top of page

Business Associate Agreements What to Include and Common Mistakes to Avoid

A weak business associate agreement can turn a routine vendor relationship into a compliance problem. In health care, the agreement is not just paperwork. It is one of the main ways a covered organization sets clear rules for how another party may use, protect, share, and return health information.


Under the Health Insurance Portability and Accountability Act, a covered organization generally must have a written agreement with a vendor or contractor that creates, receives, maintains, or transmits protected health information on its behalf. The U.S. Department of Health and Human Services explains this requirement through the Privacy Rule, especially 45 CFR 164.502(e) and 164.504(e). These rules describe what must be in a business associate contract and how the business associate must handle protected health information.


This article is informational only and is not legal advice. A qualified attorney or compliance professional should review agreements before they are signed.


Close-up view of a locked document box beside labeled health records
A strong agreement starts with clear control over sensitive information.

What a business associate agreement does


A business associate agreement is a written contract between a covered organization and a person or company that performs certain services involving protected health information.


A covered organization may include:


  • A health care provider that transmits health information in standard electronic transactions

  • A health plan

  • A health care clearinghouse


A business associate may include a billing service, legal service, claims processor, consultant, data storage provider, document disposal vendor, answering service, or technology provider if that party handles protected health information for the covered organization.


The agreement sets the rules for that relationship. It tells the business associate what it may do with the information, what it may not do, how it must protect the information, what happens if there is a breach, and what must happen when the relationship ends.


Business Associate Agreements (BAAs) matter because the covered organization remains responsible for choosing vendors carefully and documenting required protections. A handshake or a broad service contract is not enough when a vendor handles protected health information.


The essential elements every agreement should include


A strong agreement should be specific. It should match the actual services being provided, the type of information involved, and the real risks of the relationship.


The federal rules do not require every agreement to use the same exact wording. Still, the Privacy Rule lists several required contract terms. The sections below cover the core elements that should appear in a well-drafted agreement.


Define the parties and the relationship clearly


The agreement should identify each party by legal name and role.


This sounds simple, but mistakes happen. A health care practice may sign with a parent company while the work is performed by a subsidiary. A consultant may operate through a limited liability company. A software provider may use a separate entity for hosting or support.


The agreement should make clear:


  • Who the covered organization is

  • Who the business associate is

  • Whether the agreement also applies to related entities

  • What services the business associate will provide

  • What protected health information the business associate will access, create, receive, maintain, or transmit


A clear description helps avoid a common dispute later: one party claims a task was covered, while the other says it was outside the agreement.


A useful service description might say that the business associate will process billing claims, receive patient demographic data, submit claims to payers, and maintain claim status records. A weak description might only say that the business associate will provide “administrative support.” That phrase could mean many things.


State permitted uses and disclosures


The agreement must explain how the business associate may use and disclose protected health information. In plain terms, it should answer two questions:


  • What is the vendor allowed to do with the information?

  • What is the vendor forbidden to do with the information?


Under Health and Human Services guidance, a business associate may use or disclose protected health information only as allowed by the agreement or as required by law. That means the agreement should not give broad, open-ended permission.


A good clause might allow the business associate to use protected health information only to perform billing services described in the contract, manage its internal operations as allowed by law, and report improper use or disclosure.


The agreement should also ban uses that the covered organization itself could not make. For example, if a covered organization cannot sell protected health information without proper authorization, the business associate should not have permission to do so either.


This section should be practical. If the vendor needs limited use of the information for quality checks, support, legal defense, or required reporting, say so clearly. If the vendor does not need a certain type of information, the agreement should not allow access to it.


Include strong confidentiality clauses


Confidentiality is broader than simply telling a vendor to “keep information private.” A useful confidentiality clause should explain who may access the information, why they may access it, and what safeguards must apply.


A strong confidentiality section often covers:


  • Access only by workforce members who need the information for the contracted services

  • A duty to train workforce members on privacy and security responsibilities

  • A duty to protect information from improper access, use, or disclosure

  • Limits on copying, downloading, printing, or removing information

  • A duty to keep information confidential after the agreement ends


The clause should also address verbal, written, and electronic information. Protected health information may appear in many forms, including patient intake forms, claim files, appointment notes, call recordings, emails, text messages, scanned documents, and database records.


