Business Associate Agreement

Business Associate Agreement

Business Associate Agreement

A business associate agreement must specify permitted uses and disclosures, require appropriate safeguards, obligate the associate to report breaches, extend obligations to subcontractors, and require return or destruction of the information at termination.

Business associates have direct liability under HIPAA independent of the covered entity.

Alternative Names:

BAA, Business Associate Contract

Why it Matters?

Law firms handling medical records are business associates and must have agreements both with their healthcare clients and with their own vendors, since the obligation flows down the chain. Firms frequently have the first and neglect the second, which leaves protected health information with e-discovery and AI vendors under no HIPAA-compliant contract. That gap is a direct compliance failure and a client-facing problem when guidelines require confirmation.

Frequently Confused with

Related terms

Frequently asked questions

Does a law firm need business associate agreements with vendors?

Does a law firm need business associate agreements with vendors?

Yes. The obligation flows down, so any vendor accessing protected health information on the firm's systems requires one.

Are business associates directly liable under HIPAA?

Are business associates directly liable under HIPAA?

Yes. Since the HITECH Act, business associates face direct enforcement rather than liability only through the covered entity's contract.