Business Associate Agreements What to Include and Common Mistakes to Avoid
- MLJ CONSULTANCY LLC

- 14 hours ago
- 16 min read
A weak business associate agreement can turn a routine vendor relationship into a compliance problem. In health care, the agreement is not just paperwork. It is one of the main ways a covered organization sets clear rules for how another party may use, protect, share, and return health information.
Under the Health Insurance Portability and Accountability Act, a covered organization generally must have a written agreement with a vendor or contractor that creates, receives, maintains, or transmits protected health information on its behalf. The U.S. Department of Health and Human Services explains this requirement through the Privacy Rule, especially 45 CFR 164.502(e) and 164.504(e). These rules describe what must be in a business associate contract and how the business associate must handle protected health information.
This article is informational only and is not legal advice. A qualified attorney or compliance professional should review agreements before they are signed.

What a business associate agreement does
A business associate agreement is a written contract between a covered organization and a person or company that performs certain services involving protected health information.
A covered organization may include:
A health care provider that transmits health information in standard electronic transactions
A health plan
A health care clearinghouse
A business associate may include a billing service, legal service, claims processor, consultant, data storage provider, document disposal vendor, answering service, or technology provider if that party handles protected health information for the covered organization.
The agreement sets the rules for that relationship. It tells the business associate what it may do with the information, what it may not do, how it must protect the information, what happens if there is a breach, and what must happen when the relationship ends.
Business Associate Agreements (BAAs) matter because the covered organization remains responsible for choosing vendors carefully and documenting required protections. A handshake or a broad service contract is not enough when a vendor handles protected health information.
The essential elements every agreement should include
A strong agreement should be specific. It should match the actual services being provided, the type of information involved, and the real risks of the relationship.
The federal rules do not require every agreement to use the same exact wording. Still, the Privacy Rule lists several required contract terms. The sections below cover the core elements that should appear in a well-drafted agreement.
Define the parties and the relationship clearly
The agreement should identify each party by legal name and role.
This sounds simple, but mistakes happen. A health care practice may sign with a parent company while the work is performed by a subsidiary. A consultant may operate through a limited liability company. A software provider may use a separate entity for hosting or support.
The agreement should make clear:
Who the covered organization is
Who the business associate is
Whether the agreement also applies to related entities
What services the business associate will provide
What protected health information the business associate will access, create, receive, maintain, or transmit
A clear description helps avoid a common dispute later: one party claims a task was covered, while the other says it was outside the agreement.
A useful service description might say that the business associate will process billing claims, receive patient demographic data, submit claims to payers, and maintain claim status records. A weak description might only say that the business associate will provide “administrative support.” That phrase could mean many things.
State permitted uses and disclosures
The agreement must explain how the business associate may use and disclose protected health information. In plain terms, it should answer two questions:
What is the vendor allowed to do with the information?
What is the vendor forbidden to do with the information?
Under Health and Human Services guidance, a business associate may use or disclose protected health information only as allowed by the agreement or as required by law. That means the agreement should not give broad, open-ended permission.
A good clause might allow the business associate to use protected health information only to perform billing services described in the contract, manage its internal operations as allowed by law, and report improper use or disclosure.
The agreement should also ban uses that the covered organization itself could not make. For example, if a covered organization cannot sell protected health information without proper authorization, the business associate should not have permission to do so either.
This section should be practical. If the vendor needs limited use of the information for quality checks, support, legal defense, or required reporting, say so clearly. If the vendor does not need a certain type of information, the agreement should not allow access to it.
Include strong confidentiality clauses
Confidentiality is broader than simply telling a vendor to “keep information private.” A useful confidentiality clause should explain who may access the information, why they may access it, and what safeguards must apply.
