What is BAA (Business Associate Agreement)?

A BAA is the contract HIPAA requires between a covered entity (e.g. a medical practice) and any vendor that handles PHI on its behalf - defining responsibilities, breach notification timelines, and termination rights.

Under HIPAA, a Covered Entity remains liable for PHI even when a third party processes it on their behalf. A signed BAA shifts certain obligations to the Business Associate and is required by 45 CFR § 164.504(e) before the Business Associate can lawfully receive PHI.

Common Business Associates include cloud-storage providers, IT MSPs, billing services, transcription vendors, EHR vendors, and email-hosting providers. Many vendors offer BAAs only on enterprise tiers - for example Microsoft 365 Business Premium qualifies but Business Basic does not.

A BAA must include specific elements: the permitted uses of PHI, the safeguards the Business Associate will apply, breach reporting timelines (generally within 60 days of discovery), subcontractor flow-down requirements, and return / destruction of PHI on termination.

Why it matters for Florida small business

If your medical practice uses a vendor without a signed BAA, an OCR audit will find it and impose a fine. The fix is reaching out and getting one signed - many vendors have a self-serve BAA portal.

What to do

Audit your vendor list this month. For every vendor that touches PHI, confirm a signed BAA on file. Microsoft 365 + Google Workspace both offer BAAs at the Business tier and above.

Related terms