ProductCustomersPlatformJournalGlossaryMigrateFor CliniciansSecurity>_  Agent viewGet Started
All terms
Glossary / Business Associate Agreement (BAA)

Business Associate Agreement (BAA)

Definition

A Business Associate Agreement (BAA) is the HIPAA-required contract between a covered entity (or another business associate) and a vendor that handles protected health information on its behalf, making the vendor directly liable for safeguarding that data.

By Lithos Staff · Updated July 2026

At a glance
  • Required before any vendor touches PHI — at onboarding, not later
  • Business associates are directly liable to HHS since the 2013 Omnibus Rule
  • Obligations flow down to every subcontractor that handles PHI
  • Covers breach notification, safeguards, and return or destruction of PHI

Who needs a BAA?

HIPAA applies to covered entities — providers, health plans, clearinghouses — and to their business associates: any organization that creates, receives, maintains, or transmits protected health information (PHI) for them. A telehealth infrastructure platform, a cloud host storing patient records, an analytics vendor touching PHI — each needs a BAA with the party it serves, and must in turn sign BAAs with its own subcontractors that touch PHI.

For a company building a care program, the practical rule is simple: before any vendor touches patient data, a BAA is in place. A vendor that hesitates to sign one, or treats it as an enterprise upsell, is telling you something about how it handles PHI.

Covered entityprovider · medical groupBAABusiness associateplatform · EHR · hostBAASubcontractorcloud · analytics
PHI may only flow across a signed BAA — and the duties flow down the chain to every subcontractor.

What a BAA actually obligates

A BAA specifies permitted uses of PHI, requires safeguards under the HIPAA Security Rule, obligates breach notification to the covered entity, flows the same duties down to subcontractors, and requires return or destruction of PHI when the relationship ends. Since the 2013 Omnibus Rule, business associates are directly liable to HHS enforcement — the BAA is not just paper between the parties.

What to check before you sign a vendor’s BAA

Not all BAAs are equal. The ones worth signing specify breach-notification windows in days (not only “without unreasonable delay”), commit the vendor to flowing identical terms to subcontractors, spell out what happens to PHI at termination, and do not quietly grant the vendor rights to use patient data beyond delivering the service.

Watch the de-identification clause in particular: “we may use de-identified data” is standard, but the BAA should hold the vendor to the HIPAA de-identification standard, not a vaguer promise. And keep signed copies organized — investors and enterprise partners ask for BAAs earlier than most founders expect.

Compliance handled, so you can build

Lithos runs the clinicians, pharmacies, and 50-state rules behind your care program — one API.

Talk to Lithos

Frequently asked questions

Is a startup building on a telehealth API a covered entity?

Usually the clinical entity (the medical group) is the covered entity; the platform and the brand operate as business associates or under other data arrangements. The right structure depends on the care model — get it mapped before launch.

When should the BAA be signed?

At onboarding, before any PHI flows. It should be part of standard contracting, not a later add-on.

Does HIPAA apply if we only handle names and emails?

If the data is held in connection with providing care and can identify a patient, treat it as PHI. Marketing-only data collected outside the care relationship is a separate (state-privacy-law) question.

Related terms