Business Associate Agreement Example: A Clause Guide
A billing vendor emails your practice manager a 14-page contract at 4:40 p.m. on a Friday. Page nine is labeled "Exhibit B — HIPAA Business Associate Addendum." Your manager forwards it to you with one line: "Is this okay to sign?" If you want a usable answer, you need a business associate agreement example to compare it against — one that shows which clauses HIPAA actually requires, which ones the vendor rewrote in its own favor, and which ones are simply missing.
This article walks the required elements clause by clause, gives you the language patterns to look for, and tells you what the signed file needs to look like when a regulator or a client's security team asks for it.
What Must a Business Associate Agreement Include?
Under 45 CFR 164.504(e), a business associate agreement must do all of the following:
- Describe the permitted and required uses and disclosures of protected health information by the business associate.
- Prohibit uses or disclosures beyond what the contract allows or what law requires.
- Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
- Require the business associate to report unauthorized uses or disclosures, security incidents, and breaches to the covered entity.
- Bind subcontractors to the same restrictions through written agreements.
- Require the business associate to make PHI available so the covered entity can satisfy individual access requests, amendment requests, and accounting of disclosures.
- Make the business associate's internal practices, books, and records available to HHS.
- Require return or destruction of PHI at termination, where feasible.
- Authorize the covered entity to terminate for material breach of the agreement.
HHS publishes sample business associate agreement provisions covering these points. Treat that document as a floor, not a finished contract — it deliberately omits indemnification, insurance, liability caps, and notification timelines shorter than the regulatory maximum.
Reading a Business Associate Agreement Example Clause by Clause
Definitions and the Scope Clause
The first substantive paragraph should tie the agreement to the underlying services contract and state that HIPAA-defined terms carry their regulatory meaning. Watch for a scope clause that limits the BAA to "services described in Schedule 1." If the vendor later adds a service line — say, your transcription vendor starts handling patient reminder calls — the BAA may not cover it.
Fix: add "and any successor or additional services involving protected health information." One sentence, and it prevents a renewal-cycle gap.
Permitted Uses and Disclosures
This is where most vendor-drafted agreements overreach. Standard permitted uses are: performing the contracted services, the business associate's proper management and administration, and providing data aggregation services to the covered entity.
Now read for the phrase "de-identified" or "aggregate analytics" or "product improvement." A vendor that reserves the right to de-identify your patient data and use it for its own commercial purposes is asking you for something the law does not require you to give. De-identification under 45 CFR 164.514 is a use of PHI, and you control whether the agreement permits it. Strike it or price it.
Safeguards and the Security Rule Hook
A compliant clause says the business associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI, in compliance with Subpart C of Part 164. Vague language like "industry-standard security" is not a substitute.
Strong agreements add specifics: encryption of ePHI at rest and in transit, unique user identification, annual workforce training, and an annual risk analysis. HHS proposed changes to the Security Rule in January 2025 that would tighten these expectations, including annual written verification from business associates about their technical safeguards. That rule was not final as of December 2025, but the proposal signals where scrutiny is heading. Writing verification into your BAAs now costs nothing and puts you ahead of it.
The Incident and Breach Reporting Clause — Where the Clocks Live
Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. That outer limit is a disaster for you, because your own 60-day clock to notify patients under 164.404 does not reset — it can start running from the date the business associate discovered the breach, depending on the agency relationship.
Negotiate a shorter internal deadline. Common terms in the field:
- Notice of a confirmed breach of unsecured PHI within five business days of discovery.
- Notice of a suspected security incident within ten business days.
- A written incident report within 15 days containing the elements you need for patient notification: date of breach, date of discovery, categories of PHI involved, individuals affected, and mitigation steps.
- Vendor bears the cost of notification, credit monitoring, and call center services when the incident originates on its side.
Also address unsuccessful security incidents. Port scans and blocked login attempts happen constantly. Without a carve-out, a literal reading of "report all security incidents" produces a daily noise feed. Standard language: routine unsuccessful attempts are deemed reported by this paragraph and require no individual notice.
Subcontractor Flow-Down
Your billing company uses a clearinghouse. The clearinghouse uses a cloud host. Each downstream entity that creates, receives, maintains, or transmits PHI is itself a business associate and needs a written agreement with the party above it. Your BAA must require that flow-down.
