Free templateWord · Google Docs · PDF

Business Associate Agreement Template

A business associate agreement template is a HIPAA contract between a healthcare organisation and a vendor that handles its patients' health information. It limits how the vendor may use that data and sets its duties for safeguards, breach reporting and termination.

  • Twelve-clause BAA with sample wording
  • Vendor scoping table and breach timeline
  • Subcontractor terms and review checklist
Book a demo
Updated 7 Oct 20265 partsReviewed by the Spendflo procurement team
What's inside

Five parts, one BAA template

One document with five parts: the full agreement, a guide to which vendors need one, safeguards and breach reporting, subcontractor terms and a review checklist. Click any card to open that part below.
  1. 1Full agreementTwelve clauses in order, from definitions to termination, with sample wording.
  2. 2Who needs oneWhich vendors need a BAA and which usually do not, by type of service.
  3. 3Safeguards and breachesThe three types of safeguard and a breach reporting timeline.
  4. 4Subcontractor BAAHow PHI protections pass down to a vendor's own vendors.
  5. 5Review checklistTwelve checks for reviewing a BAA, whether yours or the vendor's paper.

Who it's for

  • Compliance officers
  • Privacy officers
  • In-house counsel
  • Procurement managers
  • IT security leads
  • Practice managers
Definition

What is a business associate agreement?

It is the contract HIPAA expects a covered entity, such as a hospital, clinic or health plan, to sign before a vendor creates, receives, stores or sends protected health information (PHI) on its behalf. The vendor becomes a business associate, and the BAA spells out what it may and may not do with the data.

Compliance and procurement teams put one in place for billing companies, cloud hosts, IT support providers, transcription services and other vendors whose work involves PHI. Vendors that serve healthcare customers often keep their own BAA template ready, because buyers ask for one before signing the main contract.

A BAA template gives you the clauses the HIPAA Privacy and Security Rules call for in one place. The US Department of Health and Human Services (HHS) publishes sample business associate agreement provisions that many organisations use as a starting point, and this template follows the same general structure.

Key components

Definitions

What PHI, electronic PHI, breach and security incident mean, tied to the HIPAA rules.

Permitted uses

The purposes the vendor may use or share PHI for, such as billing or cloud storage, and nothing more.

Safeguards

Administrative, physical and technical protections the vendor must keep in place.

Breach reporting

What incidents the vendor must report, to whom and within what time.

Subcontractors

Any partner the vendor uses with PHI must agree to the same restrictions.

Termination

When the agreement can be ended and how PHI is returned or destroyed.

Get the business associate agreement template free

Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.

For beginners

How a business associate agreement works

A BAA is signed before the vendor touches any PHI and stays in force for as long as the vendor holds it. It runs through five stages across the vendor relationship.
  1. 1
    Identify

    Check whether the vendor will create, receive, store or send PHI for you.

  2. 2
    Assess

    Review the vendor's security controls before sharing any data.

  3. 3
    Agree

    Negotiate and sign the BAA, usually alongside or before the main contract.

  4. 4
    Monitor

    Track incidents, subcontractors and security reviews while the vendor holds PHI.

  5. 5
    Close out

    At the end, confirm in writing that PHI was returned or destroyed.

Need something simpler?

The core of any BAA is six promises from the vendor: use PHI only as permitted, protect it, report breaches, bind subcontractors, support patient rights and return or destroy it at the end.

Part 1 · Full agreement

The business associate agreement template

The full agreement runs to twelve clauses, from definitions to general terms. Fill in the brackets, attach it to the main services contract and have counsel review before signing.

Most BAAs are attached to a main services agreement as an addendum, so keep commercial terms out of it. The clause order below follows the structure most healthcare organisations use. Do not weaken the required clauses, because a BAA missing them may not give the assurances HIPAA expects.

  1. 01Definitions

    Terms such as PHI, electronic PHI, breach, security incident and unsecured PHI, given the meaning in the HIPAA rules.

