[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-business-associate-agreement::en":3,"gloss-cluster-business-associate-agreement::en":20,"gloss-next-business-associate-agreement::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"business-associate-agreement","security","Business Associate Agreement (BAA)","A business associate agreement is the contract HIPAA requires between a covered entity — a healthcare provider, health plan or clearinghouse — and any vendor that creates, receives, maintains or transmits protected health information on its behalf. It obliges the vendor to safeguard that data, restricts how it may be used and disclosed, requires breach notification within defined timeframes, extends the same obligations down to the vendor's own subcontractors, and addresses the return or destruction of the data when the relationship ends. For a buyer in US healthcare, the BAA is not paperwork that follows the purchase; it is the condition of the purchase. Without an executed BAA, putting protected health information into a tool is a compliance violation regardless of how secure the tool actually is, and the exposure sits with the covered entity as much as with the vendor. Three practical points. Many SaaS vendors will sign a BAA only on specific plan tiers, so the same product can be usable or unusable depending on what you bought — check before you assume. Signing a BAA does not make a vendor \"HIPAA certified\"; no such certification exists, and a vendor advertising it is describing its own controls rather than an external attestation. And the BAA must reach every layer: if the vendor uses AI model providers, cloud hosting or transcription services in the path of the data, those subcontractors need equivalent agreements in place, which is worth confirming explicitly rather than assuming. Ask which product areas are in scope, whether audit logging and access controls meet the technical safeguards you rely on, and how data is handled in support workflows — support access to a record is one of the most common quiet gaps.","A BAA is the contract a US healthcare buyer must sign with any vendor that touches protected health information — no BAA, no lawful use.",null,[11,14,17],{"slug":12,"name":13},"data-processing-agreement","Data Processing Agreement (DPA)",{"slug":15,"name":16},"hipaa","HIPAA",{"slug":18,"name":19},"pii","Personally Identifiable Information (PII)",[21,25,29,33,36,39,42,45,48,51,54,55],{"slug":22,"category":5,"name":23,"updated_at":24},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":30,"category":5,"name":31,"updated_at":32},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":34,"category":5,"name":35,"updated_at":32},"bridge-letter","Bridge Letter",{"slug":37,"category":5,"name":38,"updated_at":24},"byok","Bring Your Own Key (BYOK)",{"slug":40,"category":5,"name":41,"updated_at":32},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":43,"category":5,"name":44,"updated_at":28},"data-classification","Data Classification",{"slug":46,"category":5,"name":47,"updated_at":32},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":49,"category":5,"name":50,"updated_at":32},"data-minimization","Data Minimization",{"slug":52,"category":5,"name":53,"updated_at":32},"data-poisoning","Data Poisoning",{"slug":12,"category":5,"name":13,"updated_at":32},{"slug":56,"category":5,"name":57,"updated_at":24},"data-retention","Data Retention Policy"]