Business Associate Agreement PDF: What Yours Must Say
Your billing vendor emails you at 4:40 on a Friday: a staff member's mailbox was accessed by someone outside the company, and roughly 900 of your patients' names, dates of service, and claim details were in it. The first question your attorney asks is not about the mailbox. It is: send me the signed BAA. If the only business associate agreement PDF you can find is an unsigned draft from 2019 with the vendor's old corporate name on it, you have two problems instead of one.
This article is for the person in your practice who owns the vendor list. It covers what a business associate agreement PDF must contain under 45 CFR 164.504(e), which vendors need one, which timelines you should negotiate down, how long you keep the executed copy, and what documented evidence looks like when someone asks.
What a Business Associate Agreement PDF Must Contain
The Privacy Rule specifies the required content. A compliant BAA must:
- Describe the permitted and required uses and disclosures of protected health information by the business associate.
- Prohibit uses or disclosures beyond what the contract permits or law requires.
- Require appropriate safeguards, including compliance with the Security Rule (Subpart C) for electronic PHI.
- Require the business associate to report unauthorized uses or disclosures, including breaches of unsecured PHI, to your practice.
- Require that subcontractors handling PHI agree to the same restrictions in writing.
- Require the business associate to make PHI available so you can satisfy patient access requests under 164.524, amendment requests under 164.526, and accountings of disclosures under 164.528.
- Require compliance with the applicable Privacy Rule provisions where the business associate carries out one of your obligations on your behalf.
- Require the business associate to make its internal practices, books, and records available to HHS for compliance review.
- Authorize termination if the business associate breaches a material term, and require return or destruction of PHI at termination where feasible.
HHS publishes sample business associate agreement provisions that track these requirements clause by clause. Those samples are a starting point, not a finished contract. They contain bracketed choices, optional provisions, and no signature block. Nobody at HHS reviews or approves your final document.
Who Actually Needs a BAA on Your Vendor List
The test is function, not industry. A business associate creates, receives, maintains, or transmits PHI to perform a function or activity on your behalf, or provides a listed service (legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, financial) that involves PHI.
Walk your accounts payable ledger line by line. The vendors that almost always need a signed BAA:
- Practice management and clinical software hosts
- Billing companies, coding contractors, and clearinghouses
- Transcription services and scribe platforms
- Cloud storage, backup, and hosted email providers
- Managed IT and help desk contractors with system access
- Document shredding and secure destruction companies
- Answering services, patient reminder and outreach platforms
- Release-of-information and copy services
- Outside counsel and consultants who review charts
- Collection agencies working patient balances
The Conduit Exception Is Narrower Than Vendors Claim
The conduit exception covers entities that merely transport PHI without accessing it other than randomly or infrequently — the postal service, private couriers, and telecommunications carriers. It does not cover companies that store your data. HHS has been explicit that a cloud service provider holding electronic PHI is a business associate even if it never views the data and the data is encrypted with a key the provider does not hold. Read the HHS cloud computing guidance before you accept a "we're just a pipe" argument.
Downstream Subcontractors Need Their Own Agreements
You contract with your billing company. Your billing company contracts with an offshore data entry firm. That firm is a business associate of your business associate and must sign an agreement with equivalent terms. You do not sign it, but your BAA must require it, and you should be able to ask for confirmation that it exists. Add one question to your annual vendor review: list every subcontractor with access to our PHI and confirm each has a signed agreement.
Timelines Worth Negotiating Before You Sign
The regulation gives a business associate up to 60 calendar days from discovery to notify you of a breach of unsecured PHI. Your own clock to notify patients is also 60 days from discovery — and discovery by your business associate acting as your agent can be imputed to you. If your vendor uses all 60 days, you have zero.
Push for a shorter contractual window. Five business days for any suspected security incident involving PHI, with a preliminary report and a named contact, is a reasonable ask and most serious vendors will agree. Also specify:
- Who pays for notification. Mailing, credit monitoring, call center, and media notice costs when the vendor caused the breach.
- Who drafts the notice. Your practice should control the letter that goes out under your name.
- Turnaround for records requests. If the vendor holds the only copy of a record, you need it back fast enough to meet the 30-day access deadline. Ten calendar days is a defensible contract term.
- Return or destruction at termination. Specify the format, the deadline, and a written certificate of destruction.
