Business associate agreement (BAA)
A business associate agreement (BAA) is the written contract required by the US HIPAA Privacy and Security Rules (45 CFR 164.502(e) and 164.504(e)) between a covered entity (healthcare provider, health plan or clearinghouse) and a business associate, that is, a person or organisation that creates, receives, maintains or transmits protected health information on the covered entity's behalf for functions such as claims processing, data analysis, utilisation review, billing, IT hosting, transcription or legal and consulting services. Since the 2013 Omnibus Rule, business associates are directly liable under HIPAA and must in turn conclude BAAs with their subcontractors.
A BAA must establish the permitted and required uses and disclosures of PHI by the business associate; prohibit other uses; require appropriate safeguards and compliance with the Security Rule for electronic PHI; require reporting of unauthorised uses, disclosures and breaches of unsecured PHI to the covered entity; require the business associate to ensure that subcontractors agree to the same restrictions; require assistance with individuals' rights of access, amendment and accounting of disclosures; require that PHI be made available to HHS for compliance purposes; and require return or destruction of PHI at termination. HHS publishes sample provisions, and BAAs are commonly attached to master services agreements and cloud contracts.
The BAA is the functional cousin of the GDPR's Art. 28 data processing agreement, but the two are not interchangeable. A BAA is required only within the HIPAA perimeter (a pharmaceutical sponsor receiving trial data from a US site is not a business associate and does not sign one, whereas an EDC vendor hosting data for a hospital may be), while a DPA is required for every processor regardless of sector. A BAA does not address international transfers, DPIAs or data subject rights in GDPR terms, and a DPA does not satisfy HIPAA's specific content requirements. Vendors serving both US healthcare customers and EU life sciences companies therefore typically maintain both instruments, and iliomad's contractual review checks that the two are consistent, particularly on breach timelines, subcontractor flow-down and data return. See also iliomad's HIPAA services.
