Business Associate Agreement Template (US HIPAA)

Updated on August 24, 2026

A business associate agreement is useful only if it makes the commercial promise precise enough to run a project, approve money, and resolve a dispute. The Jotform source gives users a downloadable shape, but it leaves the highest-risk points either blank or invisible: who is responsible for approvals, what changes the price, what laws affect the document, and what record each party must keep.

This US master is drafted as a practical working document rather than a decorative PDF. It adds real definitions, optional branches, statutory checkpoints, clause-by-clause guidance, and a clean fillable document that can be downloaded as DOCX or PDF without signup. The US page uses HIPAA BAA terminology because that is the correct US healthcare document. The family slug is broader because B3 will build local data-processing agreements, not translations of HIPAA.

2 of 10 blanks filled

Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark

Business Associate Agreement

Effective date:
Covered Entity:
Business Associate:
Governing state:

1. Services and HIPAA terms

Business Associate provides the following services involving Protected Health Information: . HIPAA terms used in this agreement have the meanings given in 45 CFR parts 160 and 164, including PHI, ePHI, breach, security incident, subcontractor and unsecured PHI.

2. Permitted uses and disclosures

Business Associate may use or disclose PHI only for the services and purposes stated here: , as required by law, or as otherwise permitted by this agreement in a manner consistent with 45 CFR 164.504(e). Business Associate may not use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Covered Entity.

3. Safeguards and minimum necessary

Business Associate will use appropriate administrative, physical and technical safeguards to protect PHI and ePHI, will comply with applicable Security Rule obligations for ePHI, and will limit requests, uses and disclosures to the minimum necessary consistent with Covered Entity policies provided to Business Associate.

4. Reporting

Business Associate will report to any use or disclosure not provided for by this agreement, any breach of unsecured PHI and any material security incident without unreasonable delay and no later than hours after discovery, with information reasonably needed by Covered Entity to investigate and notify.

5. Subcontractors

Subcontractor authorization: . Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions and safeguards that apply to Business Associate for that PHI.

6. Individual rights and HHS access

Business Associate will make PHI available as needed for Covered Entity to satisfy access, amendment and accounting duties, and will make internal practices, books and records relating to PHI available to the Secretary of HHS for HIPAA compliance review.

7. Return, destruction and termination

At termination, Business Associate will return or destroy PHI as directed by if feasible. If return or destruction is infeasible, Business Associate will continue protections and limit further use and disclosure to the purpose that makes return or destruction infeasible. Covered Entity may terminate this agreement for a material breach if cure is not possible or is not completed within the written cure period.

Covered Entity

Date:

Business Associate

Date:

A BAA is required because of PHI, not because of a job title

HIPAA business associate status depends on what the vendor does with protected health information. A billing service, cloud provider, claims processor, consultant, health information exchange or subcontractor may be a business associate if it creates, receives, maintains or transmits PHI for a covered function. A vendor with no PHI access generally does not become a business associate just because it serves a healthcare client.

The Jotform PDF identifies covered entity and business associate, but it uses loose terms such as protected health data and omits several operational details. This template uses HIPAA terms, requires a description of permitted uses, includes Security Rule safeguards for ePHI and adds the subcontractor flow-down language HHS expects.

45 CFR 164.504(e) is the spine

HHS guidance says the BAA must contain the elements specified at 45 CFR 164.504(e). Those include permitted and required uses and disclosures, no further use or disclosure except as permitted or required by law, safeguards, reporting of unauthorized use or disclosure, individual-rights support, HHS access to books and records, return or destruction of PHI if feasible, subcontractor restrictions and termination for material breach.

This template makes those items first-class clauses rather than burying them in a miscellaneous paragraph. It also makes minimum necessary, data aggregation, management and administration uses, breach reporting and security incidents visible choices that the parties can complete.

Self-certification is not a substitute

HHS is direct about this point: a covered entity cannot replace the BAA with a business associate self-certification. A vendor saying it is HIPAA compliant may be useful diligence, but the covered entity still needs a compliant contract or other written arrangement. This template avoids any claim that downloading it equals compliance or attorney review.

The document also avoids the opposite mistake: copying HHS sample provisions without the commercial details needed for a binding agreement. It includes term, notices, services, subcontractors, return/destruction, survival and signatures, while keeping the HIPAA-required language intact.

Why the international family is data-processing agreement

Outside the United States, Business Associate Agreement is usually the wrong phrase. In the EU and UK, the equivalent risk is commonly a controller-processor agreement under GDPR-style law. In Canada, Australia, Japan, Brazil, Mexico and other markets, health privacy and general data protection laws use their own structures.

