The Business Associate Agreement, explained
An educational explainer of what a HIPAA Business Associate Agreement (BAA) is and why a practice needs one with its vendors. Not a template to sign; have BAAs drafted or reviewed by counsel.
Current as of July 7, 2026. Laws, payer rules, and billing codes change, so confirm the current requirements for your jurisdiction and setting before you rely on it.
What's inside
What it is
A Business Associate Agreement is a contract between a covered entity, such as your practice, and a business associate, such as a vendor that creates, receives, maintains, or transmits protected health information on your behalf. HIPAA requires it.
Who is a business associate
- Your electronic health record and telehealth platform
- Billing, transcription, and some IT or cloud vendors
- Any vendor that handles protected health information for you, not a patient or another treating provider
What a BAA commonly addresses
- The permitted uses and disclosures of protected health information
- Required safeguards and compliance with the Security Rule
- Reporting of breaches and security incidents to you
- Return or destruction of protected health information when the relationship ends
- Flow-down to subcontractors
Note
Sign a BAA before a vendor touches protected health information. Do not rely on a generic form without review; confirm current HHS requirements and have counsel adapt it.
About this resource
This reference is part of the shrinkiatry resource library, a set of free, clinician-facing references and examples. It's reviewed by Shariq Refai, MD, MBA, FAPA, a board-certified psychiatrist, on a quarterly schedule. Next scheduled review: October 1, 2026. First published July 7, 2026, last reviewed July 7, 2026.
Browse the rest of the resource library, or verify who reviews this site. Spotted something out of date? Email corrections@shrinkiatry.com.