a top-level BAA with a customer without confirming each downstream tool that processes PHI also has one in place.
Direct liability under HITECH and the Omnibus Rule
Before 2009, business associates owed their obligations primarily through the BAA. HITECH made them directly liable for Security Rule violations; the 2013 Omnibus Rule extended direct liability to many Privacy Rule violations. The practical implication: HHS Office for Civil Rights can pursue and fine a business associate directly, in addition to any contractual remedy the covered entity may seek.
OCR enforcement against business associates has included multi-million-dollar settlements for failure to perform a risk analysis, failure to encrypt portable devices, and failure to implement basic access controls. A signed BAA shifts no responsibility — it sets up additional liability rather than reducing existing liability.
A practical BAA checklist before signing
- Are you actually a business associate, or are you a conduit? Get this right before the conversation about which template to use.
- Does the BAA use the customer's template or yours? Either is fine; your template is faster if it is well-written.
- Does the BAA include indemnification, liability caps, or insurance requirements above HIPAA's baseline? These are negotiated, not statutory.
- Do you have downstream BAAs for every subcontractor that touches PHI?
- Have you mapped the BAA's reporting obligations into your incident response runbook? The deadlines are short.