security
Glossary ↗Business Associate Agreement (BAA)
A business associate agreement is the contract HIPAA requires between a covered entity — a healthcare provider, health plan or clearinghouse — and any vendor that creates, receives, maintains or transmits protected health information on its behalf. It obliges the vendor to safeguard that data, restricts how it may be used and disclosed, requires breach notification within defined timeframes, extends the same obligations down to the vendor's own subcontractors, and addresses the return or destruction of the data when the relationship ends. For a buyer in US healthcare, the BAA is not paperwork that follows the purchase; it is the condition of the purchase. Without an executed BAA, putting protected health information into a tool is a compliance violation regardless of how secure the tool actually is, and the exposure sits with the covered entity as much as with the vendor. Three practical points. Many SaaS vendors will sign a BAA only on specific plan tiers, so the same product can be usable or unusable depending on what you bought — check before you assume. Signing a BAA does not make a vendor "HIPAA certified"; no such certification exists, and a vendor advertising it is describing its own controls rather than an external attestation. And the BAA must reach every layer: if the vendor uses AI model providers, cloud hosting or transcription services in the path of the data, those subcontractors need equivalent agreements in place, which is worth confirming explicitly rather than assuming. Ask which product areas are in scope, whether audit logging and access controls meet the technical safeguards you rely on, and how data is handled in support workflows — support access to a record is one of the most common quiet gaps.
Related terms