Business Associate Agreements Under HIPAA: What It Means for Your Organization
If a vendor creates, receives, keeps or sends protected health information on behalf of a HIPAA covered entity, HIPAA requires a written business associate agreement (BAA) before that work begins. The same rule applies when a business associate passes the information to its own subcontractor. The agreement must include specific terms set out in 45 CFR 164.504(e) and, for electronic information, 45 CFR 164.314(a). A covered entity does not need its own agreement with its business associate’s subcontractors; the business associate is responsible for those. HHS publishes sample provisions you can adapt, but the terms have to fit your actual arrangement. ALCON DTS can help you keep track of which vendors touch patient information and which agreements are in place.
This page answers:
At a glance
- Requirement: HIPAA Privacy Rule, 45 CFR 164.502(e) and 164.504(e); HIPAA Security Rule, 45 CFR 164.308(b) and 164.314(a); and Breach Notification Rule, 45 CFR 164.410
- Who it applies to: HIPAA covered entities (health plans, health care clearinghouses and most health care providers) and their business associates, including business associates that use subcontractors
- What it requires: Satisfactory assurances, documented in a written contract or other written arrangement, that the business associate will appropriately safeguard protected health information (164.502(e)(2), 164.308(b)(3))
- Breach reporting: The agreement must require the business associate to report breaches of unsecured protected health information as required by 164.410, which sets an outer limit of 60 calendar days after discovery
- Sample language: HHS Sample Business Associate Agreement Provisions (published January 25, 2013). Using them is optional.
- Enforced by: the HHS Office for Civil Rights (OCR)
- Official text: 45 CFR 164.504 on eCFR
- Last reviewed: September 30, 2026
What is a business associate agreement?
HIPAA lets a covered entity share protected health information with a business associate, and lets the business associate create, receive, maintain or transmit it on the covered entity’s behalf, only after the covered entity obtains “satisfactory assurance that the business associate will appropriately safeguard the information” (45 CFR 164.502(e)(1)(i)). Those assurances “must be documented through a written contract or other written agreement or arrangement with the business associate that meets the applicable requirements of ยง 164.504(e)” (164.502(e)(2)). That written contract is the business associate agreement.
HHS describes its purpose this way: the HIPAA Rules generally require these contracts “to ensure that the business associates will appropriately safeguard protected health information,” and the contract “serves to clarify and limit, as appropriate, the permissible uses and disclosures of protected health information by the business associate.”
A business associate is, in general, a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information for a function or activity regulated by HIPAA on your behalf, or that provides services such as legal, accounting, consulting, management, administrative or financial services that involve disclosure of protected health information (45 CFR 160.103). A subcontractor that creates, receives, maintains or transmits protected health information on behalf of a business associate is also a business associate (160.103).
What does a business associate agreement cover, and what doesn’t it?
It covers: how the business associate may use and disclose protected health information, the safeguards it must use, what it must report to you, how it supports patients’ rights to their records, what flows down to its subcontractors, and what happens to the information when the contract ends (164.504(e)(2)).
It is not:
- A certification. Signing a business associate agreement does not make either party “HIPAA certified” or compliant. HHS does not issue a HIPAA certification. Asked which cloud providers offer HIPAA-compliant services, OCR answers that it “does not endorse, certify, or recommend specific technology or products.”
- A substitute for doing the work. A business associate is directly liable under the HIPAA Rules for uses and disclosures not allowed by its contract or required by law, and for failing to safeguard electronic protected health information under the Security Rule (HHS Sample Business Associate Agreement Provisions).
- Required for every vendor. A person whose work does not involve protected health information, such as a janitorial service or electrician, does not need one if any access would be only incidental and reasonable safeguards are in place (HHS Business Associates guidance).
- A complete contract if it is built only from HHS’s sample language. HHS notes that its sample provisions “alone may not be sufficient to result in a binding contract under State law,” that “Reliance on this sample may not be sufficient for compliance with State law,” and that it “does not replace consultation with a lawyer or negotiations between the parties to the contract.”