The agreement should not rely on trust alone. It should require practical controls, such as limiting access, using secure transmission methods, storing records safely, and keeping logs where appropriate.


Set clear data handling procedures


Data handling is where many agreements become too vague. The agreement should explain how the business associate will receive, store, use, send, retain, return, or destroy protected health information.


This section should match how the work actually gets done. If information moves through secure file transfer, say that. If records are stored in a cloud-based system, the agreement should address that. If paper records are picked up, scanned, shredded, or returned, the agreement should describe the process.


Key data handling terms may include:


  • How protected health information will be received

  • Where and how information will be stored

  • Who may access the information

  • Whether remote access is allowed

  • How information will be sent back to the covered organization

  • How long records will be retained

  • How copies and backups will be handled

  • How paper records will be secured and destroyed


The Security Rule requires certain administrative, physical, and technical safeguards for electronic protected health information. These safeguards are not optional when the business associate handles electronic health information. The agreement should require the business associate to use appropriate protections, even if the details are handled in a separate security policy or service schedule.


Overhead view of sealed envelopes and a written checklist for data handling
Data handling terms should reflect how records actually move and where they are stored.

Require safeguards that match the risk


The agreement should require safeguards that fit the type and amount of information involved. A vendor that stores thousands of electronic patient records carries a different risk than a one-time consultant who reviews a small file set.


Common safeguards include:


  • Unique user access rather than shared logins

  • Password rules and multifactor authentication where appropriate

  • Encryption for stored records or transmitted records when suitable

  • Secure disposal of paper and electronic records

  • Physical protection for devices and media

  • Regular access reviews

  • Security incident tracking

  • Workforce training


The agreement does not need to describe every internal procedure in long detail. In fact, too much detail can become outdated. But it should set a clear standard and require compliance with applicable privacy and security rules.


For example, instead of saying “the business associate will use good security,” the agreement could say the business associate will implement administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic protected health information, as required by the Security Rule.


That wording ties the duty to a known legal standard rather than a vague promise.


Address breach reporting and security incidents


The Breach Notification Rule requires certain notices when unsecured protected health information is breached. A business associate agreement should make breach reporting duties clear before anything goes wrong.


The agreement should cover:


  • What counts as a reportable breach or security incident

  • Who receives the report

  • How quickly the business associate must report

  • What details must be included

  • How the parties will cooperate during investigation and notice

  • Who pays for costs caused by the breach, if applicable


The federal rule generally requires a business associate to notify the covered organization after discovering a breach of unsecured protected health information. The covered organization often needs information quickly so it can assess harm, meet notice deadlines, and document its response.


Avoid vague timing such as “as soon as possible.” A better agreement sets a specific reporting window, such as within a stated number of calendar days after discovery. The exact period should fit the relationship and legal obligations.


The agreement should also distinguish between a minor security event and a breach. For example, a blocked login attempt may be a security incident, while an email sent to the wrong recipient may require a different response. Both should be addressed, but they may not require the same process.


Control subcontractors and downstream vendors


Many business associates use subcontractors. A billing provider may use a mailing vendor. A technology provider may use a hosting service. A consultant may hire a data analyst.


The Privacy Rule requires a business associate to ensure that subcontractors who create, receive, maintain, or transmit protected health information agree to similar restrictions and conditions. The covered organization should not assume this happens automatically.


The agreement should state that:


  • The business associate may not share protected health information with subcontractors unless the subcontractor agrees to proper privacy and security terms

  • The subcontractor’s terms must be at least as protective as the business associate agreement

  • The business associate remains responsible for subcontractor compliance

  • The covered organization may request information about key subcontractors where appropriate


This does not mean every subcontractor must sign directly with the covered organization. In many cases, the business associate signs its own agreement with the subcontractor. The point is to keep protections from disappearing as information moves down the chain.


Include access, amendment, and accounting support


Covered organizations have duties to respond to certain individual rights requests under the Privacy Rule. These may include requests to access records, amend records, or receive an accounting of certain disclosures.


