BAA
A BAA (business associate agreement) is the written contract HIPAA requires between a covered entity and any vendor that handles protected health information for it. It sets out what the vendor may do with the data and how it must protect and report on it.
Also called: business associate agreement, business associate contract
HIPAA’s Privacy Rule (45 C.F.R. §164.504(e)) says a covered entity may share PHI with a business associate only under a contract containing specific terms: the permitted and required uses of the information, a promise not to use or disclose it otherwise, appropriate safeguards, reporting of any breach or improper use, flow-down of the same terms to subcontractors, support for patients’ access and amendment rights, and return or destruction of the data when the contract ends.
A business associate that itself uses a subcontractor to handle PHI, a transcription provider, a cloud host, needs a BAA with that subcontractor in turn. The chain of agreements is how responsibility follows the data.
A signed BAA does not by itself make a service “HIPAA compliant”; it is the legal precondition for sharing PHI, alongside the safeguards the vendor actually operates. A vendor that will not sign one cannot lawfully be given PHI by a covered entity.