Does the business associate agreement requirement apply to you?
The requirement applies in two directions:
- Covered entities. Health plans, health care clearinghouses and most health care providers need an agreement with each business associate (164.502(e)(1)(i), 164.308(b)(1)).
- Business associates. A business associate needs an agreement with each subcontractor that creates, receives, maintains or transmits protected health information on its behalf (164.502(e)(1)(ii), 164.308(b)(2)). HHS says a business associate must have that agreement in place “before disclosing PHI to the subcontractor.”
HHS lists common examples of business associates, including billing and claims administrators, accountants and attorneys whose work involves protected health information, cloud service providers that store or process electronic protected health information, and IT contractors or managed services providers whose support work requires them to create, receive, maintain or transmit it. HHS also says a cloud service provider that stores only encrypted information and has no key is still a business associate.
Quick check: does this apply to you?
- You are a HIPAA covered entity (a health plan, a health care clearinghouse, or a health care provider that conducts standard transactions such as insurance billing electronically), or you work on behalf of one.
- An outside person or company creates, receives, keeps or sends patient information for you, including your IT support, cloud storage, email, billing, transcription or backup providers.
If both are true, the business associate agreement requirement very likely applies to you. If you are unsure whether a vendor is a business associate, confirm with your attorney.
When an agreement is not needed. The business associate definition excludes some relationships, such as a covered entity’s disclosures to a health care provider for the patient’s treatment (160.103). HHS also explains that a “conduit” that only transmits information, like the postal service or certain couriers and their electronic equivalents, is not a business associate. That exception is limited to transmission services, including temporary storage incident to transmission. An entity that stores information, or accesses it on a regular or frequent basis to perform a service, is not a conduit.
What do you need to have in place?
The table below lists the terms a business associate agreement must contain and where each comes from in the rules and the HHS sample provisions.
| Required element | What the agreement must say | Rule | HHS sample provision |
|---|---|---|---|
| Permitted uses and disclosures | Set the uses and disclosures the business associate may make. The contract may not allow uses or disclosures that would violate the Privacy Rule if done by the covered entity, except for the business associate’s own management and administration and data aggregation where allowed | 164.504(e)(2)(i) | Permitted Uses and Disclosures by Business Associate |
| No other use or disclosure | The business associate will not use or further disclose the information other than as the contract permits or requires, or as required by law | 164.504(e)(2)(ii)(A) | Obligations (a) |
| Safeguards | Use appropriate safeguards and comply, where applicable, with the Security Rule for electronic protected health information | 164.504(e)(2)(ii)(B); 164.314(a)(2)(i)(A) | Obligations (b) |
| Reporting | Report any use or disclosure not provided for by the contract, including breaches of unsecured protected health information under 164.410, and any security incident it becomes aware of | 164.504(e)(2)(ii)(C); 164.314(a)(2)(i)(C) | Obligations (c) |
| Subcontractors | Make sure subcontractors that handle the information agree to the same restrictions and conditions | 164.504(e)(2)(ii)(D); 164.314(a)(2)(i)(B) | Obligations (d) |
| Patient access | Make protected health information available as required by 164.524 | 164.504(e)(2)(ii)(E) | Obligations (e) |
| Amendments | Make information available for amendment and incorporate amendments as required by 164.526 | 164.504(e)(2)(ii)(F) | Obligations (f) |
| Accounting of disclosures | Make available the information needed for an accounting of disclosures under 164.528 | 164.504(e)(2)(ii)(G) | Obligations (g) |
| Covered entity’s obligations | Where the business associate carries out a covered entity’s Privacy Rule obligation, comply with the requirements that apply to that obligation | 164.504(e)(2)(ii)(H) | Obligations (h) |
| Books and records | Make internal practices, books and records available to the HHS Secretary for compliance review | 164.504(e)(2)(ii)(I) | Obligations (i) |
| Return or destruction | At termination, return or destroy the information if feasible and keep no copies, or if not feasible, extend the contract’s protections and limit further uses | 164.504(e)(2)(ii)(J) | Term and Termination (c) |
| Termination | Allow the covered entity to terminate the contract if the business associate violates a material term | 164.504(e)(2)(iii) | Term and Termination (b) |
How fast must a business associate report a breach?
