Compliance & Regulatory

    Business Associate Agreement (BAA)

    A BAA is a contract required under HIPAA between a healthcare provider and any vendor that handles PHI on their behalf, including software development partners and cloud hosts. A development team building healthcare software needs to operate under a signed BAA before touching real patient data.

    Key takeaways

    • HIPAA-required contract for any vendor handling PHI
    • Covers dev partners, cloud hosts, and subprocessors
    • Defines safeguards, breach notice, and data return or destruction
    • Obligations cascade to subcontractors down the chain
    • Must be signed before a partner touches real patient data

    What BAA means

    A BAA is the contract HIPAA requires between a covered entity, such as a healthcare provider, and any business associate that handles protected health information on its behalf. That definition sweeps in software development partners, cloud hosts, analytics vendors, and many subprocessors. The agreement makes each party's responsibilities for safeguarding data explicit and legally binding rather than assumed.

    In practice the BAA defines how PHI may be used and disclosed, the safeguards each side must maintain, breach notification obligations, and what happens to data when the relationship ends. It also cascades: a vendor that passes PHI to its own subcontractors generally needs equivalent agreements in place with them. This creates a chain of accountability that has to hold end to end for the arrangement to be compliant.

    The operational rule for a development team is simple and strict: a signed BAA should be in place before anyone touches real patient data. Until then, teams work with synthetic or de-identified data. When evaluating a partner, the willingness and ability to sign a BAA, and to name which subprocessors are covered, is a quick signal of whether they take healthcare data handling seriously.

    Explore this on Agnotic

    Where BAA shows up in how we build.

    Frequently asked questions

    Any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity, which includes software development partners, cloud hosting providers, and many third-party tools. If a service will touch real patient data, it generally needs a BAA. Vendors that only handle de-identified data typically do not.

    Talk through your build with an engineer

    Tell us what you're building and the systems it needs to talk to, and we'll map a clear, compliant path to launch.