A HIPAA business associate agreement is a written contract that a covered entity must put in place before sharing protected health information (PHI) with any outside person or company that will handle that data on its behalf. The contract defines what the vendor can do with the information, requires specific safeguards, obligates the vendor to report breaches, and extends HIPAA’s protections beyond the healthcare organization itself.1HHS.gov. Business Associate Contracts Without one, both parties face civil penalties starting at $145 per violation and, in some cases, criminal prosecution.
The agreement has to be in writing. It can stand on its own or live inside a broader services contract, but a verbal understanding or a handshake does not satisfy HIPAA.2U.S. Department of Health and Human Services. Business Associates Regulators ask for the document during audits, so the paper trail matters as much as the security work behind it.
When You Need One
A business associate agreement is required whenever a covered entity engages an outside party that will create, receive, maintain, or transmit PHI on the covered entity’s behalf.1HHS.gov. Business Associate Contracts The two sides of that relationship are worth pinning down.
A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically for standard transactions such as billing or eligibility checks.3eCFR. 45 CFR 160.103 – Definitions Hospitals, insurers, physician practices, and pharmacies are the typical examples.
A business associate is any outside person or organization (not an employee of the covered entity) that handles PHI while doing work for the covered entity. That definition sweeps in billing companies, IT firms managing electronic health records, cloud storage providers, claims processors, outside consultants who review patient files, and shredding services that destroy paper records containing PHI. One covered entity can also be a business associate of another when it performs services involving PHI on the other’s behalf.
The Conduit Exception
Not every service that touches PHI in transit needs an agreement. HHS recognizes a narrow conduit exception for services that only transmit PHI without storing it in any meaningful way. The postal service delivering a sealed envelope of medical records and an internet provider routing encrypted packets are the standard examples. The line is transient access versus persistent access. If the vendor stores PHI beyond what’s briefly necessary to complete a transmission, it’s a business associate, whether or not it ever looks at the data.4HHS.gov. Can a CSP Be Considered to Be a Conduit
This trips people up. An electronic fax service usually stores faxes on its servers rather than passing them straight through, which makes it a business associate. Cloud service providers almost always qualify, encryption and access controls notwithstanding, because they persistently hold the data.
What the Agreement Must Contain
HIPAA leaves little room for improvisation on content. The regulation at 45 CFR 164.504(e)(2) lists the provisions every business associate agreement needs. Missing any of them makes the contract non-compliant, which is functionally the same as having none.
Every agreement must:5eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements
- Spell out the permitted uses and disclosures of PHI, and prohibit any use the covered entity itself could not make under HIPAA.
- Require the business associate to use appropriate safeguards and, for electronic PHI, comply with the HIPAA Security Rule.
- Require the business associate to report any unauthorized use or disclosure, including breaches of unsecured PHI.
- Bind subcontractors to the same restrictions when they handle PHI on the business associate’s behalf.
- Require the business associate to make PHI available so individuals can exercise their access rights.
- Require the business associate to accommodate amendments to PHI when directed.
- Require the business associate to track and produce the information needed for an accounting of disclosures.
- Require the business associate to make its internal practices and records available to the Secretary of HHS for compliance review.
- At the end of the contract, require the return or destruction of all PHI, with no copies retained where feasible.
- Give the covered entity authority to terminate the contract if the business associate violates a material term.
Two optional provisions are worth flagging. The agreement may allow the business associate to use PHI for its own management and administration, and it may permit data aggregation services related to the covered entity’s healthcare operations.5eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements These are permissions, not defaults, and belong in the contract only when the business relationship actually calls for them. HHS publishes sample provisions that work as a drafting checklist.1HHS.gov. Business Associate Contracts
The Minimum Necessary Standard
One requirement sits alongside the contract language rather than inside it. Both covered entities and business associates must make reasonable efforts to limit PHI to the least amount needed for the task.6eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information A billing vendor processing claims doesn’t need a patient’s full psychiatric notes. Access controls, not just contract clauses, should reflect that.
The rule has carve-outs: it doesn’t apply to disclosures for treatment, disclosures to the patient, uses the patient has authorized, or disclosures required by law.6eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information
Breach Notification Timing
When a breach of unsecured PHI happens at a business associate, the clock starts on discovery. The business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering the breach.7eCFR. 45 CFR 164.410 – Notification by a Business Associate Sixty days is a ceiling, not a target.
The notice must include, to the extent known, the identities of the affected individuals and any other information the covered entity needs to meet its own notification duties. If the business associate hasn’t yet identified every affected person, it should still report on time. Partial information now beats complete information late.8HHS.gov. Breach Notification Rule
The covered entity then has its own 60-day window to notify affected individuals. Breaches affecting 500 or more people also require notice to HHS and to prominent media in the affected area. Smaller breaches are reported to HHS annually. A business associate that reports late can push the covered entity past its own deadline, which is why enforcement actions for delayed notification frequently name both.8HHS.gov. Breach Notification Rule
The Agreement Does Not Cap the Vendor’s Liability
Business associates are directly liable to HHS for HIPAA violations, not just to the covered entity through contract. Since the HITECH Act took effect in 2009, business associates have been on the hook for Security Rule compliance, breach notification, unauthorized uses and disclosures, the minimum necessary standard, subcontractor agreements of their own, and providing electronic PHI when required.9HHS.gov. Direct Liability of Business Associates
A signed agreement doesn’t shield a business associate from HHS enforcement, civil monetary penalties, or criminal prosecution when it fails on its own obligations. It also doesn’t shift the covered entity’s responsibility away. Both parties are accountable in parallel.
Penalties for Operating Without a Compliant Agreement
Civil penalties fall into four tiers based on the violator’s awareness and intent, from “did not know” at the low end to “willful neglect, not corrected” at the top. After the most recent inflation adjustment effective in 2025, penalties start at $145 per violation and reach $2,190,294 per violation for the worst tier, with per-year caps at the top of $2,190,294 for each violation category. The per-year cap applies per category, not in aggregate, and a single breach affecting thousands of patients can produce thousands of separate violations. Settlements regularly reach seven figures.
Criminal penalties apply to individuals who knowingly obtain or disclose PHI in violation of HIPAA:10Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information
- Knowing violation: up to $50,000 in fines and one year in prison.
- False pretenses: up to $100,000 in fines and five years in prison.
- Intent to sell, transfer, or use PHI for personal gain or malicious harm: up to $250,000 in fines and ten years in prison.
Criminal exposure runs against individuals, including employees at a business associate. Someone who browses records out of curiosity or sells PHI can face personal prosecution regardless of what the employer’s agreement says.
Ending the Relationship
When the business associate relationship ends, the contract’s termination provisions come into play. The default rule requires the business associate to return or destroy all PHI it received from or created for the covered entity, keeping no copies.1HHS.gov. Business Associate Contracts If the business associate genuinely needs to retain certain PHI for its own legal or administrative purposes, the agreement can authorize that, but HIPAA safeguards continue to apply to whatever is kept, indefinitely.
If a covered entity discovers that a business associate has materially violated the agreement, the covered entity must take reasonable steps to cure the problem. If cure fails, termination is required when feasible. If termination isn’t feasible, the covered entity must report the situation to HHS.5eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements Leaving a non-compliant business associate in place without acting is itself a compliance failure.