A business associate agreement must specify permitted uses and disclosures, require appropriate safeguards, obligate the associate to report breaches, extend obligations to subcontractors, and require return or destruction of the information at termination.
Business associates have direct liability under HIPAA independent of the covered entity.
Alternative Names:
BAA, Business Associate Contract
Why it Matters?
Law firms handling medical records are business associates and must have agreements both with their healthcare clients and with their own vendors, since the obligation flows down the chain. Firms frequently have the first and neglect the second, which leaves protected health information with e-discovery and AI vendors under no HIPAA-compliant contract. That gap is a direct compliance failure and a client-facing problem when guidelines require confirmation.
Frequently Confused with
Related terms
Frequently asked questions
Does a law firm need business associate agreements with vendors?
Are business associates directly liable under HIPAA?