A strong confidentiality section often covers:
Access only by workforce members who need the information for the contracted services
A duty to train workforce members on privacy and security responsibilities
A duty to protect information from improper access, use, or disclosure
Limits on copying, downloading, printing, or removing information
A duty to keep information confidential after the agreement ends
The clause should also address verbal, written, and electronic information. Protected health information may appear in many forms, including patient intake forms, claim files, appointment notes, call recordings, emails, text messages, scanned documents, and database records.
The agreement should not rely on trust alone. It should require practical controls, such as limiting access, using secure transmission methods, storing records safely, and keeping logs where appropriate.
Set clear data handling procedures
Data handling is where many agreements become too vague. The agreement should explain how the business associate will receive, store, use, send, retain, return, or destroy protected health information.
This section should match how the work actually gets done. If information moves through secure file transfer, say that. If records are stored in a cloud-based system, the agreement should address that. If paper records are picked up, scanned, shredded, or returned, the agreement should describe the process.
Key data handling terms may include:
How protected health information will be received
Where and how information will be stored
Who may access the information
Whether remote access is allowed
How information will be sent back to the covered organization
How long records will be retained
How copies and backups will be handled
How paper records will be secured and destroyed
The Security Rule requires certain administrative, physical, and technical safeguards for electronic protected health information. These safeguards are not optional when the business associate handles electronic health information. The agreement should require the business associate to use appropriate protections, even if the details are handled in a separate security policy or service schedule.

Require safeguards that match the risk
The agreement should require safeguards that fit the type and amount of information involved. A vendor that stores thousands of electronic patient records carries a different risk than a one-time consultant who reviews a small file set.
Common safeguards include:
Unique user access rather than shared logins
Password rules and multifactor authentication where appropriate
Encryption for stored records or transmitted records when suitable
Secure disposal of paper and electronic records
Physical protection for devices and media
Regular access reviews
Security incident tracking
Workforce training
The agreement does not need to describe every internal procedure in long detail. In fact, too much detail can become outdated. But it should set a clear standard and require compliance with applicable privacy and security rules.
For example, instead of saying “the business associate will use good security,” the agreement could say the business associate will implement administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic protected health information, as required by the Security Rule.
That wording ties the duty to a known legal standard rather than a vague promise.
Address breach reporting and security incidents
The Breach Notification Rule requires certain notices when unsecured protected health information is breached. A business associate agreement should make breach reporting duties clear before anything goes wrong.
The agreement should cover:
What counts as a reportable breach or security incident
Who receives the report
How quickly the business associate must report
What details must be included
How the parties will cooperate during investigation and notice
Who pays for costs caused by the breach, if applicable
The federal rule generally requires a business associate to notify the covered organization after discovering a breach of unsecured protected health information. The covered organization often needs information quickly so it can assess harm, meet notice deadlines, and document its response.
Avoid vague timing such as “as soon as possible.” A better agreement sets a specific reporting window, such as within a stated number of calendar days after discovery. The exact period should fit the relationship and legal obligations.
The agreement should also distinguish between a minor security event and a breach. For example, a blocked login attempt may be a security incident, while an email sent to the wrong recipient may require a different response. Both should be addressed, but they may not require the same process.
Control subcontractors and downstream vendors
Many business associates use subcontractors. A billing provider may use a mailing vendor. A technology provider may use a hosting service. A consultant may hire a data analyst.
The Privacy Rule requires a business associate to ensure that subcontractors who create, receive, maintain, or transmit protected health information agree to similar restrictions and conditions. The covered organization should not assume this happens automatically.
The agreement should state that:
The business associate may not share protected health information with subcontractors unless the subcontractor agrees to proper privacy and security terms
The subcontractor’s terms must be at least as protective as the business associate agreement
The business associate remains responsible for subcontractor compliance
The covered organization may request information about key subcontractors where appropriate
This does not mean every subcontractor must sign directly with the covered organization. In many cases, the business associate signs its own agreement with the subcontractor. The point is to keep protections from disappearing as information moves down the chain.