  2. 02Permitted uses and disclosures

    The services for which the business associate may use or disclose PHI, plus its own management and legal duties.

  3. 03Obligations of the business associate

    Not to use or disclose PHI beyond the agreement or the law, and to apply the minimum necessary standard.

  4. 04Safeguards

    Appropriate safeguards for all PHI, and compliance with the Security Rule for electronic PHI.

  5. 05Reporting and breach notification

    Reporting of improper uses, security incidents and breaches of unsecured PHI, with timing and content.

  6. 06Subcontractors

    Subcontractors that handle PHI must agree in writing to the same restrictions and conditions.

  7. 07Individual rights

    Helping the covered entity give patients access to, amendment of and an accounting of disclosures of their PHI.

  8. 08Books and records

    Making internal practices and records available to HHS to determine compliance.

  9. 09Obligations of the covered entity

    Telling the business associate about limits in its privacy notice or restrictions agreed with patients.

  10. 10Term and termination

    How long the BAA lasts, and the covered entity's right to terminate for a material breach.

  11. 11Return or destruction of PHI

    Returning or destroying PHI at the end, or protecting any PHI that cannot feasibly be returned.

  12. 12General terms

    Regulatory references, amendment as the law changes, interpretation in favour of HIPAA compliance, and signatures.

Sample clauses: permitted uses, reporting and return of PHI
2. Permitted Uses and Disclosures
[Business Associate Name] may use or disclose Protected Health Information only as necessary to perform the services described in [the Services Agreement dated Date], or as required by law. Business Associate will limit its uses and disclosures to the minimum necessary to accomplish the intended purpose.

5. Reporting
Business Associate will report to [Covered Entity Name] any use or disclosure of Protected Health Information not provided for by this Agreement, including any Breach of Unsecured Protected Health Information, without unreasonable delay and in no case later than [number] [business / calendar] days after discovery. The report will identify each individual affected, to the extent known, and include the other information Covered Entity needs to meet its own notification duties.

11. Return or Destruction
On termination, Business Associate will return to Covered Entity or destroy all Protected Health Information it maintains in any form, and will retain no copies. If return or destruction is not feasible, Business Associate will extend the protections of this Agreement to that information and limit further uses to the purposes that make return or destruction infeasible.
This template is a starting point, not legal advice. Have your counsel review it before you sign. HIPAA requirements change, so check the agreement against the current rules and the sample provisions published by HHS.
Part 2 · Who needs one

Which vendors need a BAA

A vendor needs a BAA when it creates, receives, stores or sends PHI on behalf of a covered entity. Vendors that never handle PHI, or only see it by chance, usually do not.

Not every healthcare vendor is a business associate. Ask one question for each vendor: will it handle PHI to do the job for us? Record the answer and the reason in your vendor list, so the decision can be explained at audit.

Vendor typeHandles PHI for you?BAA usually needed?
Cloud hosting or storage of patient recordsYes, stores PHI even if encryptedYes
Medical billing or claims companyYes, processes PHIYes
IT support with access to systems holding PHIYes, can access PHIYes
Transcription or patient messaging serviceYes, creates or sends PHIYes
Postal service or internet provider acting only as a conduitTransmits without routine accessUsually no
Cleaning or building maintenance staffOnly incidental exposureUsually no
Another provider treating the same patientDisclosure for treatmentNo

General guidance only. Edge cases depend on the facts, so confirm with your privacy officer or counsel.

Scoping is easier when every vendor goes through the same review. A third-party risk management process can flag vendors that will handle health data before the contract is signed.

Part 3 · Safeguards and breaches

Safeguards and breach reporting

The vendor must protect PHI with administrative, physical and technical safeguards. If something goes wrong, it must report to the covered entity quickly enough for the covered entity to meet its own notification duties.

HIPAA sets an outer limit for a business associate's breach notice of 60 calendar days after discovery, and requires it without unreasonable delay. Many covered entities set a much shorter window in the BAA, because they need time to investigate and notify patients themselves.

