BAA Requirements
Business Associate Agreement Requirements
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Use written arrangements that define permitted PHI uses, required safeguards, incident reporting, subcontractor obligations, and return or destruction duties for business associates.
Points of focus
- Execute a BAA before a business associate handles PHI
- Flow equivalent restrictions to subcontractors
- Define reporting, termination, and data-disposition obligations
Implementation notes
Gate PHI-capable vendors and customer deployments on executed BAAs, link each agreement to data flows and subprocessors, and operationalize its reporting deadlines in incident and offboarding workflows. Operationalize execute a baa before a business associate handles phi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain executed baa linked to the applicable service and legal entity with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a vendor signs a generic dpa but no baa before receiving phi Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample executed baa linked to the applicable service and legal entity with dates and named reviewers. Be ready to walk through how you detect and correct: a vendor signs a generic dpa but no baa before receiving phi
Evidence auditors typically request:
- Executed BAA linked to the applicable service and legal entity
- Subcontractor BAA inventory and contract review records
- Offboarding evidence for PHI return or destruction
Common gaps
- A vendor signs a generic DPA but no BAA before receiving PHI
- The BAA names a product or entity that no longer matches the operating service
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | BAA Requirements | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: BAA Requirements