A business associate agreement template is a HIPAA contract between a healthcare organisation and a vendor that handles its patients' health information. It limits how the vendor may use that data and sets its duties for safeguards, breach reporting and termination.
It is the contract HIPAA expects a covered entity, such as a hospital, clinic or health plan, to sign before a vendor creates, receives, stores or sends protected health information (PHI) on its behalf. The vendor becomes a business associate, and the BAA spells out what it may and may not do with the data.
Compliance and procurement teams put one in place for billing companies, cloud hosts, IT support providers, transcription services and other vendors whose work involves PHI. Vendors that serve healthcare customers often keep their own BAA template ready, because buyers ask for one before signing the main contract.
A BAA template gives you the clauses the HIPAA Privacy and Security Rules call for in one place. The US Department of Health and Human Services (HHS) publishes sample business associate agreement provisions that many organisations use as a starting point, and this template follows the same general structure.
What PHI, electronic PHI, breach and security incident mean, tied to the HIPAA rules.
The purposes the vendor may use or share PHI for, such as billing or cloud storage, and nothing more.
Administrative, physical and technical protections the vendor must keep in place.
What incidents the vendor must report, to whom and within what time.
Any partner the vendor uses with PHI must agree to the same restrictions.
When the agreement can be ended and how PHI is returned or destroyed.
Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.
Check whether the vendor will create, receive, store or send PHI for you.
Review the vendor's security controls before sharing any data.
Negotiate and sign the BAA, usually alongside or before the main contract.
Track incidents, subcontractors and security reviews while the vendor holds PHI.
At the end, confirm in writing that PHI was returned or destroyed.
The core of any BAA is six promises from the vendor: use PHI only as permitted, protect it, report breaches, bind subcontractors, support patient rights and return or destroy it at the end.
Most BAAs are attached to a main services agreement as an addendum, so keep commercial terms out of it. The clause order below follows the structure most healthcare organisations use. Do not weaken the required clauses, because a BAA missing them may not give the assurances HIPAA expects.
Terms such as PHI, electronic PHI, breach, security incident and unsecured PHI, given the meaning in the HIPAA rules.
The services for which the business associate may use or disclose PHI, plus its own management and legal duties.
Not to use or disclose PHI beyond the agreement or the law, and to apply the minimum necessary standard.
Appropriate safeguards for all PHI, and compliance with the Security Rule for electronic PHI.
Reporting of improper uses, security incidents and breaches of unsecured PHI, with timing and content.
Subcontractors that handle PHI must agree in writing to the same restrictions and conditions.
Helping the covered entity give patients access to, amendment of and an accounting of disclosures of their PHI.
Making internal practices and records available to HHS to determine compliance.
Telling the business associate about limits in its privacy notice or restrictions agreed with patients.
How long the BAA lasts, and the covered entity's right to terminate for a material breach.
Returning or destroying PHI at the end, or protecting any PHI that cannot feasibly be returned.
Regulatory references, amendment as the law changes, interpretation in favour of HIPAA compliance, and signatures.
2. Permitted Uses and Disclosures [Business Associate Name] may use or disclose Protected Health Information only as necessary to perform the services described in [the Services Agreement dated Date], or as required by law. Business Associate will limit its uses and disclosures to the minimum necessary to accomplish the intended purpose. 5. Reporting Business Associate will report to [Covered Entity Name] any use or disclosure of Protected Health Information not provided for by this Agreement, including any Breach of Unsecured Protected Health Information, without unreasonable delay and in no case later than [number] [business / calendar] days after discovery. The report will identify each individual affected, to the extent known, and include the other information Covered Entity needs to meet its own notification duties. 11. Return or Destruction On termination, Business Associate will return to Covered Entity or destroy all Protected Health Information it maintains in any form, and will retain no copies. If return or destruction is not feasible, Business Associate will extend the protections of this Agreement to that information and limit further uses to the purposes that make return or destruction infeasible.
Not every healthcare vendor is a business associate. Ask one question for each vendor: will it handle PHI to do the job for us? Record the answer and the reason in your vendor list, so the decision can be explained at audit.
| Vendor type | Handles PHI for you? | BAA usually needed? |
|---|---|---|
| Cloud hosting or storage of patient records | Yes, stores PHI even if encrypted | Yes |
| Medical billing or claims company | Yes, processes PHI | Yes |
| IT support with access to systems holding PHI | Yes, can access PHI | Yes |
| Transcription or patient messaging service | Yes, creates or sends PHI | Yes |
| Postal service or internet provider acting only as a conduit | Transmits without routine access | Usually no |
| Cleaning or building maintenance staff | Only incidental exposure | Usually no |
| Another provider treating the same patient | Disclosure for treatment | No |
General guidance only. Edge cases depend on the facts, so confirm with your privacy officer or counsel.
Scoping is easier when every vendor goes through the same review. A third-party risk management process can flag vendors that will handle health data before the contract is signed.