Include access, amendment, and accounting support
Covered organizations have duties to respond to certain individual rights requests under the Privacy Rule. These may include requests to access records, amend records, or receive an accounting of certain disclosures.
If a business associate holds records needed to respond, the agreement should require cooperation.
For example, if a billing vendor stores claim records and a patient requests a copy from the covered organization, the covered organization may need the billing vendor to provide information on time. If the agreement is silent, delays and disputes become more likely.
The agreement should say how the business associate will help with:
Access requests
Amendment requests
Accounting of disclosures
Restriction requests if applicable
Confidential communication requests if applicable
It should also set response times. A general promise to “cooperate” may not be enough when the covered organization faces a legal deadline.
Give the covered organization audit and assurance rights
A covered organization does not need unlimited access to a vendor’s systems. But it should have some way to confirm that the business associate is meeting its obligations.
Audit and assurance provisions may include:
A right to request written proof of privacy and security practices
A right to review relevant policies or summaries
A right to ask about security incidents
A right to receive certifications or assessment summaries if available
A right to investigate suspected noncompliance
The agreement should keep these rights reasonable. For example, a small vendor may not be able to host an on-site inspection on demand. A large technology vendor may offer standard compliance documentation instead of custom audits. The key is to create a reliable path for oversight.
If the business associate refuses any form of assurance, that is a warning sign. The covered organization needs enough information to make a reasonable vendor decision.
Set termination conditions and post-termination duties
Termination clauses matter because protected health information does not disappear when a service relationship ends. The agreement should explain when the covered organization may terminate and what happens to the information afterward.
A strong termination section should include:
Termination for material breach
A chance to cure the breach, if appropriate
Immediate termination for serious privacy or security failures
Return or destruction of protected health information
Treatment of copies, archives, and backups
Continued confidentiality duties after termination
The Privacy Rule requires the agreement to authorize termination if the covered organization determines that the business associate has violated a material term. If termination is not feasible, the covered organization may have other reporting obligations.
Post-termination language should be specific. If return or destruction is feasible, the business associate should do it. If it is not feasible, such as when records remain in a required backup system for a limited time, the agreement should require continued protection and limit further use or disclosure.
Common mistakes businesses make when drafting these agreements
Many agreement problems come from speed. A vendor relationship starts, services begin, information changes hands, and the contract gets treated as a formality. That approach creates risk because privacy and security duties depend on details.
Here are the mistakes that appear most often.
Using vague language
Vague language is one of the biggest drafting problems. Phrases such as “properly protect data,” “follow all applicable laws,” or “use reasonable efforts” may sound useful, but they often fail to explain what each party must do.
A vague agreement can cause problems when:
A breach occurs
A patient requests records
A subcontractor mishandles information
The covered organization asks for proof of safeguards
The relationship ends and records must be returned
Clear wording does not need to be complicated. It should identify duties, deadlines, and limits.
Weak wording might say:
The vendor will protect patient information as needed.
Stronger wording would identify the type of information, the required safeguards, breach reporting duties, and limits on use. It would also connect those duties to the services provided.
Leaving out required compliance terms
Some service contracts include confidentiality language but still fail as business associate agreements. A basic nondisclosure clause is not enough for hipaa compliance when protected health information is involved.
The agreement must include terms required by the Privacy Rule. These include limits on use and disclosure, safeguard duties, breach reporting, subcontractor protections, access for the Secretary of Health and Human Services to determine compliance, and return or destruction of information when the agreement ends, among others.
A contract can be well written and still be incomplete if it misses required health information terms. That is why copying a general vendor contract can create hidden risk.
Failing to identify all protected health information involved
Some agreements do not specify what information the business associate will handle. This makes it hard to apply the right safeguards.
For example, a vendor might first handle only appointment reminders, then later receive billing data, diagnosis codes, or scanned medical records. If the agreement never gets updated, the written terms may no longer match the real work.
The agreement should describe the information categories, such as demographic data, billing records, claim information, appointment data, medical record extracts, or call recordings. It should also require review if the services change.