That is why the family slug is data-processing-agreement. The US master is a HIPAA BAA because that is what the Jotform keyword asks for. The localized B3 pages must be local data-processing or health-information processing agreements, not HIPAA translations.

BAA clause-by-clause guide

Definitions
Uses HIPAA terms such as PHI, ePHI, breach, security incident, subcontractor and designated record set.
Permitted uses and disclosures
Limits PHI use to the services, required law, management/administration and permitted data aggregation.
Minimum necessary
Requires requests and disclosures to follow the covered entity minimum necessary policies.
Safeguards and Security Rule
Requires administrative, physical and technical safeguards for ePHI.
Reporting
Separates unauthorized use/disclosure, breach of unsecured PHI and security incidents.
Individual rights support
Supports access, amendment and accounting obligations where the business associate holds relevant PHI.
Subcontractors
Requires downstream subcontractors with PHI access to accept the same restrictions.
HHS access
Makes books and records available to HHS for compliance review as required.
Return or destruction
Requires return or destruction at termination if feasible and continued protection if infeasible.
Termination for material breach
Allows cure or termination when a material HIPAA term is violated.

US HIPAA BAA checklist

  • Confirm the vendor is a business associate

    HHS defines business associates by functions involving PHI, and subcontractors that create, receive, maintain or transmit PHI for another business associate are also covered.

    HHS Business Associates guidance
  • Include all 45 CFR 164.504(e) elements

    The BAA must describe permitted uses/disclosures, restrict further disclosure, require safeguards and reporting, address individual rights support, HHS access, return/destruction, subcontractors and termination.

    HHS sample BAA provisions
  • Do not rely on self-certification

    HHS says a covered entity must enter into a contract or other written arrangement that meets 45 CFR 164.504(e); self-certification is not enough.

    HHS self-certification FAQ
  • Address ePHI safeguards

    The business associate is directly liable for failing to safeguard electronic PHI under the Security Rule, so the agreement should include practical security obligations.

  • Flow terms down to subcontractors

    A subcontractor with PHI access must agree to the same restrictions and conditions that apply to the business associate.

  • State breach and security-incident timing

    The agreement should require prompt reporting and enough detail for the covered entity to meet its own notification obligations.

How to complete this BAA

  1. Identify the parties and services. Enter covered entity, business associate and the service agreement or services involving PHI.
  2. Define permitted PHI uses. Describe exactly what PHI may be used or disclosed for and whether de-identification or data aggregation is allowed.
  3. Set security and reporting obligations. Add safeguard expectations, reporting contacts and breach/security incident timing.
  4. Address subcontractors. Require written downstream agreements before PHI is shared with subcontractors.
  5. Set return or destruction mechanics. State what happens to PHI at termination and what protections continue if destruction is infeasible.
  6. Review with the service contract. Make sure the BAA matches the underlying services agreement, privacy notices and security exhibits.

Frequently asked questions

What is a business associate agreement?

It is the HIPAA-required contract or written arrangement that lets a covered entity share PHI with a business associate for permitted services while requiring safeguards, limits on use and disclosure, reporting, subcontractor flow-down and return or destruction obligations.

Who needs a BAA?

A covered entity needs one with a vendor that creates, receives, maintains or transmits PHI for covered functions. A business associate also needs one with a subcontractor that handles PHI on its behalf.

Can a vendor self-certify instead of signing a BAA?

No. HHS says self-certification is not a substitute for the contract or other written arrangement required by 45 CFR 164.504(e).

Does this make my organization HIPAA compliant?

No template can do that. The BAA is one required contract piece. HIPAA compliance also depends on privacy practices, security risk management, workforce training, policies, breach response and the facts of the services.

Can the business associate use PHI for its own purposes?

Only within narrow permitted purposes such as proper management and administration, required law, or data aggregation if allowed. It cannot use or disclose PHI in a way that would violate the Privacy Rule if done by the covered entity.

What should happen at termination?

The business associate should return or destroy PHI if feasible. If return or destruction is infeasible, it must continue protecting the PHI and limit further use or disclosure to the purpose that makes return or destruction infeasible.

Why is the family called data-processing agreement?

Because outside the US, the local equivalent is usually a controller-processor or data-processing agreement, not a HIPAA BAA. B3 must build those local equivalents from local law.

Related templates

Disclaimer

This template and guide are for general information only and do not constitute legal, tax, privacy, insurance, construction, transport, or health-care compliance advice. Check the current law, regulator guidance, solicitation terms, and contract facts before signing.