Safeguard typeWhat it coversExamples to ask about
AdministrativePolicies, people and risk managementRisk analysis, staff training, access approval, incident response plan
PhysicalFacilities and devicesData centre access controls, device disposal, workstation security
TechnicalSystems and dataEncryption, unique user IDs, audit logs, automatic log-off

Breach reporting timeline

Write the agreed timings into clause 5. The days below are illustrative contract terms, not legal requirements.

StepWho actsTypical contract timing
Incident discoveredBusiness associateDay 0
Initial notice to covered entityBusiness associateWithin [5] business days
Full report with affected individualsBusiness associateWithin [15] business days, updated as facts emerge
Patient and regulator noticesCovered entityAs the HIPAA Breach Notification Rule requires
Part 4 · Subcontractor BAA

Subcontractor business associate agreement

When a business associate uses another company to handle PHI, that company becomes a subcontractor business associate. The vendor must sign a BAA with it that carries the same restrictions down the chain.

A cloud software vendor might host data with an infrastructure provider and send support tickets through a helpdesk tool. Each of those is a subcontractor if it handles PHI. Ask your vendor for a list and confirm a BAA is in place for each one.

  1. 1
    List subcontractors

    Ask the vendor which subcontractors will create, receive, store or send your PHI.

  2. 2
    Confirm agreements

    Each one needs a written agreement with restrictions at least as strict as yours.

  3. 3
    Require notice of changes

    Add a clause requiring the vendor to tell you before adding a subcontractor that handles PHI.

Sample clause: subcontractors
6. Subcontractors
Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits Protected Health Information on behalf of Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate under this Agreement. Business Associate will give Covered Entity [30] days' written notice before engaging a new subcontractor to handle Protected Health Information.
Part 5 · Review checklist

BAA review checklist

Use these twelve checks on any BAA, whether you drafted it or the vendor sent its own. They cover the required clauses and the points most often negotiated.

Vendors serving healthcare often insist on their own BAA template. That is common and usually acceptable, provided it covers everything below. Tick each check and keep the list with the signed agreement.

0 of 12 done

Required content

Negotiated points

Admin

Spendflo TPRM flags vendors that will handle sensitive data before the contract is signed.

See TPRM
Glossary

HIPAA terms used in a BAA

A BAA borrows its key terms from the HIPAA rules, so the definitions must match them. These six appear in almost every agreement.
Covered entity

A health plan, healthcare clearinghouse or healthcare provider that carries out certain transactions electronically.

Business associate

A person or company that handles PHI while performing a service for a covered entity.

Protected health information (PHI)

Individually identifiable health information held or sent by a covered entity or business associate.

Electronic PHI

PHI created, stored or sent electronically, which the Security Rule specifically protects.

Unsecured PHI

PHI not rendered unusable or unreadable to unauthorised people, for example by approved encryption.

Minimum necessary

Using or disclosing only the PHI needed for the purpose at hand.

Best practices

Do this, avoid that

Sign the BAA before any PHI moves, keep it aligned with the main contract and review it when the law or the service changes. Most BAA gaps come from vendors that started work before the paperwork was done.

Do

  • ✓
    Sign before data moves

    No test data, demo data or support access involving PHI until the BAA is signed.

  • ✓
    Set a breach window in days

    A fixed number of days is easier to enforce than without unreasonable delay alone.

  • ✓
    Link it to the main contract

    Name the services agreement so the BAA's scope matches the actual services.

  • ✓
    Ask about subcontractors

    Get a list of subcontractors that will handle PHI and confirm their agreements.

  • ✓
    Track BAAs like contracts

    Record each BAA's status and end date in your vendor and contract records.

Avoid

  • ×
    Assuming encryption removes the need

    A host storing encrypted PHI is generally still a business associate.

  • ×
    Overly broad permitted uses

    Do not let the vendor use PHI for its own product development unless counsel agrees it is allowed.

  • ×
    Putting PHI in the agreement

    The BAA should describe data categories, never include actual patient information.

