Free BAA template generator
Fill in the parties and get a complete plain-language business associate agreement template with every provision 45 CFR 164.504(e) requires — free, no signup, and nothing you type leaves your browser. It is a starting draft for counsel review, not a finished contract.
Last reviewed .
Your template
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement ("Agreement") is entered into as of [EFFECTIVE DATE] ("Effective Date") between:
Covered Entity: [COUNTERPARTY LEGAL NAME]
Business Associate: [YOUR ORGANIZATION'S LEGAL NAME]
(each a "Party" and together the "Parties").
RECITALS
Covered Entity wishes to engage Business Associate to perform services that involve the creation, receipt, maintenance or transmission of Protected Health Information ("PHI"), and the Parties intend to comply with the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164 (the "HIPAA Rules"), including the business associate contract requirements at 45 CFR 164.504(e).
1. DEFINITIONS
Terms used but not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules, including "Protected Health Information," "Electronic Protected Health Information," "Breach," "Unsecured Protected Health Information," "Security Incident," "Subcontractor," "Covered Entity," "Business Associate," and "Secretary" (45 CFR 160.103, 164.304, 164.402). "PHI" in this Agreement means Protected Health Information that Business Associate creates, receives, maintains or transmits for or on behalf of Covered Entity.
2. PERMITTED USES AND DISCLOSURES (45 CFR 164.504(e)(2)(i))
2.1 Services. Business Associate may use and disclose PHI only as necessary to perform the services described in the underlying services agreement between the Parties dated [DATE OF SERVICES AGREEMENT], and as permitted or required by this Agreement or required by law.
2.2 Management and administration. Business Associate may use PHI for its own proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes if the disclosure is required by law, or if Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as required by law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instance of which it is aware in which confidentiality has been breached.
2.3 Data aggregation. [INCLUDE OR DELETE: Business Associate may use PHI to provide data aggregation services relating to the health care operations of Covered Entity as permitted by 45 CFR 164.504(e)(2)(i)(B).]
2.4 Limits. Business Associate shall not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, and shall make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of each use, disclosure or request.
3. OBLIGATIONS OF BUSINESS ASSOCIATE (45 CFR 164.504(e)(2)(ii))
3.1 Limited use and disclosure. Business Associate shall not use or further disclose PHI other than as permitted or required by this Agreement or as required by law (164.504(e)(2)(ii)(A)).
3.2 Safeguards. Business Associate shall use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement, and shall comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to Electronic Protected Health Information (164.504(e)(2)(ii)(B), 164.314(a)(2)(i)).
3.3 Reporting. Business Associate shall report to Covered Entity: (a) any use or disclosure of PHI not provided for by this Agreement of which it becomes aware; (b) any Security Incident of which it becomes aware; and (c) any Breach of Unsecured PHI, without unreasonable delay and in no case later than [NUMBER — the regulatory outer limit is 60] calendar days after discovery, in accordance with 45 CFR 164.410, including to the extent known the identity of each individual whose PHI was involved and the other information Covered Entity needs for its own notification obligations (164.504(e)(2)(ii)(C)).
3.4 Subcontractors. Business Associate shall ensure, in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement, including compliance with the Security Rule for electronic PHI (164.504(e)(2)(ii)(D)).
3.5 Access by individuals. Business Associate shall make PHI in a Designated Record Set available to Covered Entity (or, as directed by Covered Entity, to the individual) as necessary to satisfy obligations under 45 CFR 164.524, within [NUMBER] business days of a request (164.504(e)(2)(ii)(E)).
3.6 Amendment. Business Associate shall make PHI in a Designated Record Set available for amendment and incorporate any amendments as necessary to satisfy obligations under 45 CFR 164.526 (164.504(e)(2)(ii)(F)).
3.7 Accounting of disclosures. Business Associate shall document disclosures of PHI and make available the information required for an accounting of disclosures as necessary to satisfy obligations under 45 CFR 164.528 (164.504(e)(2)(ii)(G)).
3.8 Delegated obligations. To the extent Business Associate is to carry out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, Business Associate shall comply with the requirements of Subpart E that apply to the performance of that obligation (164.504(e)(2)(ii)(H)).
3.9 Books and records. Business Associate shall make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules (164.504(e)(2)(ii)(I)).
3.10 Return or destruction. At termination of this Agreement, Business Associate shall, if feasible, return or destroy all PHI that it still maintains in any form and retain no copies. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to that PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as the PHI is maintained (164.504(e)(2)(ii)(J)).
4. OBLIGATIONS OF COVERED ENTITY
4.1 Covered Entity shall notify Business Associate of any limitation in its notice of privacy practices, any change in or revocation of an individual's permission to use or disclose PHI, and any restriction on use or disclosure that Covered Entity has agreed to or must abide by, in each case to the extent the change may affect Business Associate's permitted uses or disclosures.
4.2 Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity.
5. TERM AND TERMINATION
5.1 Term. This Agreement takes effect on the Effective Date and continues until the underlying services agreement terminates and all PHI is returned or destroyed, or the protections of Section 3.10 are applied.
5.2 Termination for cause. As required by 45 CFR 164.504(e)(2)(iii), Covered Entity may terminate this Agreement and the underlying services agreement if Business Associate has violated a material term of this Agreement and has not cured the violation within [NUMBER, e.g. 30] days of written notice, or immediately if cure is not possible.
5.3 Survival. The obligations of Business Associate under Section 3.10 survive termination.
6. MISCELLANEOUS
6.1 Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules. A reference to a section of the HIPAA Rules means the section as in effect or as amended.