If a business associate holds records needed to respond, the agreement should require cooperation.


For example, if a billing vendor stores claim records and a patient requests a copy from the covered organization, the covered organization may need the billing vendor to provide information on time. If the agreement is silent, delays and disputes become more likely.


The agreement should say how the business associate will help with:


  • Access requests

  • Amendment requests

  • Accounting of disclosures

  • Restriction requests if applicable

  • Confidential communication requests if applicable


It should also set response times. A general promise to “cooperate” may not be enough when the covered organization faces a legal deadline.


Give the covered organization audit and assurance rights


A covered organization does not need unlimited access to a vendor’s systems. But it should have some way to confirm that the business associate is meeting its obligations.


Audit and assurance provisions may include:


  • A right to request written proof of privacy and security practices

  • A right to review relevant policies or summaries

  • A right to ask about security incidents

  • A right to receive certifications or assessment summaries if available

  • A right to investigate suspected noncompliance


The agreement should keep these rights reasonable. For example, a small vendor may not be able to host an on-site inspection on demand. A large technology vendor may offer standard compliance documentation instead of custom audits. The key is to create a reliable path for oversight.


If the business associate refuses any form of assurance, that is a warning sign. The covered organization needs enough information to make a reasonable vendor decision.


Set termination conditions and post-termination duties


Termination clauses matter because protected health information does not disappear when a service relationship ends. The agreement should explain when the covered organization may terminate and what happens to the information afterward.


A strong termination section should include:


  • Termination for material breach

  • A chance to cure the breach, if appropriate

  • Immediate termination for serious privacy or security failures

  • Return or destruction of protected health information

  • Treatment of copies, archives, and backups

  • Continued confidentiality duties after termination


The Privacy Rule requires the agreement to authorize termination if the covered organization determines that the business associate has violated a material term. If termination is not feasible, the covered organization may have other reporting obligations.


Post-termination language should be specific. If return or destruction is feasible, the business associate should do it. If it is not feasible, such as when records remain in a required backup system for a limited time, the agreement should require continued protection and limit further use or disclosure.


Common mistakes businesses make when drafting these agreements


Many agreement problems come from speed. A vendor relationship starts, services begin, information changes hands, and the contract gets treated as a formality. That approach creates risk because privacy and security duties depend on details.


Here are the mistakes that appear most often.


Using vague language


Vague language is one of the biggest drafting problems. Phrases such as “properly protect data,” “follow all applicable laws,” or “use reasonable efforts” may sound useful, but they often fail to explain what each party must do.


A vague agreement can cause problems when:


  • A breach occurs

  • A patient requests records

  • A subcontractor mishandles information

  • The covered organization asks for proof of safeguards

  • The relationship ends and records must be returned


Clear wording does not need to be complicated. It should identify duties, deadlines, and limits.


Weak wording might say:


The vendor will protect patient information as needed.

Stronger wording would identify the type of information, the required safeguards, breach reporting duties, and limits on use. It would also connect those duties to the services provided.


Leaving out required compliance terms


Some service contracts include confidentiality language but still fail as business associate agreements. A basic nondisclosure clause is not enough for hipaa compliance when protected health information is involved.


The agreement must include terms required by the Privacy Rule. These include limits on use and disclosure, safeguard duties, breach reporting, subcontractor protections, access for the Secretary of Health and Human Services to determine compliance, and return or destruction of information when the agreement ends, among others.


A contract can be well written and still be incomplete if it misses required health information terms. That is why copying a general vendor contract can create hidden risk.


Failing to identify all protected health information involved


Some agreements do not specify what information the business associate will handle. This makes it hard to apply the right safeguards.


For example, a vendor might first handle only appointment reminders, then later receive billing data, diagnosis codes, or scanned medical records. If the agreement never gets updated, the written terms may no longer match the real work.


The agreement should describe the information categories, such as demographic data, billing records, claim information, appointment data, medical record extracts, or call recordings. It should also require review if the services change.


