EnglishEspañol

What Is a Business Associate Agreement (BAA)? HIPAA Guide (2026)

By Recording Law Editorial TeamReviewed August 8, 202612 min read
What Is a Business Associate Agreement (BAA)? HIPAA Guide (2026)

Frequently Asked Questions

What is the difference between a covered entity and a business associate under HIPAA?

A covered entity is a health plan, healthcare clearinghouse, or healthcare provider that conducts certain electronic transactions. A business associate is any outside person or organization that performs functions or activities on behalf of a covered entity involving PHI. The distinction matters because both have separate but overlapping obligations under HIPAA, and a BAA is required whenever a covered entity shares PHI with a business associate.

Does a BAA need to be a standalone contract?

No. HHS allows the required BAA provisions to be incorporated into a broader services agreement between the covered entity and the business associate. The provisions can be part of a master services agreement, a vendor contract, or a standalone document. What matters is that all provisions required by 45 CFR 164.504(e)(2) are present in writing, regardless of the document format.

Can a covered entity be held liable for a business associate's HIPAA violation?

A covered entity can be held liable if it knew of a pattern of activity or practice by the business associate that constituted a material breach of the BAA and failed to take reasonable steps to cure the breach or end the violation. Under 45 CFR 164.504(e)(1), if corrective steps are unsuccessful, the covered entity must terminate the contract or arrangement, if feasible.

Do business associates need BAAs with their own subcontractors?

Yes. The 2013 Omnibus Rule expanded the definition of business associate to include subcontractors that create, receive, maintain, or transmit PHI. Under 45 CFR 164.504(e)(5), the same contract requirements that apply between a covered entity and a business associate also apply between a business associate and its subcontractors. This creates a chain of written agreements extending to every entity handling PHI.

How long does a business associate have to report a breach to the covered entity?

Under the HIPAA Breach Notification Rule at 45 CFR 164.410, a business associate must notify the covered entity of a discovered breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. Many covered entities negotiate shorter reporting deadlines in their BAAs, sometimes requiring notification within 24 to 72 hours.

Updates

Governing law re-checked for recent changes

Removed a fabricated 'report the problem to HHS' compliance alternative from an FAQ answer about business associate violations; the current 45 CFR 164.504(e)(1) only conditions compliance on curing the breach and terminating the contract if feasible.

Governing law re-checked for recent changes

Sources and References

  1. HHS Business Associates Guidance(hhs.gov).gov
  2. HHS Sample Business Associate Agreement Provisions(hhs.gov).gov
  3. HHS Direct Liability of Business Associates Fact Sheet(hhs.gov).gov
  4. 45 CFR 164.504 - Uses and Disclosures: Organizational Requirements(law.cornell.edu)
  5. HHS HIPAA Enforcement: North Memorial Health Care Settlement(hhs.gov).gov
  6. HHS HIPAA Enforcement: Raleigh Orthopaedic Clinic Settlement(hhs.gov).gov
  7. HHS HIPAA Enforcement: CHSPSC LLC Settlement(hhs.gov).gov
  8. HIPAA Omnibus Rule Final Rule (Federal Register)(govinfo.gov).gov
  9. HHS Guidance on HIPAA and Cloud Computing(hhs.gov).gov
  10. HHS HIPAA Enforcement: BST & Co. CPAs Settlement(hhs.gov).gov
  11. 42 U.S.C. 1320d-6 - Wrongful Disclosure of Health Information(law.cornell.edu)
  12. HHS Resolution Agreements and Civil Money Penalties(hhs.gov).gov
Share: