Free Consultation
#hipaa

Business Associate Agreements: What a BAA Actually Covers and Where the Protection Ends

August 7, 2026

A Business Associate Agreement (BAA) sits at the center of nearly every major HIPAA enforcement case involving a vendor. Raleigh Orthopaedic Clinic paid $750,000 in 2016 after handing X-ray films containing protected health information (PHI) for roughly 17,300 patients to a vendor with no BAA in place. North Memorial Health Care paid $1,550,000 the same year, in part for giving a contractor access to a database of 289,904 patients without a signed agreement. These cases share a pattern: the agreement itself was treated as a checkbox rather than a working contract with defined obligations.

This article explains what a BAA covers under federal law, what it leaves out, and why enforcement so often traces back to this single document. A BAA establishes legal responsibilities between a covered entity and a vendor. It does not replace a risk analysis, a Notice of Privacy Practices, or a broader security program. Treating the BAA as the finish line rather than the starting point of vendor oversight is where most compliance gaps begin.

What Is a BAA and Who Needs One

A Business Associate Agreement is the written contract required whenever an outside person or company handles PHI on behalf of a covered entity. Under federal guidance, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of PHI on behalf of, or provides services to, a covered entity. Common examples include billing companies, cloud hosting providers, managed IT vendors, and software platforms that store or transmit PHI.

Not every vendor relationship triggers this requirement. In certain situations, a covered entity is not required to have a business associate contract or other written agreement in place before PHI may be disclosed to the person or entity. A hospital referring a patient to a specialist for treatment is one example, since the disclosure falls under treatment coordination rather than a service arrangement. Outside these narrow exceptions, a written BAA is mandatory before PHI changes hands.

What a Compliant BAA Must Include

Federal regulation spells out the minimum content of a BAA in specific terms. The HIPAA Privacy Rule requires the BAA between a covered entity and a business associate, or between a business associate and its subcontractor, to contain the elements specified at 45 CFR 164.504(e).

A compliant agreement generally addresses the following:

The BAA must describe the permitted and required uses and disclosures of PHI by the business associate. It must also state that the business associate will not use or further disclose PHI beyond what is permitted or required. Where the business associate carries out a covered entity's Privacy Rule obligations, the agreement must require compliance with those same obligations. A BAA missing any of these elements does not meet the regulatory standard, regardless of how thorough it looks on the surface.

What a BAA Does Not Cover

A BAA is a liability allocation document, not a security control. Signing one does not verify that a vendor actually encrypts data, trains staff, or monitors access logs. It creates a contractual promise. It does not test whether that promise holds up in practice.

A BAA also has no bearing on the Notice of Privacy Practices (NPP), a separate patient-facing document. A Notice of Privacy Practices is a written document that gives individuals a clear, user-friendly explanation of their rights regarding their PHI. Covered entities must provide patients with this notice no later than the date of first service delivery, including services delivered electronically. A well-drafted BAA with a vendor says nothing about whether the covered entity itself is meeting its own direct obligations to patients.

Finally, a BAA does not eliminate the need for oversight. A signed contract sitting in a file folder provides no protection if the covered entity never confirms the vendor is following it.

Subcontractor Chains: Why BAAs Must Flow Down

PHI often passes through more than one vendor before reaching its final destination, and the BAA requirement follows it at every step. Any subcontractor of a business associate that creates, maintains, or transmits PHI on behalf of that business associate is also a business associate. A cloud hosting provider used by a billing vendor needs its own BAA with that billing vendor, even though the covered entity never contracts with the hosting provider directly.

This flow-down obligation is a frequent point of failure. A business associate that uses subcontractors to provide services involving PHI must execute business associate agreements with those subcontractors as well. OCR's 2023 settlement with MedEvolve illustrates the consequence of skipping this step: the investigation found that MedEvolve failed to enter into a business associate agreement with a subcontractor, and its risk assessment of electronic PHI (ePHI) vulnerabilities was not sufficiently accurate or thorough. The company paid a $350,000 penalty and entered a Corrective Action Plan (CAP) as a result.

HIPAA Violation Examples Tied to Missing or Weak BAAs

Enforcement history shows a consistent pattern behind many HIPAA violation examples. North Memorial's case is instructive. The organization did not have a documented BAA with its billing company from March through October of 2011. That lapse resulted in the unlawful disclosure of PHI for at least 289,904 patients during that period. The absence of the agreement, not just the underlying breach, became a separate finding.

Civil penalties for these gaps scale with culpability and how quickly an organization corrects course. Under the penalty structure OCR currently applies:

These figures apply per violation, and a single missing BAA covering thousands of patient records can generate a large number of counted violations quickly.

How Poor Drafting Creates Risk Even With a Signed BAA

A signed agreement with vague language carries nearly the same risk as no agreement at all. Breach-reporting clauses that lack a specific timeframe give a vendor room to delay notification. Safeguard language that describes obligations in general terms, without naming specific controls, makes it difficult to hold a vendor accountable after an incident.

Reviewing existing BAAs against the checklist above is a reasonable starting point for organizations unsure of their current exposure. Comparing each agreement to the required elements at 45 CFR 164.504(e) identifies gaps before an investigator does.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in HIPAA readiness for SMBs in healthcare and health technology. Our vCISOs and compliance managers help organizations choose the right approach, configure governance, risk, and compliance (GRC) tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is a BAA in HIPAA compliance?
A BAA, or Business Associate Agreement, is the written contract required between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on the entity's behalf. It sets out permitted uses of the data, safeguard obligations, breach reporting duties, and terms for returning or destroying the information when the relationship ends.
Does a BAA replace the Notice of Privacy Practices?
No. A BAA governs the relationship between a covered entity and a vendor, while a Notice of Privacy Practices informs patients directly about how their information may be used and what rights they hold. The two documents serve different audiences, and neither substitutes for the other.
What happens if a vendor never signs a BAA?
Operating without a signed BAA where one is legally required is itself a HIPAA violation, separate from any data breach that might follow. Enforcement history shows this gap frequently surfaces during breach investigations and has led to settlements well into six figures for organizations of varying sizes.
Do subcontractors of a business associate need their own BAA?
Yes. Any subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate is itself considered a business associate and needs a written agreement covering the same required elements. This flow-down requirement applies regardless of how many layers separate the subcontractor from the original covered entity.
How often should a BAA be reviewed or updated?
There is no fixed federal renewal schedule, but reviewing a BAA whenever the vendor relationship changes, a service scope expands, or a breach occurs is a sound practice. Periodic review also catches outdated language that no longer matches current subcontractor arrangements or breach notification timelines.

Related blog posts