Ignoring subcontractors


Subcontractors are a common weak point. A covered organization may carefully review its direct vendor but never ask what happens after the vendor sends information elsewhere.


This is risky because protected health information can pass through multiple hands. If the downstream party lacks proper safeguards or contract terms, the covered organization may face delays, gaps, or exposure after an incident.


The business associate agreement should require written downstream protections. It should also require the business associate to manage its subcontractors and report problems that affect protected health information.


Setting unrealistic breach reporting deadlines


Some agreements require immediate reporting of every possible incident. Others give the vendor too much time. Both approaches can fail.


If the deadline is impossible, the business associate may not follow it. If the deadline is too loose, the covered organization may not have enough time to investigate, assess risk, and meet notice duties.


A better approach is to define different reporting duties for different situations. A suspected breach of unsecured protected health information should be reported quickly. Routine blocked security events may follow a different reporting process, such as periodic summaries, unless they suggest a bigger problem.


Eye-level view of a cracked padlock near scattered paper warning notices
Unclear breach duties can slow the response when timing matters most.

Forgetting to update the agreement


A business associate agreement is not a one-time task. Services change. Technology changes. Laws and guidance may change. Vendors add subcontractors. Data flows expand.


An agreement signed years ago may no longer describe the current relationship.


Common triggers for review include:


  • A new service line

  • A new software or storage method

  • A new subcontractor

  • A merger or ownership change

  • A new type of protected health information

  • A security incident

  • A change in law or regulatory guidance


A practical review schedule helps. Many organizations review these agreements at renewal, during vendor risk reviews, or when services change.


Treating templates as finished agreements


Templates can help, but they are not a substitute for careful drafting. A template may include standard required terms, but it cannot know the specific service, data flow, risk level, or vendor structure.


The biggest template problems include:


  • Terms that do not match the services

  • Missing state law requirements

  • Wrong party names

  • No breach reporting detail

  • No subcontractor language

  • No return or destruction process

  • Conflicting terms between the main service contract and the business associate agreement


Templates work best as a starting point. The final agreement should reflect the actual relationship.


Practical tips for drafting a solid agreement


A solid agreement does not need to be long for the sake of length. It needs to be clear, complete, and usable. The tips below help reduce common problems.


Map the information before drafting


Before writing or signing, identify how protected health information will move.


Ask:


  • What information will the business associate receive?

  • Who sends it?

  • How is it sent?

  • Where is it stored?

  • Who can access it?

  • Will the business associate create new records?

  • Will information go to subcontractors?

  • What happens when the work ends?


This simple mapping step improves the whole agreement. It helps the parties write accurate permitted uses, safeguard duties, breach response terms, and termination procedures.


Match the agreement to the service contract


The business associate agreement and the main service contract should work together. If one document says records are retained for 30 days and another says seven years, the conflict can create confusion.


Check for consistency on:


  • Services provided

  • Fees for special requests

  • Record retention

  • Breach costs

  • Insurance requirements

  • Termination rights

  • Subcontractor approval

  • Data return or destruction


If one document controls in case of conflict, say so clearly. Many organizations state that privacy and security terms control when the issue involves protected health information.


Use specific deadlines


Deadlines make duties real. Without them, cooperation can become slow and uncertain.


Useful deadline areas include:


  • Breach reporting

  • Security incident reporting

  • Access request support

  • Amendment request support

  • Return or destruction after termination

  • Notice of subcontractor changes

  • Response to compliance inquiries


The exact deadline should be realistic. For urgent privacy events, the window should be short. For routine documentation requests, a longer window may be reasonable.


Keep language plain enough to follow


A business associate agreement should be understandable to the people who must follow it. That includes operations staff, privacy staff, security staff, and vendor contacts.


Plain drafting helps people comply. For example, “Do not use protected health information for any purpose other than the services listed in this agreement unless the law requires it or the covered organization gives written approval” is easier to follow than dense legal wording with multiple cross-references.


Legal precision matters, but precision does not require confusing language.


Require proof, not just promises


A vendor may promise strong safeguards. The covered organization still needs a way to evaluate that promise.


Depending on the relationship, proof may include:


  • Written security policy summaries

  • Training confirmations

  • Security assessment summaries

  • Incident response procedures

  • Data disposal certificates

  • Subcontractor management procedures

  • Access control descriptions


The agreement should permit reasonable requests for this type of information. It should also protect the vendor’s sensitive security details where needed.


Plan the exit before the start


Termination terms should be discussed before records move. By the time a relationship ends, the parties may be under time pressure or in conflict.


The agreement should answer:


  • Will records be returned, destroyed, or both?

  • In what format will records be returned?

  • Who pays for return or transfer?

  • How quickly must this happen?

  • What happens to backup copies?

  • Will the business associate certify destruction?

  • What duties continue after termination?


Planning the exit helps protect patients and reduces operational disruption.


A quick drafting checklist


Use this checklist as a practical review tool before signing or renewing an agreement.


Agreement area

What to confirm

Parties and roles

Legal names, covered organization, business associate, related entities if needed

Services

Clear description of work involving protected health information

Permitted uses

Specific allowed uses and disclosures tied to the services

Confidentiality

Access limits, workforce duties, continued protection after termination

Safeguards

Administrative, physical, and technical protections for electronic records

Breach reporting

Clear timing, content, investigation duties, cooperation

Subcontractors

Written downstream protections and responsibility for compliance

Individual rights

Support for access, amendment, and disclosure accounting

Oversight

Reasonable audit, documentation, or assurance rights

Termination

Return, destruction, backups, breach termination, continuing duties

Updates

Review triggers for service, vendor, technology, or legal changes


When to get legal or compliance review


Some agreements are simple. Others deserve close review before signing.


Legal or compliance review is especially helpful when:


  • The business associate handles large amounts of protected health information

  • The vendor stores or transmits electronic records

  • The vendor uses multiple subcontractors

  • The services cross state lines

  • The agreement limits liability in a way that conflicts with risk

  • The vendor refuses standard privacy or security terms

  • The relationship involves sensitive records

  • A prior incident has occurred


The cost of review is often lower than the cost of fixing a poor agreement after a breach, failed audit, or vendor dispute.


For help building or reviewing privacy agreements and related compliance support, see the available consulting and compliance pricing plans.


Frequently asked questions


Is a confidentiality agreement the same as a business associate agreement?


No. A confidentiality agreement may require a vendor to keep information private, but a business associate agreement must include specific privacy and security terms required by the Health Insurance Portability and Accountability Act rules. A general confidentiality clause usually does not cover all required duties.


Who is responsible for getting the agreement signed?


The covered organization usually has the duty to make sure a proper agreement is in place before sharing protected health information with a business associate. The business associate also has duties under the law, especially once it handles protected health information.


Does every vendor need a business associate agreement?


No. A vendor needs one when it creates, receives, maintains, or transmits protected health information for a covered organization or another business associate in a role covered by the rules. A plumber fixing a sink in a clinic usually does not need one. A billing company handling patient claim records usually does.


What happens if a business associate refuses to sign?


That is a serious warning sign. If the vendor will handle protected health information and refuses to sign a proper agreement, the covered organization should not share the information until the issue is resolved.


How often should a business associate agreement be reviewed?


Review it when services change, technology changes, subcontractors change, laws or guidance change, or the contract renews. Many organizations also review these agreements as part of regular vendor oversight.


Wide-angle view of a sealed storage crate on a clean shelf with labeled folders
Ending a vendor relationship should include a clear plan for return or destruction of records.

The takeaway


A strong business associate agreement is clear, specific, and tied to the real work being performed. It should define the parties, limit permitted uses, require confidentiality, explain data handling, set safeguard duties, control subcontractors, address breach reporting, and spell out termination procedures.


The most common mistakes are avoidable. Vague language, missing required terms, ignored subcontractors, unrealistic deadlines, and outdated templates all create risk. The better approach is simple: map the information, write duties in plain language, set specific deadlines, require reasonable proof, and review the agreement when the relationship changes.


A well-drafted agreement does more than satisfy a legal requirement. It gives both parties a clear operating plan for protecting health information from the first day of service to the final return or destruction of records.


Comments


bottom of page