Ignoring subcontractors
Subcontractors are a common weak point. A covered organization may carefully review its direct vendor but never ask what happens after the vendor sends information elsewhere.
This is risky because protected health information can pass through multiple hands. If the downstream party lacks proper safeguards or contract terms, the covered organization may face delays, gaps, or exposure after an incident.
The business associate agreement should require written downstream protections. It should also require the business associate to manage its subcontractors and report problems that affect protected health information.
Setting unrealistic breach reporting deadlines
Some agreements require immediate reporting of every possible incident. Others give the vendor too much time. Both approaches can fail.
If the deadline is impossible, the business associate may not follow it. If the deadline is too loose, the covered organization may not have enough time to investigate, assess risk, and meet notice duties.
A better approach is to define different reporting duties for different situations. A suspected breach of unsecured protected health information should be reported quickly. Routine blocked security events may follow a different reporting process, such as periodic summaries, unless they suggest a bigger problem.

Forgetting to update the agreement
A business associate agreement is not a one-time task. Services change. Technology changes. Laws and guidance may change. Vendors add subcontractors. Data flows expand.
An agreement signed years ago may no longer describe the current relationship.
Common triggers for review include:
A new service line
A new software or storage method
A new subcontractor
A merger or ownership change
A new type of protected health information
A security incident
A change in law or regulatory guidance
A practical review schedule helps. Many organizations review these agreements at renewal, during vendor risk reviews, or when services change.
Treating templates as finished agreements
Templates can help, but they are not a substitute for careful drafting. A template may include standard required terms, but it cannot know the specific service, data flow, risk level, or vendor structure.
The biggest template problems include:
Terms that do not match the services
Missing state law requirements
Wrong party names
No breach reporting detail
No subcontractor language
No return or destruction process
Conflicting terms between the main service contract and the business associate agreement
Templates work best as a starting point. The final agreement should reflect the actual relationship.
Practical tips for drafting a solid agreement
A solid agreement does not need to be long for the sake of length. It needs to be clear, complete, and usable. The tips below help reduce common problems.
Map the information before drafting
Before writing or signing, identify how protected health information will move.
Ask:
What information will the business associate receive?
Who sends it?
How is it sent?
Where is it stored?
Who can access it?
Will the business associate create new records?
Will information go to subcontractors?
What happens when the work ends?
This simple mapping step improves the whole agreement. It helps the parties write accurate permitted uses, safeguard duties, breach response terms, and termination procedures.
Match the agreement to the service contract
The business associate agreement and the main service contract should work together. If one document says records are retained for 30 days and another says seven years, the conflict can create confusion.
Check for consistency on:
Services provided
Fees for special requests
Record retention
Breach costs
Insurance requirements
Termination rights
Subcontractor approval
Data return or destruction
If one document controls in case of conflict, say so clearly. Many organizations state that privacy and security terms control when the issue involves protected health information.
Use specific deadlines
Deadlines make duties real. Without them, cooperation can become slow and uncertain.
Useful deadline areas include:
Breach reporting
Security incident reporting
Access request support
Amendment request support
Return or destruction after termination
Notice of subcontractor changes
Response to compliance inquiries
The exact deadline should be realistic. For urgent privacy events, the window should be short. For routine documentation requests, a longer window may be reasonable.
Keep language plain enough to follow
A business associate agreement should be understandable to the people who must follow it. That includes operations staff, privacy staff, security staff, and vendor contacts.
Plain drafting helps people comply. For example, “Do not use protected health information for any purpose other than the services listed in this agreement unless the law requires it or the covered organization gives written approval” is easier to follow than dense legal wording with multiple cross-references.
Legal precision matters, but precision does not require confusing language.
Require proof, not just promises
A vendor may promise strong safeguards. The covered organization still needs a way to evaluate that promise.
