Beyond SOC 2
What is a business associate agreement?
What is a business associate agreement?
A business associate agreement, or BAA, is a contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It obliges the vendor to safeguard PHI, report breaches, bind its own subcontractors to the same terms, and return or destroy PHI when the relationship ends. Without a signed BAA, disclosing PHI to that vendor is itself a violation, regardless of whether anything goes wrong.
What a BAA has to contain
| Required term | What it means |
|---|---|
| Permitted uses and disclosures | What the business associate may do with the PHI, and nothing beyond it |
| Safeguards | Implement the Security Rule's administrative, physical, and technical protections |
| Breach reporting | Report unauthorised uses and disclosures, within agreed timelines |
| Subcontractor flow-down | Any subcontractor touching PHI signs an equivalent agreement |
| Access rights | Support the covered entity's obligations for individual access and amendment |
| Return or destruction | At termination, return or destroy PHI where feasible |
| Termination for breach | The covered entity can terminate for material violation |
Who is a business associate
Anyone handling PHI on behalf of a covered entity: cloud hosting, EHR vendors, billing companies, analytics providers, transcription services, backup providers, and most B2B SaaS serving healthcare. Company size is irrelevant. Intent is irrelevant. If PHI passes through your systems for a covered entity, you are one.
Since the Omnibus Rule (2013), business associates carry direct liability to HHS rather than only contractual liability to their customer, and must hold BAAs with their own subcontractors. The obligation flows all the way down the chain.
The practical trap: per-service coverage
Most major cloud and SaaS vendors will sign a BAA. What catches teams out is that coverage is usually per-service, not per-account. A provider may sign a BAA that covers its core compute and storage while excluding a newer service you happen to be using, and that exclusion is your problem, not theirs.
Check two things every time:
- Will they sign, and on your current plan tier rather than only on enterprise?
- Is the specific service you are using inside the BAA's scope?
Keeping track of them
A BAA register is something an auditor will ask for, and it is the artifact most likely to be out of date. Every vendor touching PHI, the BAA status, the date signed, and the services covered. This is the same problem as vendor management generally, which is why the two usually live together. See what are the 5 stages of third party management and BAA status by tool.