Skip to content
compliancebase
HIPAATopics — Business Associate Agreement Requirements

BAA Requirements

Business Associate Agreement Requirements

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Use written arrangements that define permitted PHI uses, required safeguards, incident reporting, subcontractor obligations, and return or destruction duties for business associates.

Points of focus

  • Execute a BAA before a business associate handles PHI
  • Flow equivalent restrictions to subcontractors
  • Define reporting, termination, and data-disposition obligations

Implementation notes

Gate PHI-capable vendors and customer deployments on executed BAAs, link each agreement to data flows and subprocessors, and operationalize its reporting deadlines in incident and offboarding workflows. Operationalize execute a baa before a business associate handles phi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain executed baa linked to the applicable service and legal entity with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a vendor signs a generic dpa but no baa before receiving phi Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample executed baa linked to the applicable service and legal entity with dates and named reviewers. Be ready to walk through how you detect and correct: a vendor signs a generic dpa but no baa before receiving phi

Evidence auditors typically request:

  • Executed BAA linked to the applicable service and legal entity
  • Subcontractor BAA inventory and contract review records
  • Offboarding evidence for PHI return or destruction

Common gaps

  • A vendor signs a generic DPA but no BAA before receiving PHI
  • The BAA names a product or entity that no longer matches the operating service

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAABAA RequirementsThis control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

Business Associate Agreement Requirements applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — execute a baa before a business associate handles phi — with evidence stored where auditors and customers can sample it.

Lead with executed baa linked to the applicable service and legal entity and pair it with subcontractor baa inventory and contract review records. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a vendor signs a generic dpa but no baa before receiving phi Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above