Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is the HIPAA-required contract between a covered entity (or another business associate) and a vendor that handles protected health information on its behalf, making the vendor directly liable for safeguarding that data.
- Required before any vendor touches PHI — at onboarding, not later
- Business associates are directly liable to HHS since the 2013 Omnibus Rule
- Obligations flow down to every subcontractor that handles PHI
- Covers breach notification, safeguards, and return or destruction of PHI
Who needs a BAA?
HIPAA applies to covered entities — providers, health plans, clearinghouses — and to their business associates: any organization that creates, receives, maintains, or transmits protected health information (PHI) for them. A telehealth infrastructure platform, a cloud host storing patient records, an analytics vendor touching PHI — each needs a BAA with the party it serves, and must in turn sign BAAs with its own subcontractors that touch PHI.
For a company building a care program, the practical rule is simple: before any vendor touches patient data, a BAA is in place. A vendor that hesitates to sign one, or treats it as an enterprise upsell, is telling you something about how it handles PHI.
What a BAA actually obligates
A BAA specifies permitted uses of PHI, requires safeguards under the HIPAA Security Rule, obligates breach notification to the covered entity, flows the same duties down to subcontractors, and requires return or destruction of PHI when the relationship ends. Since the 2013 Omnibus Rule, business associates are directly liable to HHS enforcement — the BAA is not just paper between the parties.
What to check before you sign a vendor’s BAA
Not all BAAs are equal. The ones worth signing specify breach-notification windows in days (not only “without unreasonable delay”), commit the vendor to flowing identical terms to subcontractors, spell out what happens to PHI at termination, and do not quietly grant the vendor rights to use patient data beyond delivering the service.
Watch the de-identification clause in particular: “we may use de-identified data” is standard, but the BAA should hold the vendor to the HIPAA de-identification standard, not a vaguer promise. And keep signed copies organized — investors and enterprise partners ask for BAAs earlier than most founders expect.
Compliance handled, so you can build
Lithos runs the clinicians, pharmacies, and 50-state rules behind your care program — one API.
Frequently asked questions
Is a startup building on a telehealth API a covered entity?
Usually the clinical entity (the medical group) is the covered entity; the platform and the brand operate as business associates or under other data arrangements. The right structure depends on the care model — get it mapped before launch.
When should the BAA be signed?
At onboarding, before any PHI flows. It should be part of standard contracting, not a later add-on.
Does HIPAA apply if we only handle names and emails?
If the data is held in connection with providing care and can identify a patient, treat it as PHI. Marketing-only data collected outside the care relationship is a separate (state-privacy-law) question.