Under 164.410(b), and subject to the law-enforcement delay in 164.412, a business associate must notify the covered entity of a breach of unsecured protected health information “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.” A breach is treated as discovered on the first day it is known to the business associate, or would have been known with reasonable diligence (164.410(a)(2)). The notice must identify, to the extent possible, each affected individual, and the business associate must provide any other available information the covered entity must include in its notice to individuals, at the time of notice or promptly thereafter as it becomes available (164.410(c)).
The HHS sample provisions note that the parties may add more specific breach terms, “such as a stricter timeframe for the business associate to report a potential breach to the covered entity and/or whether the business associate will handle breach notifications to individuals, the HHS Office for Civil Rights (OCR), and potentially the media.” HHS cloud computing guidance adds that the Security Rule does not set the level of detail, frequency or format of security incident reports, so the parties can work those out in the agreement, and that an agreement may set more timely reporting than the Breach Notification Rule requires but may not override it.
What if a business associate is not keeping its promises?
If a covered entity knows of a pattern of activity or practice by a business associate that is a material breach or violation of the agreement, it must take reasonable steps to cure the breach or end the violation and, if those steps fail, terminate the contract if feasible (164.504(e)(1)(ii)). A business associate has the same duty toward its subcontractors (164.504(e)(1)(iii)).
Are there alternatives to a standard contract?
Yes, in limited cases. When both parties are governmental entities, a memorandum of understanding or other law that accomplishes the same objectives can meet the requirement (164.504(e)(3)(i)). A covered entity that discloses only a limited data set for health care operations can rely on a data use agreement that meets 164.514(e)(4) and 164.314(a)(1) (164.504(e)(3)(iv)). If a business associate is required by law to perform the function, the covered entity may disclose what is needed without a contract, provided it tries in good faith to obtain the assurances and documents why it could not (164.504(e)(3)(ii)). Your attorney can tell you whether one of these fits.
Should you use the HHS sample provisions?
They are a helpful starting point. HHS says “This is only sample language and use of these sample provisions is not required for compliance with the HIPAA Rules.” The provisions can be changed to reflect your business arrangement, placed in a service agreement or kept as a separate agreement. HHS also cautions that they “do not include many formalities and substantive provisions that may be required or typically included in a valid contract.” Have your attorney review the final agreement.
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. Your attorney drafts or reviews and negotiates your agreements, including any agreement with ALCON DTS, and you decide which vendors you work with. ALCON DTS can help you find the vendors that touch patient information, keep your agreements organized, and run the safeguards the agreements promise on the systems we manage.
| Business associate agreement need | What ALCON DTS provides |
|---|---|
| An agreement with your IT provider | A business associate agreement with ALCON DTS wherever our services require one |
| Knowing which vendors touch patient information | A review of vendor access, email, devices, file storage and backups, so you can see where patient information goes |
| Keeping agreements organized | An organized evidence file with your business associate agreements, risk analysis, training records and written procedures |
| Written procedures | Written procedures that include how business associate agreements are kept where HIPAA applies |
| Safeguards the agreement promises | Identity and access with multifactor authentication and tight administrator rights; email authentication and mailbox controls; devices kept updated, protected and encrypted; tested backup and recovery |
| Vendor and guest access | Guest and vendor access kept under control, with joiner, mover and leaver changes handled promptly |
| Spotting and reporting incidents | Monitoring that routes alerts to a named owner who can act. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control. |
Your EHR, billing and hospital platforms stay with the vendors who own them, and their agreements stay between you and them. The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap. ALCON DTS does not provide legal advice or draft your contracts, and we do not claim a HIPAA certification.