  • ×
    Forgetting termination steps

    Without a return or destroy clause, PHI can sit with a former vendor indefinitely.

How to use it

Put a BAA in place in a week

Confirm the vendor will handle PHI, review its security, then agree the BAA alongside the main contract. Store both together and diary the review date.
  1. Step 1

    Scope the vendor

    Use the who-needs-one table to decide whether the vendor is a business associate.

  2. Step 2

    Review security

    Send a security questionnaire and check the vendor's safeguards before sharing data.

  3. Step 3

    Agree the BAA

    Use your template or review the vendor's against the checklist, and negotiate the breach window.

  4. Step 4

    Sign and file

    Sign before any PHI is shared and store the BAA with the main contract.

Example

One BAA, from scoping to signature

A cloud storage vendor was a business associate even though the data was encrypted. Agreeing a short breach window was the main negotiation point.

Cedar Health plans to store scanned patient forms with Kestrel Data, a cloud storage vendor. Because Kestrel will hold PHI, Cedar's privacy officer requires a BAA. Kestrel offers its own template with notice "without unreasonable delay"; Cedar negotiates an illustrative 5 business days for initial notice, adds subcontractor notice and signs on 14 October 2026, before any files are uploaded.

Ready to use it? Download the business associate agreement template

Every part on this page, in Word, Google Docs and PDF, with the examples filled in.

Variants

Fit it to your side of the deal

Covered entities usually want their own BAA with tight reporting terms. Vendors and subcontractors adapt the same structure, depending on where they sit in the chain.
Hospitals, clinics, health plans

Covered entity paper

Use the full template, set short breach windows and require notice of new subcontractors. Keep one standard version for all vendors.

Software and service vendors

Business associate paper

Keep a standard BAA ready for healthcare customers, and decide in advance which changes you will accept.

Vendors using vendors

Subcontractor BAA

Use the same clauses with the vendor as covered party, and make sure terms are at least as strict as the upstream BAA.

Spendflo has handled 15,000+ agreements, at 30% average savings on software spend.

See your savings
Bottom line

A BAA protects data only if it is in place first

A good BAA template limits how vendors use patient data, sets clear breach duties and makes sure PHI comes back at the end. The harder part is knowing which vendors need one and making sure none start work before it is signed.

FAQ

Frequently asked questions

Quick answers to what people ask most about the business associate agreement template.

What is a business associate agreement in simple terms?

It is a contract in which a vendor promises a healthcare organisation to protect patient health information, use it only for the agreed services and report any breach. HIPAA expects one whenever a vendor handles PHI on the organisation's behalf. You can download a free BAA template from this page.

Is a baa needed with every vendor?

No, only with vendors that create, receive, store or send PHI on behalf of a covered entity. Vendors with no access, or only incidental exposure, generally do not need one. The download includes a scoping table to help you decide.

Which detail should not be in a business associate agreement?

It should not allow the vendor to use or disclose PHI in ways the covered entity itself could not, and it should never contain actual patient information. Commercial terms are also better kept in the main contract. Download the template for clause wording that stays within those limits.

What is the standard format for a B2B contract agreement?

Most business contracts follow the same order: parties, definitions, scope, payment, term and termination, confidentiality, liability, general terms and signatures. A BAA is usually attached to that main agreement as an addendum. Download the template to see the BAA clauses in order.

Where can I download a free business associate agreement template?

You can download it free from this page in Word, Google Docs or PDF. It includes the full agreement, a vendor scoping table, breach reporting terms, a subcontractor clause and a review checklist.

Template library

Browse all procurement templates

See all 60 templates →

Know which vendors touch sensitive data.

Spendflo's third-party risk management flags vendors that will handle sensitive data during intake, and its Contracts Agent keeps each BAA with the main contract and tracks renewal dates.

Book a demo
  • 12-clause BAA
  • 7 vendor types scoped
  • 12-point review checklist
  • Subcontractor clause included