A business associate agreement (BAA) is a written contract, required by the HIPAA Privacy Rule, in which a vendor that handles protected health information (PHI) for a covered entity promises to safeguard that information, use it only as permitted, and report breaches. The requirement lives at 45 CFR 164.502(e), and it is the single most consequential sentence in healthcare vendor management: if a vendor will touch PHI and will not sign a BAA, the covered entity cannot lawfully use that vendor for that work. Every "is this tool HIPAA compliant" question ultimately resolves to this contract first. This article is general information, not legal advice.
Key takeaways:
- A BAA is required whenever a business associate creates, receives, maintains, or transmits PHI on behalf of a covered entity.
- The definitions come from 45 CFR 160.103; the contract requirement from 45 CFR 164.502(e); the required contents from 45 CFR 164.504(e).
- Since the 2013 HITECH Omnibus Rule, business associates are directly liable under HIPAA, and their subcontractors need BAAs too.
- A BAA makes vendor use permissible; it does not make a product "HIPAA compliant" or transfer the covered entity's own obligations.
- Operating without a required BAA is itself a violation, and enforcement actions by the HHS Office for Civil Rights have targeted exactly that failure.
The definitions that make the rule work
HIPAA, the Health Insurance Portability and Accountability Act of 1996, is administered by the Department of Health and Human Services (HHS) and enforced by its Office for Civil Rights (OCR). Three definitions from 45 CFR 160.103 do the heavy lifting:
- Covered entity: a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically for standard transactions. Clinics, hospitals, insurers, and most practices qualify.
- Protected health information: individually identifiable health information held or transmitted by a covered entity or business associate, in any form. Names attached to appointments, diagnoses, images, and billing details all count.
- Business associate: a person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity, or provides services involving PHI, such as billing, IT, cloud storage, messaging, analytics, transcription, or legal and accounting work that touches patient data.
A crisp working definition for the whole concept: a BAA is the contract that extends HIPAA's obligations from the healthcare organization to the vendors it trusts with patient information.
Notably, HHS cloud guidance confirms that a cloud provider storing encrypted PHI is a business associate even if it never views the data and lacks the decryption key. "We cannot see it" does not exempt a vendor.
What a BAA must actually contain
The required elements are listed at 45 CFR 164.504(e). In plain language, a compliant BAA must:
- Define permitted uses and disclosures. The vendor may use PHI only to perform the contracted services, plus narrow additional purposes the rule allows.
- Prohibit everything else. Uses outside the contract, including most marketing and any sale of PHI, are off the table.
- Require safeguards. The vendor must implement appropriate administrative, physical, and technical safeguards and comply with the Security Rule for electronic PHI.
- Require breach and incident reporting. The vendor must report security incidents and breaches of unsecured PHI to the covered entity, feeding the covered entity's duties under the Breach Notification Rule at 45 CFR 164.400 through 164.414.
- Flow down to subcontractors. Any subcontractor that handles the PHI must sign its own BAA with equivalent restrictions, a chain requirement added by the 2013 Omnibus Rule.
- Support individual rights. The vendor must make PHI available for patient access, amendment, and accounting of disclosures as applicable.
- Permit HHS oversight. The vendor must make its practices and records available to HHS for compliance determination.
- Handle termination. At contract end, the vendor must return or destroy PHI where feasible, or extend protections if not.
A vendor's willingness to sign is only the first checkpoint. The scope matters: which services are covered, which plan tiers qualify, and what configuration duties the customer retains. Large vendors differ widely here, which is why answers vary so much across tools like Slack, Zoom, and consumer apps that offer no BAA at all.
What a BAA does not do
Misunderstanding the limits of a BAA causes as many failures as missing one:
- It does not make a product compliant. Compliance describes an organization's practices, not a product. A covered entity can violate HIPAA badly while using a fully covered tool, for example by over-sharing access or ignoring audit logs.
- It does not transfer your obligations. The covered entity still owes its own risk analysis under 45 CFR 164.308(a)(1), workforce training, access management, and minimum necessary discipline under 45 CFR 164.502(b).
- It does not cover services outside its scope. If the BAA lists included services, PHI in an excluded service is unprotected by the agreement.
- It does not excuse bad configuration. A covered messaging platform used without consent records, or covered storage shared by public link, fails on the customer's side of the line.
