Glossary

What is business associate agreement?

A business associate agreement, or BAA, is a contract required under HIPAA between a healthcare covered entity and a vendor that creates, receives, maintains or transmits protected health information on its behalf. It sets out how the vendor will safeguard that information and what happens if a breach occurs.

How business associate agreement works

A BAA typically covers the permitted uses and disclosures of protected health information, the safeguards the business associate must apply, a requirement to report any breach or unauthorized use to the covered entity within a set timeframe, and what happens to the data when the relationship ends, such as returning or destroying it.

Any vendor that touches this information as part of its work, including a billing company, IT provider or offshore support team, needs a signed BAA before it begins handling that data, not after. A covered entity that fails to get a BAA in place with a vendor handling this data is itself out of compliance with HIPAA, regardless of the vendor's own practices.

Example

A dental practice hires a billing support provider to post insurance payments. Before any patient data is shared, the practice and the provider sign a BAA specifying the provider will encrypt the data, restrict access to trained staff, and notify the practice within 5 business days of any suspected breach, consistent with HIPAA's breach notification expectations.

Business associate agreement in QuickBooks Online vs Xero

Not software-specific: a BAA is a legal contract rather than a software feature, though cloud providers such as Google Workspace and Microsoft 365 offer their own BAA to customers handling protected health information on their platforms. Businesses typically maintain a signed BAA on file with every vendor and cloud service that touches this data.

Common mistakes

  • Letting a vendor begin working with protected health information before a BAA is signed, which leaves the covered entity out of compliance from the first day of the engagement.
  • Signing a BAA with vague breach notification language instead of a specific timeframe, which can delay a practice's own required response if the vendor discovers a problem late.
  • Forgetting what happens to the data at engagement end, which can leave protected health information sitting with a vendor with no contractual obligation to return or destroy it.

Why it matters

A signed BAA is what makes a vendor relationship involving patient data compliant under HIPAA, so skipping it or signing one with weak terms puts a healthcare provider at regulatory and financial risk. For a medical or dental practice choosing a billing or bookkeeping provider, a BAA covering safeguards, breach notification and data handling at offboarding is a non-negotiable part of vetting any vendor that will touch protected health information.

Related terms

How LedgerBPO handles business associate agreement

We sign a business associate agreement with every healthcare client before handling protected health information, covering safeguards, breach notification and data handling at the end of an engagement. Our compliance page has more detail on how we structure BAAs and the training our staff complete before working on healthcare accounts.

Compliance, country by country

Ask an AI assistant to summarize this page

Next step

Books closed. Invoices paid. Every month.

Tell us what is going on with your books or billing. You will hear from a named person within 1 business day, with a custom quote and a plan for the first close.

  • Reply from a named person within 1 business day
  • No setup fee, month-to-month
  • Your software, your data, no lock-in

Start with a custom quote

Get a custom quote Book a 20-minute call

Or call +1-657-777-0006 during US, UK or Australian business hours.

Call WhatsApp Book