A Business Associate Agreement (BAA) sits at the center of nearly every major HIPAA enforcement case involving a vendor. Raleigh Orthopaedic Clinic paid $750,000 in 2016 after handing X-ray films containing protected health information (PHI) for roughly 17,300 patients to a vendor with no BAA in place. North Memorial Health Care paid $1,550,000 the same year, in part for giving a contractor access to a database of 289,904 patients without a signed agreement. These cases share a pattern: the agreement itself was treated as a checkbox rather than a working contract with defined obligations.
This article explains what a BAA covers under federal law, what it leaves out, and why enforcement so often traces back to this single document. A BAA establishes legal responsibilities between a covered entity and a vendor. It does not replace a risk analysis, a Notice of Privacy Practices, or a broader security program. Treating the BAA as the finish line rather than the starting point of vendor oversight is where most compliance gaps begin.
What Is a BAA and Who Needs One
A Business Associate Agreement is the written contract required whenever an outside person or company handles PHI on behalf of a covered entity. Under federal guidance, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of PHI on behalf of, or provides services to, a covered entity. Common examples include billing companies, cloud hosting providers, managed IT vendors, and software platforms that store or transmit PHI.
Not every vendor relationship triggers this requirement. In certain situations, a covered entity is not required to have a business associate contract or other written agreement in place before PHI may be disclosed to the person or entity. A hospital referring a patient to a specialist for treatment is one example, since the disclosure falls under treatment coordination rather than a service arrangement. Outside these narrow exceptions, a written BAA is mandatory before PHI changes hands.
What a Compliant BAA Must Include
Federal regulation spells out the minimum content of a BAA in specific terms. The HIPAA Privacy Rule requires the BAA between a covered entity and a business associate, or between a business associate and its subcontractor, to contain the elements specified at 45 CFR 164.504(e).
A compliant agreement generally addresses the following:
- Permitted and required uses and disclosures of PHI
- Prohibition on further disclosure beyond what the agreement or the law allows
- Required safeguards to protect the confidentiality and integrity of PHI
- Breach and security incident reporting obligations
- Subcontractor flow-down requirements
- Support for individual rights, including access and amendment requests
- Return or destruction of PHI at the end of the relationship
- A termination clause for material breach
The BAA must describe the permitted and required uses and disclosures of PHI by the business associate. It must also state that the business associate will not use or further disclose PHI beyond what is permitted or required. Where the business associate carries out a covered entity's Privacy Rule obligations, the agreement must require compliance with those same obligations. A BAA missing any of these elements does not meet the regulatory standard, regardless of how thorough it looks on the surface.
What a BAA Does Not Cover
A BAA is a liability allocation document, not a security control. Signing one does not verify that a vendor actually encrypts data, trains staff, or monitors access logs. It creates a contractual promise. It does not test whether that promise holds up in practice.
A BAA also has no bearing on the Notice of Privacy Practices (NPP), a separate patient-facing document. A Notice of Privacy Practices is a written document that gives individuals a clear, user-friendly explanation of their rights regarding their PHI. Covered entities must provide patients with this notice no later than the date of first service delivery, including services delivered electronically. A well-drafted BAA with a vendor says nothing about whether the covered entity itself is meeting its own direct obligations to patients.
Finally, a BAA does not eliminate the need for oversight. A signed contract sitting in a file folder provides no protection if the covered entity never confirms the vendor is following it.
Subcontractor Chains: Why BAAs Must Flow Down
PHI often passes through more than one vendor before reaching its final destination, and the BAA requirement follows it at every step. Any subcontractor of a business associate that creates, maintains, or transmits PHI on behalf of that business associate is also a business associate. A cloud hosting provider used by a billing vendor needs its own BAA with that billing vendor, even though the covered entity never contracts with the hosting provider directly.
This flow-down obligation is a frequent point of failure. A business associate that uses subcontractors to provide services involving PHI must execute business associate agreements with those subcontractors as well. OCR's 2023 settlement with MedEvolve illustrates the consequence of skipping this step: the investigation found that MedEvolve failed to enter into a business associate agreement with a subcontractor, and its risk assessment of electronic PHI (ePHI) vulnerabilities was not sufficiently accurate or thorough. The company paid a $350,000 penalty and entered a Corrective Action Plan (CAP) as a result.
HIPAA Violation Examples Tied to Missing or Weak BAAs
Enforcement history shows a consistent pattern behind many HIPAA violation examples. North Memorial's case is instructive. The organization did not have a documented BAA with its billing company from March through October of 2011. That lapse resulted in the unlawful disclosure of PHI for at least 289,904 patients during that period. The absence of the agreement, not just the underlying breach, became a separate finding.
Civil penalties for these gaps scale with culpability and how quickly an organization corrects course. Under the penalty structure OCR currently applies:
- Tier 1 (no knowledge): $145 to $73,011 per violation, with a calendar-year cap of $2,190,294
- Tier 2 (reasonable cause): $1,461 to $73,011 per violation, with the same annual cap
- Tier 3 (willful neglect, corrected within 30 days): $14,602 to $73,011 per violation, with the same annual cap
- Tier 4 (willful neglect, not corrected): at least $73,011 per violation, with the maximum penalty and calendar-year cap both set at $2,190,294
These figures apply per violation, and a single missing BAA covering thousands of patient records can generate a large number of counted violations quickly.
How Poor Drafting Creates Risk Even With a Signed BAA
A signed agreement with vague language carries nearly the same risk as no agreement at all. Breach-reporting clauses that lack a specific timeframe give a vendor room to delay notification. Safeguard language that describes obligations in general terms, without naming specific controls, makes it difficult to hold a vendor accountable after an incident.
Reviewing existing BAAs against the checklist above is a reasonable starting point for organizations unsure of their current exposure. Comparing each agreement to the required elements at 45 CFR 164.504(e) identifies gaps before an investigator does.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in HIPAA readiness for SMBs in healthcare and health technology. Our vCISOs and compliance managers help organizations choose the right approach, configure governance, risk, and compliance (GRC) tools if needed, and get audit-ready without wasted time.