HIPAA sets an outer limit for a business associate's breach notice of 60 calendar days after discovery, and requires it without unreasonable delay. Many covered entities set a much shorter window in the BAA, because they need time to investigate and notify patients themselves.
| Safeguard type | What it covers | Examples to ask about |
|---|---|---|
| Administrative | Policies, people and risk management | Risk analysis, staff training, access approval, incident response plan |
| Physical | Facilities and devices | Data centre access controls, device disposal, workstation security |
| Technical | Systems and data | Encryption, unique user IDs, audit logs, automatic log-off |
Write the agreed timings into clause 5. The days below are illustrative contract terms, not legal requirements.
| Step | Who acts | Typical contract timing |
|---|---|---|
| Incident discovered | Business associate | Day 0 |
| Initial notice to covered entity | Business associate | Within [5] business days |
| Full report with affected individuals | Business associate | Within [15] business days, updated as facts emerge |
| Patient and regulator notices | Covered entity | As the HIPAA Breach Notification Rule requires |
A cloud software vendor might host data with an infrastructure provider and send support tickets through a helpdesk tool. Each of those is a subcontractor if it handles PHI. Ask your vendor for a list and confirm a BAA is in place for each one.
Ask the vendor which subcontractors will create, receive, store or send your PHI.
Each one needs a written agreement with restrictions at least as strict as yours.
Add a clause requiring the vendor to tell you before adding a subcontractor that handles PHI.
6. Subcontractors Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits Protected Health Information on behalf of Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate under this Agreement. Business Associate will give Covered Entity [30] days' written notice before engaging a new subcontractor to handle Protected Health Information.
Vendors serving healthcare often insist on their own BAA template. That is common and usually acceptable, provided it covers everything below. Tick each check and keep the list with the signed agreement.
Spendflo TPRM flags vendors that will handle sensitive data before the contract is signed.
See TPRMA health plan, healthcare clearinghouse or healthcare provider that carries out certain transactions electronically.
A person or company that handles PHI while performing a service for a covered entity.
Individually identifiable health information held or sent by a covered entity or business associate.
PHI created, stored or sent electronically, which the Security Rule specifically protects.
PHI not rendered unusable or unreadable to unauthorised people, for example by approved encryption.
Using or disclosing only the PHI needed for the purpose at hand.
No test data, demo data or support access involving PHI until the BAA is signed.
A fixed number of days is easier to enforce than without unreasonable delay alone.
Name the services agreement so the BAA's scope matches the actual services.
Get a list of subcontractors that will handle PHI and confirm their agreements.
Record each BAA's status and end date in your vendor and contract records.
A host storing encrypted PHI is generally still a business associate.
Do not let the vendor use PHI for its own product development unless counsel agrees it is allowed.
The BAA should describe data categories, never include actual patient information.
Without a return or destroy clause, PHI can sit with a former vendor indefinitely.
Use the who-needs-one table to decide whether the vendor is a business associate.
Send a security questionnaire and check the vendor's safeguards before sharing data.
Use your template or review the vendor's against the checklist, and negotiate the breach window.
Sign before any PHI is shared and store the BAA with the main contract.
Cedar Health plans to store scanned patient forms with Kestrel Data, a cloud storage vendor. Because Kestrel will hold PHI, Cedar's privacy officer requires a BAA. Kestrel offers its own template with notice "without unreasonable delay"; Cedar negotiates an illustrative 5 business days for initial notice, adds subcontractor notice and signs on 14 October 2026, before any files are uploaded.
Every part on this page, in Word, Google Docs and PDF, with the examples filled in.
Use the full template, set short breach windows and require notice of new subcontractors. Keep one standard version for all vendors.
Keep a standard BAA ready for healthcare customers, and decide in advance which changes you will accept.
Use the same clauses with the vendor as covered party, and make sure terms are at least as strict as the upstream BAA.
Best for negotiating with counsel on both sides.
Best for internal review by compliance and procurement.
Best for the review checklist and the signed copy.
Spendflo has handled 15,000+ agreements, at 30% average savings on software spend.
See your savingsA good BAA template limits how vendors use patient data, sets clear breach duties and makes sure PHI comes back at the end. The harder part is knowing which vendors need one and making sure none start work before it is signed.
Quick answers to what people ask most about the business associate agreement template.
It is a contract in which a vendor promises a healthcare organisation to protect patient health information, use it only for the agreed services and report any breach. HIPAA expects one whenever a vendor handles PHI on the organisation's behalf. You can download a free BAA template from this page.
No, only with vendors that create, receive, store or send PHI on behalf of a covered entity. Vendors with no access, or only incidental exposure, generally do not need one. The download includes a scoping table to help you decide.
It should not allow the vendor to use or disclose PHI in ways the covered entity itself could not, and it should never contain actual patient information. Commercial terms are also better kept in the main contract. Download the template for clause wording that stays within those limits.
Most business contracts follow the same order: parties, definitions, scope, payment, term and termination, confidentiality, liability, general terms and signatures. A BAA is usually attached to that main agreement as an addendum. Download the template to see the BAA clauses in order.
You can download it free from this page in Word, Google Docs or PDF. It includes the full agreement, a vendor scoping table, breach reporting terms, a subcontractor clause and a review checklist.
Contracts
Purchase orders
Vendor management
Sourcing and RFx
Budgets and business cases
Procurement
Accounts payable
Purchasing
Software buying
Supply chain
Spendflo's third-party risk management flags vendors that will handle sensitive data during intake, and its Contracts Agent keeps each BAA with the main contract and tracks renewal dates.
Enter your work email and we'll unlock every format.
Didn't start, or need another format? Pick one below.
Google Docs: upload the file to Google Drive, then open it with Google Docs.