Want to know which of your vendors need a business associate agreement? We will look at where patient information goes today and which agreements you already have on file.
How do business associate agreements fit with other rules?
- HIPAA Security Risk Analysis (45 CFR 164.308(a)(1)(ii)(A)). Covered entities and business associates must each complete a risk analysis. HHS cloud guidance notes that you should understand a provider’s environment so you can conduct your own risk analysis and enter into appropriate agreements. Your vendor list and your risk analysis should match.
- HIPAA Breach Notification Rule (45 CFR 164.400 to 164.414). The covered entity notifies individuals, HHS and, for larger breaches, the media. The business associate’s job is to notify the covered entity under 164.410, unless the agreement assigns more to it.
- Texas breach notification law (Bus. and Com. Code Sec. 521.053). Health information that identifies a person is sensitive personal information in Texas (Sec. 521.002(a)(2)(B)). A person that maintains that data for someone else must notify the owner “immediately after discovering the breach” (Sec. 521.053(c)), and the owner has its own notice duties, including the Texas Attorney General within 30 days when at least 250 Texas residents are involved (Sec. 521.053(i)). Talk with your attorney about how the Texas timing fits with the terms in your agreements.
- Texas medical records privacy law (Texas Health and Safety Code Ch. 181). Texas defines “covered entity” more broadly than HIPAA, including anyone who comes into possession of protected health information (Sec. 181.001). Chapter 181 can reach organizations that HIPAA treats only as business associates, or not at all. Talk with your attorney about how Chapter 181 applies.
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). For Texas business entities with fewer than 250 employees that own or license computerized data that includes sensitive personal information (Sec. 542.002), a qualifying cybersecurity program can support a defense against exemplary damages after a breach. HIPAA is one of the laws that program must also conform to if you are subject to it (Sec. 542.004(b)(2)(A)). See Texas SB 2610 Cybersecurity Safe Harbor.
- Proposed Security Rule changes. On January 6, 2025, HHS published a proposed rule to strengthen the Security Rule (90 FR 898). As of September 30, 2026, no final rule has been published in the Federal Register, so the current business associate requirements described on this page remain the rules you follow.
Frequently asked questions
Is a business associate agreement required by HIPAA?
Does your IT provider need to sign a business associate agreement?
Does a cloud provider that cannot see your data still need one?
Do subcontractors need business associate agreements too?
How quickly must a business associate report a breach?
Do you have to use the HHS sample agreement?
What happens to patient information when the contract ends?
Does signing a business associate agreement make a vendor HIPAA compliant?
Sources
- 45 CFR 160.103, Definitions, including business associate (eCFR)
- 45 CFR 164.502, Uses and disclosures of protected health information: General rules, including (e) disclosures to business associates (eCFR)
- 45 CFR 164.504, Uses and disclosures: Organizational requirements, including (e) business associate contracts (eCFR)
- 45 CFR 164.308, Administrative safeguards, including (b) business associate contracts and other arrangements (eCFR)
- 45 CFR 164.314, Organizational requirements, including (a) business associate contracts or other arrangements (eCFR)
- 45 CFR 164.410, Notification by a business associate (eCFR)
- Sample Business Associate Agreement Provisions (published January 25, 2013) (HHS Office for Civil Rights)
- Business Associates (HHS Office for Civil Rights)
- Guidance on HIPAA and Cloud Computing (HHS Office for Civil Rights)
- HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, proposed rule, 90 FR 898 (Federal Register)
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information (Texas Constitution and Statutes)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- Texas Health and Safety Code, Chapter 181, Medical Records Privacy (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about HIPAA business associate agreements and related Texas law, not legal advice for your situation.
Talk with ALCON DTS about your business associate agreements
Not sure which vendors touch your patient information, or whether every agreement is on file? We will walk through where patient information goes, show you what you have and give you a clear plan for the rest.
Email: info@alcondts.com ยท Phone: 512-892-6900