Ask for the list. A reasonable clause obligates the vendor to maintain a current roster of subcontractors handling your PHI and to provide it on request within ten business days. You will not audit every one, but you need to know whether your data left the country or landed with a fourth party you have never heard of.
Individual Rights Support
Your practice owes a patient access to their designated record set within 30 days of the request, with one 30-day extension available. If the records live in a vendor's system, your BAA has to obligate that vendor to produce them fast enough for you to meet the deadline. Write in a specific turnaround — ten business days is typical — rather than the regulation's soft "make available" language.
The same applies to amendment requests under 164.526 and accounting of disclosures under 164.528. If your vendor cannot generate a disclosure log, you found that out during negotiation instead of during a complaint investigation.
Termination and Data Return
The clause should require return or destruction of all PHI at termination and, where return or destruction is infeasible, extend the agreement's protections indefinitely to the retained data. Add a certificate-of-destruction requirement with a deadline — 30 days after termination — and specify the destruction method for electronic media consistent with NIST SP 800-88 media sanitization guidance.
Practices routinely skip this and then discover, three years after switching vendors, that the old system still holds a full patient database nobody is patching.
Building Your Own Business Associate Agreement Example Instead of Signing Theirs
Whoever drafts, wins. When a vendor sends its paper, you spend your leverage arguing about liability caps and breach timelines. When you send yours, the vendor spends its legal budget instead — and small vendors frequently sign without changes.
Keep one standard template and a one-page rider for the terms you will concede. If you do not have counsel on retainer for this, you can generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export, then hand the DOCX to your attorney for a single review pass. One-time purchase, no subscription — which matters when you are papering fourteen vendors before the end of the fiscal year.
Who Signs, and What the File Has to Show
Assign this before the next contract lands, not after.
- Practice manager or contracts lead flags every new vendor and asks one question: will this company create, receive, maintain, or transmit PHI on our behalf? If yes, no PHI moves until the BAA is executed.
- Privacy officer reviews the agreement against your template, documents any deviations in a one-paragraph memo, and dates it.
- Authorized signer — usually an owner, administrator, or officer — executes. A front-desk staffer's signature on a vendor portal checkbox is a weak record.
- Privacy officer files the executed PDF in a single vendor folder with the effective date, renewal date, and a calendar reminder 90 days before expiration.
Your evidence package for any given vendor should contain: the fully executed BAA with both signatures and dates, the underlying services agreement, the vendor's most recent security attestation or questionnaire response, the subcontractor list if you requested one, and the certificate of destruction if the relationship ended. That is five documents. An investigator who asks for a BAA and receives it within an hour is dealing with a different practice than one who receives "we think it's in the old email account."
Who Does Not Need a BAA
Conduits that merely transport PHI without accessing it other than randomly or incidentally — the postal service, a courier, an internet service provider moving encrypted packets. Also: other treating providers receiving PHI for treatment purposes, health plans receiving enrollment data, and workforce members. HHS's business associates guidance works through the edge cases. When in doubt, sign one. There is no penalty for an unnecessary BAA and there is a real one for a missing required BAA.
The Three Failures That Show Up in Investigations
The unsigned draft. Negotiation stalled, PHI started flowing anyway, and the file holds a redline nobody executed. Track BAA status as a gate on vendor onboarding, not a follow-up task.
The BAA that predates the relationship's current shape. You signed in 2018 for scheduling software. The vendor now runs your patient messaging and stores documents. The safeguards clause never contemplated any of it. Review BAAs at contract renewal and any time a vendor's scope expands.
No downstream visibility. Breaches reported to OCR frequently trace back to a vendor, and the covered entity's name appears on the public breach portal alongside the vendor's. Your patients see your name. Your BAA is the instrument that allocates the cost and defines what you get told and when.
Next Step
Pull your vendor list this week and mark each row: executed BAA on file, draft only, or none. For every row that is not "executed," you have a task with a name and a date attached. If you need clean paper to send, build a business associate agreement in six steps and export it as PDF or DOCX — then work the list. If your broader documentation set is also thin, automated risk analysis and policy generation covers the rest of the file an investigator will ask for.