6.2 Amendment. The Parties agree to amend this Agreement as necessary for compliance with changes to the HIPAA Rules. No other amendment is effective unless in writing and signed by both Parties.
6.3 No third-party beneficiaries. Nothing in this Agreement confers any right or remedy on any person other than the Parties.
6.4 Governing law. This Agreement is governed by the laws of the State of [STATE], except where preempted by federal law.
SIGNATURES
Covered Entity: [COUNTERPARTY LEGAL NAME]
Signature: ______________________________
Name: ______________________________
Title: ______________________________
Date: ______________________________
Business Associate: [YOUR ORGANIZATION'S LEGAL NAME]
Signature: ______________________________
Name: ______________________________
Title: ______________________________
Date: ______________________________
---
Starting template generated at hipaacompliancesoftware.org/tools/baa-template.
Bracketed text must be completed before use. Have an attorney licensed in your
state review this document before either party signs it. This template is
general information, not legal advice.Bracketed text marks decisions the template cannot make for you. Complete every bracket, then have an attorney licensed in your state review the document before either party signs. A template is a starting point, not a finished contract.
What the regulation actually requires a BAA to say
The required contents of a business associate contract are set out at 45 CFR 164.504(e)(2). The template above contains a section for each. When a client sends you their own agreement instead, this list is also your checklist for reading it — anything beyond these provisions is a negotiated business term, not a regulatory requirement.
- 164.504(e)(2)(i)Establish the permitted and required uses and disclosures — what the business associate may actually do with the information, tied to the services being performed.
- 164.504(e)(2)(ii)(A)No use or disclosure beyond what the contract permits or the law requires.
- 164.504(e)(2)(ii)(B)Appropriate safeguards, including compliance with the Security Rule for electronic PHI.
- 164.504(e)(2)(ii)(C)Report impermissible uses and disclosures, security incidents, and breaches of unsecured PHI under 164.410.
- 164.504(e)(2)(ii)(D)Bind subcontractors that touch the information to the same restrictions, in writing.
- 164.504(e)(2)(ii)(E)–(G)Support individuals' rights: access under 164.524, amendment under 164.526 and an accounting of disclosures under 164.528.
- 164.504(e)(2)(ii)(H)Where the business associate carries out a covered entity's Privacy Rule obligation, comply with the rules that would apply to the covered entity.
- 164.504(e)(2)(ii)(I)Make internal practices, books and records available to the Secretary of HHS.
- 164.504(e)(2)(ii)(J)Return or destroy all PHI at termination where feasible; extend the contract's protections where it is not.
- 164.504(e)(2)(iii)Authorize the covered entity to terminate the contract if the business associate violates a material term.
One level down, the same requirements apply between a business associate and its subcontractors under 45 CFR 164.504(e)(5) — the generator’s subcontractor option adjusts the parties and references for that arrangement. The Security Rule’s organizational requirements at 45 CFR 164.314(a) overlap this list for electronic PHI and are covered by the same provisions.
Signing the agreement is the start, not the finish
A signed BAA obligates you to the things it recites: safeguards, a risk analysis behind them, trained staff, agreements with your own vendors, and breach reporting on a deadline. When a client’s security questionnaire arrives, it asks for evidence of exactly those commitments — the agreement itself is only the first attachment.
Track every BAA you sign — and the ones your vendors owe you.
The vendor register records who touches patient data, what is signed, and when it expires, and chases renewals before they lapse. 14 days free, no credit card.
Common questions
- What must a business associate agreement contain?
- 45 CFR 164.504(e)(2) requires the contract to establish the permitted uses and disclosures of protected health information, and to obligate the business associate to: use it only as the contract or law allows; apply safeguards, including Security Rule compliance for electronic PHI; report impermissible uses, security incidents and breaches; bind its own subcontractors to the same restrictions; support individuals' rights of access, amendment and accounting; make its records available to HHS; and return or destroy the information at termination. It must also authorize termination if the business associate materially breaches the contract.
- Who needs to sign a BAA?
- A covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf — and, one level down, that business associate and each of its own subcontractors that touch the information (45 CFR 164.502(e), 164.504(e)(5)). The chain continues downward: every link needs a written agreement before the data flows.
- Is a BAA template safe to use without a lawyer?
- Use a template to understand the required provisions and to produce a working draft — then have an attorney review it before signing. The regulatory provisions are standard; what varies deal to deal is everything else: indemnification, insurance requirements, notification timelines shorter than the regulation's 60 days, offshore restrictions and audit rights. Those are negotiated terms, not compliance boilerplate, and they are where counsel earns the fee.
Keep reading
- HIPAA risk assessment softwareGuided assessment with remediation tracking and carry-forward.
- Policies and acknowledgementsVersioned policies your staff read and sign.
- Staff training and certificatesAnnual courses with dated certificates and chasing.
- Vendor and BAA registerWho touches patient data, what is signed, when it expires.
- Incident and breach logFour-factor assessment with the deadline counting down.
Looking for the software rather than the explanation? Vendor and BAA register.
Sent a security questionnaire along with the BAA? Here is how to answer it →
This generator produces a general starting template and is informational only, not legal advice — we are not a law firm. The required provisions come from 45 CFR 164.504(e); the terms parties actually negotiate (indemnity, insurance, shorter notice windows, offshore restrictions) are not in any template. Have an attorney licensed in your state review the document before either party signs.