Depending on the relationship, proof may include:
Written security policy summaries
Training confirmations
Security assessment summaries
Incident response procedures
Data disposal certificates
Subcontractor management procedures
Access control descriptions
The agreement should permit reasonable requests for this type of information. It should also protect the vendor’s sensitive security details where needed.
Plan the exit before the start
Termination terms should be discussed before records move. By the time a relationship ends, the parties may be under time pressure or in conflict.
The agreement should answer:
Will records be returned, destroyed, or both?
In what format will records be returned?
Who pays for return or transfer?
How quickly must this happen?
What happens to backup copies?
Will the business associate certify destruction?
What duties continue after termination?
Planning the exit helps protect patients and reduces operational disruption.
A quick drafting checklist
Use this checklist as a practical review tool before signing or renewing an agreement.
Agreement area | What to confirm |
Parties and roles | Legal names, covered organization, business associate, related entities if needed |
Services | Clear description of work involving protected health information |
Permitted uses | Specific allowed uses and disclosures tied to the services |
Confidentiality | Access limits, workforce duties, continued protection after termination |
Safeguards | Administrative, physical, and technical protections for electronic records |
Breach reporting | Clear timing, content, investigation duties, cooperation |
Subcontractors | Written downstream protections and responsibility for compliance |
Individual rights | Support for access, amendment, and disclosure accounting |
Oversight | Reasonable audit, documentation, or assurance rights |
Termination | Return, destruction, backups, breach termination, continuing duties |
Updates | Review triggers for service, vendor, technology, or legal changes |
When to get legal or compliance review
Some agreements are simple. Others deserve close review before signing.
Legal or compliance review is especially helpful when:
The business associate handles large amounts of protected health information
The vendor stores or transmits electronic records
The vendor uses multiple subcontractors
The services cross state lines
The agreement limits liability in a way that conflicts with risk
The vendor refuses standard privacy or security terms
The relationship involves sensitive records
A prior incident has occurred
The cost of review is often lower than the cost of fixing a poor agreement after a breach, failed audit, or vendor dispute.
For help building or reviewing privacy agreements and related compliance support, see the available consulting and compliance pricing plans.
Frequently asked questions
Is a confidentiality agreement the same as a business associate agreement?
No. A confidentiality agreement may require a vendor to keep information private, but a business associate agreement must include specific privacy and security terms required by the Health Insurance Portability and Accountability Act rules. A general confidentiality clause usually does not cover all required duties.
Who is responsible for getting the agreement signed?
The covered organization usually has the duty to make sure a proper agreement is in place before sharing protected health information with a business associate. The business associate also has duties under the law, especially once it handles protected health information.
Does every vendor need a business associate agreement?
No. A vendor needs one when it creates, receives, maintains, or transmits protected health information for a covered organization or another business associate in a role covered by the rules. A plumber fixing a sink in a clinic usually does not need one. A billing company handling patient claim records usually does.
What happens if a business associate refuses to sign?
That is a serious warning sign. If the vendor will handle protected health information and refuses to sign a proper agreement, the covered organization should not share the information until the issue is resolved.
How often should a business associate agreement be reviewed?
Review it when services change, technology changes, subcontractors change, laws or guidance change, or the contract renews. Many organizations also review these agreements as part of regular vendor oversight.

The takeaway
A strong business associate agreement is clear, specific, and tied to the real work being performed. It should define the parties, limit permitted uses, require confidentiality, explain data handling, set safeguard duties, control subcontractors, address breach reporting, and spell out termination procedures.
The most common mistakes are avoidable. Vague language, missing required terms, ignored subcontractors, unrealistic deadlines, and outdated templates all create risk. The better approach is simple: map the information, write duties in plain language, set specific deadlines, require reasonable proof, and review the agreement when the relationship changes.
A well-drafted agreement does more than satisfy a legal requirement. It gives both parties a clear operating plan for protecting health information from the first day of service to the final return or destruction of records.





Comments