Producing a Signature-Ready Business Associate Agreement PDF
Most practices lose weeks here. A staff member downloads the HHS sample provisions, pastes them into a document, and then stalls on the bracketed decisions: which state law governs, whether the vendor may de-identify data, what the indemnification looks like, whether subcontractors are permitted at all. The draft sits in a shared folder while the vendor keeps processing claims without a signed agreement.
If you need an executable document rather than a template to wrestle with, a six-step BAA generator that exports a signature-ready PDF and DOCX walks you through the required clauses and the optional decisions, then produces a finished agreement you can send the same afternoon. It is a one-time purchase with no subscription, which matters when you are papering nine vendors at once and do not want another recurring line item.
Whatever tool you use, the output needs a real signature block: legal entity names on both sides, printed names and titles of the signers, dates, and an effective date. A business associate agreement PDF without dated signatures from both parties is a draft, and an investigator will read it as an unsigned draft.
Where BAAs Fail in the Real World
Four failure patterns show up repeatedly in practices of every size.
The agreement exists but nobody can find it. It was signed in a portal by an office manager who left in 2022. Fix: one folder, one naming convention — VendorLegalName_BAA_YYYY-MM-DD.pdf — and a spreadsheet or register that maps every vendor to its file path, effective date, and renewal or review date.
The signed party no longer exists. Your vendor was acquired and now operates under a new entity. The old BAA may not follow. Fix: on notice of any acquisition, request a new agreement or a written assignment and assumption.
The vendor's paper is silent on the hard parts. Vendor-supplied BAAs frequently cap liability at fees paid, extend breach notice to the full 60 days, and permit unlimited subcontracting. Those are business terms, not regulatory ones — you are allowed to redline them.
Scope drift. You signed a BAA covering appointment reminders. Two years later the same vendor runs your patient portal messaging and holds clinical notes. The agreement's description of permitted uses no longer matches reality. Fix: review permitted-use language whenever a vendor's product footprint expands.
Retention: Six Years From Creation or Last Effective Date
Under 164.530(j), you retain required documentation for six years from the date it was created or the date it last was in effect, whichever is later. For a BAA signed in 2019 and terminated in 2024, the clock runs to 2030. Keep terminated agreements, amendments, certificates of destruction, and the correspondence around termination in the same file.
Do not store the only copy inside a vendor's portal. If the relationship ends badly, your access ends with it.
A 30-Day Workflow to Close Your BAA Gaps
Days 1–5 — Build the list. Export twelve months of accounts payable. Add every SaaS login your staff uses, including anything a clinician signed up for individually. Assign one owner: usually the privacy officer, with the practice manager providing the AP export.
Days 6–10 — Classify. Mark each vendor as business associate, not a business associate, or unclear. Document the reasoning in one sentence per vendor. That sentence is your evidence if the classification is later questioned.
Days 11–15 — Inventory what you hold. For every business associate, locate the executed agreement. Record effective date, signer names, and whether the clause set matches the nine requirements above. Anything missing a signature goes on the gap list.
Days 16–25 — Paper the gaps. Send your own agreement first. Reviewing your document beats negotiating theirs. Track sent, received, and countersigned dates.
Days 26–30 — Escalate and decide. For any vendor that refuses to sign, you have a documented decision to make: terminate, restrict PHI access, or accept and record the risk with leadership sign-off. Silence is not a decision, and OCR's public breach reporting portal is full of incidents that trace back to third parties.
Tie the finished register into your risk analysis. Vendor relationships are a documented input, and NIST's SP 800-66 Revision 2 resource guide for the HIPAA Security Rule treats third-party access as part of scoping. If your risk analysis, policies, and vendor register live in three unconnected places, automating the compliance document set keeps them consistent when someone asks for all three at once.
One Change on the Horizon
In January 2025, HHS published a proposed rule to strengthen the HIPAA Security Rule. Among the proposals: requiring business associates to verify to covered entities, on a recurring basis, that they have deployed required technical safeguards, supported by written analysis and certification. As of December 8, 2025, that rule is not final and imposes no obligation. But if it is adopted in something like its proposed form, your BAAs will need amendment language, and vendors who cannot produce technical documentation today will not produce it then either. Asking now tells you something useful about who you are working with.
Your Next Concrete Step
Pull your accounts payable export this week and count the vendors with PHI access but no countersigned agreement. If that number is above zero, generate the missing documents and send them before your next staff meeting — a guided BAA builder with PDF and DOCX export turns a stalled draft into a signed file in an afternoon. Then file each executed business associate agreement PDF in one place, log the date, and set the six-year retention reminder. That register is the evidence, and it is the first thing anyone will ask to see.