Who needs a BAA, and who does not
Needs a BAA: cloud storage and email providers, messaging and telehealth platforms, EHR vendors, billing and coding services, IT support with system access, transcription services, shredding companies handling records, analytics vendors, answering services, and any subcontractor of the above that touches PHI.
Does not need a BAA: members of the covered entity's own workforce (they are governed by policy and training instead), conduits that merely transport data without storing it (the classic examples are the postal service and pure internet carriage), other providers receiving PHI for treatment purposes, and vendors that genuinely never touch PHI, such as a landscaping company or a software vendor whose product runs entirely on-premises without vendor access.
The conduit exception is narrow, and OCR has said so explicitly. A texting platform that stores messages, even briefly and even encrypted, is a business associate, not a conduit. This is why choosing a messaging vendor that signs a BAA is foundational for healthcare texting, as our guide to how HIPAA-compliant SMS works explains step by step.
Enforcement: operating without a BAA is itself a violation
OCR has repeatedly settled cases where the core failure was a missing BAA: patient data given to a billing vendor, a records-storage company, or an IT contractor with no agreement in place. Civil monetary penalties under 45 CFR Part 160 are tiered by culpability, from unknowing violations to willful neglect, with annual caps per violation category adjusted over time, and willful neglect drawing mandatory penalties. Since the HITECH Act, business associates themselves are directly liable for their own violations, which means vendors can no longer treat HIPAA as their customers' problem.
For a covered entity, the practical exposure stacks: the missing contract, the impermissible disclosures that flowed through it, potential breach notification duties, and the corrective action plan that typically follows a settlement.
A working checklist for vendor diligence
- Inventory every vendor relationship and mark which ones touch PHI in any form.
- Obtain a signed BAA before PHI flows, not after the pilot succeeds.
- Read the scope: covered services, eligible plan tiers, customer configuration duties.
- Confirm subcontractor flow-down language.
- Calendar renewals and re-review when the vendor changes plans or products.
- Verify the operational safeguards the BAA presumes: encryption in transit and at rest, access controls, audit logging.
- Keep BAAs with your risk analysis documentation, where an auditor will ask for them.
Our HIPAA SMS compliance checklist applies this diligence to the messaging channel specifically. FRANSiS operates as a business associate for its healthcare customers, with a signed BAA included, encryption in transit (TLS 1.3) and at rest (256-bit AES), and audit logging built in. The broader channel guidance lives in the HIPAA-compliant text messaging pillar guide.
Frequently asked questions
What is a business associate agreement in simple terms?
It is the contract HIPAA requires between a healthcare organization and any vendor that handles patient information for it. The vendor promises in writing to safeguard the data, use it only for the contracted work, report breaches, and bind its own subcontractors to the same rules.
Where does the BAA requirement come from in the law?
The Privacy Rule at 45 CFR 164.502(e) requires satisfactory written assurances before a business associate handles PHI, and 45 CFR 164.504(e) lists the provisions the contract must contain. The definitions of covered entity, business associate, and PHI are at 45 CFR 160.103.
Does a signed BAA make a vendor HIPAA compliant?
No. The BAA makes the relationship permissible and binds the vendor to safeguards, but compliance depends on both parties' actual practices. The covered entity keeps its own duties, including risk analysis, training, access management, and correct configuration of the vendor's product.
Do subcontractors of my vendors need BAAs too?
Yes. Since the 2013 Omnibus Rule, a business associate must obtain a BAA from any subcontractor that creates, receives, maintains, or transmits PHI on its behalf, with restrictions at least as strict. The chain continues down through every layer that touches the data.
Is a texting or email provider a conduit that avoids the BAA requirement?
Almost never. The conduit exception covers entities that merely transport data with only transient access, like the postal service. Platforms that store messages, even temporarily and encrypted, are business associates. A healthcare texting program should run only on a platform that signs a BAA.
Conclusion
The BAA is HIPAA's mechanism for making trust contractual: it takes the promises a healthcare organization owes its patients and extends them, in enforceable writing, to every vendor in the data path. Learn to ask the BAA question first, read the scope second, and configure third, and most vendor-compliance puzzles resolve themselves in the right order.
Choosing a messaging vendor for patient communication? Contact the FRANSiS team to see HIPAA-supported texting with a signed BAA included, plus an AI Powered Helper that handles routine patient questions inside a fully governed channel.


