HealthAIdir logoHealthAIdir

BAA

A business associate agreement sets permitted PHI uses and safeguards between a covered entity and business associate.

industryPublished 2026/06/06Last verified 2026/07/17

Healthcare compliance context

This definition is for general healthcare technology research and is not legal or compliance advice. BAA requirements and contract terms should be reviewed by qualified counsel and compliance teams.

BAA means business associate agreement. In HIPAA workflows, it is a written contract or arrangement that establishes how a business associate may use or disclose PHI and what safeguards and obligations apply.

For healthcare AI tools, BAA availability is a key review signal, but it is not the only one. Teams should also inspect security practices, data retention, model training terms, breach notification, subcontractor controls, and whether the intended workflow is covered by the agreement.

Application scenario: In care setting review, this term helps teams connect a vendor claim to the clinical, administrative, compliance, or patient-facing workflow where it applies. Procurement impact: Buyers should evaluate evidence, implementation effort, integration needs, security, privacy, pricing assumptions, support, and compliance responsibilities before shortlisting or contracting for a tool that depends on this capability.

Sources and review notes

These links support definition-level research and do not establish the regulatory status, safety, or suitability of any product.

HHS explains that a covered entity engaging a business associate for functions involving PHI generally needs a written business associate contract or other arrangement that identifies the work and requires protection of PHI; business associates are also directly liable for specified HIPAA provisions. HHS guidance describes required contract subjects such as permitted uses and disclosures, safeguards, incident and breach reporting, assistance with individual rights, access for HHS, subcontractor obligations, and return or destruction at termination when feasible. HHS's sample provisions are optional examples, may need adaptation, do not include every term required for a binding agreement, and do not replace state-law review or legal advice. A signed BAA does not prove that an organization, product, configuration, or data flow is HIPAA compliant. Teams must map each entity and subcontractor role; PHI creation, receipt, maintenance, transmission, support access and location; permitted purposes including model training or de-identification; minimum-necessary limits; security and incident duties; notification timing; rights support; retention, backup and deletion; termination; evidence and audit rights; conflict with service terms; and whether the actual workflow falls inside the executed agreement.

FAQs

Is a BAA enough to approve an AI tool?
No. A BAA is important, but teams should also review security, workflow fit, PHI use, subcontractors, data retention, and local policies.

Related research

Use related glossary terms and healthcare AI tool profiles to connect terminology checks with vendor due diligence.