<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is a business associate agreement?"
title: "What Is a Business Associate Agreement"
seoTitle: "What Is a Business Associate Agreement (BAA)?"
summary: "A business associate agreement is a contract required by HIPAA between a covered entity and any vendor that handles protected health information on its behalf. It obliges the vendor to safeguard PHI, report breaches, bind its own subcontractors, and return or destroy PHI at termination. Without a signed BAA in place, disclosing PHI to that vendor is itself a HIPAA violation."
publishedAt: "2026-08-18"
keywords:
  - "what is business associate agreement"
  - "BAA HIPAA"
  - "HIPAA compliant business associate agreement"
  - "business associate"
pillar: "Beyond SOC 2"
faqs:
  - question: "Who needs to sign a business associate agreement?"
    answer: "A covered entity and any business associate that creates, receives, maintains, or transmits PHI on its behalf. Since the Omnibus Rule of 2013, business associates must also have BAAs with their own subcontractors who touch PHI, so the obligation flows down the chain."
  - question: "What happens if there is no BAA?"
    answer: "Disclosing PHI to a vendor without a signed BAA is itself a HIPAA violation by the covered entity, independent of whether anything goes wrong. Enforcement actions regularly cite missing BAAs on their own, and the business associate carries direct liability as well."
  - question: "Do cloud providers sign BAAs?"
    answer: "The major ones do, including AWS, Google Cloud, Microsoft Azure, and many SaaS vendors, though some restrict it to specific plan tiers and only cover named services. Check both that the vendor will sign and that the specific service you use is in scope, because BAA coverage is usually per-service rather than account-wide."
---

## What is a business associate agreement?

A business associate agreement, or BAA, is a **contract HIPAA requires** between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It obliges the vendor to safeguard PHI, report breaches, bind its own subcontractors to the same terms, and return or destroy PHI when the relationship ends. **Without a signed BAA, disclosing PHI to that vendor is itself a violation**, regardless of whether anything goes wrong.

### What a BAA has to contain

| Required term | What it means |
|---|---|
| Permitted uses and disclosures | What the business associate may do with the PHI, and nothing beyond it |
| Safeguards | Implement the Security Rule's administrative, physical, and technical protections |
| Breach reporting | Report unauthorised uses and disclosures, within agreed timelines |
| Subcontractor flow-down | Any subcontractor touching PHI signs an equivalent agreement |
| Access rights | Support the covered entity's obligations for individual access and amendment |
| Return or destruction | At termination, return or destroy PHI where feasible |
| Termination for breach | The covered entity can terminate for material violation |

## Who is a business associate

Anyone handling PHI on behalf of a covered entity: cloud hosting, EHR vendors, billing companies, analytics providers, transcription services, backup providers, and most B2B SaaS serving healthcare. Company size is irrelevant. Intent is irrelevant. If PHI passes through your systems for a covered entity, you are one.

Since the **Omnibus Rule (2013)**, business associates carry **direct liability** to HHS rather than only contractual liability to their customer, and must hold BAAs with their own subcontractors. The obligation flows all the way down the chain.

## The practical trap: per-service coverage

Most major cloud and SaaS vendors will sign a BAA. What catches teams out is that coverage is usually **per-service, not per-account**. A provider may sign a BAA that covers its core compute and storage while excluding a newer service you happen to be using, and that exclusion is your problem, not theirs.

Check two things every time:

1. Will they sign, and on your current plan tier rather than only on enterprise?
2. Is the **specific service** you are using inside the BAA's scope?

## Keeping track of them

A BAA register is something an auditor will ask for, and it is the artifact most likely to be out of date. Every vendor touching PHI, the BAA status, the date signed, and the services covered. This is the same problem as vendor management generally, which is why the two usually live together. See [what are the 5 stages of third party management](/resources/answers/what-are-the-5-stages-of-third-party-management) and [BAA status by tool](/hipaa).
