Business Associate Agreements in Medical Billing
When a practice hands its billing, its claims, or its collections to an outside company, it is disclosing protected health information to that company — and the HIPAA Privacy Rule permits that disclosure only after a specific written contract is in place. That contract is the business associate agreement (BAA). It is not a formality or a general confidentiality clause: the rule sets out much of what the agreement must say, and getting a claim paid through a vendor is only compliant if the BAA exists first and contains the terms HIPAA requires.
Updated 14 min read
On this page
Key takeaways
- A business associate agreement is the written contract a covered entity must obtain before it discloses PHI to — or lets — a business associate create, receive, maintain, or transmit PHI on its behalf (45 CFR 164.502(e)). The contract has to exist before the data moves.
- The rule dictates the agreement's content. A BAA must contain a defined set of provisions (45 CFR 164.504(e)(2)) — the permitted uses and disclosures, appropriate safeguards, a duty to report impermissible uses and breaches, flow-down to subcontractors, availability of PHI for patient access and amendment and for an accounting, records access for HHS, and return or destruction of PHI at termination.
- Two rules require it, not one. The Privacy Rule requires the contract (164.502(e), 164.504(e)); whenever electronic PHI is involved the Security Rule imposes its own written-contract requirement too (164.308(b), 164.314(a)), so a compliant BAA satisfies both.
- The obligations flow down the chain. A business associate's subcontractors that handle PHI are themselves business associates (45 CFR 160.103) and need their own agreements — and it is the business associate, not the covered entity, that must obtain those assurances (164.502(e)(1)(ii); 164.504(e)(5)).
- Since the 2013 Omnibus Rule, business associates are directly liable to federal enforcement for the HIPAA requirements the HITECH Act made applicable to them — the contract is no longer the only thing that binds them.
- The agreement is enforceable. If a covered entity learns of a pattern of activity that is a material breach of the business associate's obligations, it must take reasonable steps to cure it and, if that fails, terminate the contract where feasible (45 CFR 164.504(e)(1)(ii)).
What a business associate agreement is
A business associate is the outside party — a billing company, a clearinghouse, a collections agency, a software or storage vendor — that handles PHI to perform work for a practice. The business associate agreement is the contract between the two. The distinction matters because the rule treats them differently: the business associate is who does the work, and the BAA is the written instrument that makes the arrangement permissible in the first place.
The Privacy Rule permits a covered entity to disclose PHI to a business associate, or to let a business associate create, receive, maintain, or transmit PHI on its behalf, only if the covered entity first obtains satisfactory assurances that the business associate will safeguard the information (45 CFR 164.502(e)(1)). Those assurances are not a handshake — the rule requires them to be documented through a written contract or other written arrangement that meets the content requirements of 45 CFR 164.504(e) (164.502(e)(2)). The BAA is that document.
A BAA is not a confidentiality clause
When a billing operation needs one
The trigger is function, not job title: an agreement is required whenever an outside party will create, receive, maintain, or transmit PHI to perform a service for the practice. The business-associate definition at 45 CFR 160.103 lists the kinds of work that qualify — claims processing and administration, billing, data analysis, utilization review, practice management — and the revenue cycle is full of them. A third-party billing service, a clearinghouse acting beyond a pure transmission role, a collections agency, and the software or hosting vendors whose systems hold claim data are all business associates, and each needs a BAA before it receives PHI.
Some relationships that look similar do not require a BAA, and knowing the boundary keeps a practice from papering over a relationship the rule leaves alone. The definition at 160.103 excludes several parties, and two matter most in billing:
- The conduit
- An entity that only transports PHI and has at most random or incidental access to it — a courier, the postal service, an internet service provider carrying data — is not a business associate. The line the rule draws is routine access: a service that requires access to the information on a routine basis to do its job is a business associate; one that merely moves a sealed package is a conduit. A vendor that stores or processes claim data is well past the conduit line.
- The treating provider
- A disclosure of PHI from one provider to another for the treatment of the patient does not make the receiving provider a business associate (45 CFR 160.103). Sending records to a referring physician for care is a treatment disclosure, not a business-associate relationship — a different lane from sending claim data to a billing vendor.
The contract comes before the data
What the agreement must contain
The rule does not leave the content of a BAA to the parties' imagination. 45 CFR 164.504(e)(2) sets out what the contract must establish and require. The first piece is scope: the agreement establishes the permitted and required uses and disclosures of PHI by the business associate, and it may not authorize the business associate to use or disclose the information in a way the covered entity itself could not (164.504(e)(2)(i)). Within that limit, the contract may allow the business associate to use PHI for its own proper management and administration and to provide data aggregation services for the covered entity's operations.
On top of scope, the agreement must require the business associate to do a defined set of things (45 CFR 164.504(e)(2)(ii)):
- Not use or further disclose the information except as the contract permits or as required by law.
- Use appropriate safeguards — and, for electronic PHI, comply with the Security Rule — to prevent uses or disclosures the contract does not allow.
- Report to the covered entity any use or disclosure not provided for by the contract that it becomes aware of, including breaches of unsecured PHI.
- Ensure that any subcontractors it uses to create, receive, maintain, or transmit PHI agree to the same restrictions and conditions that apply to the business associate.
- Make PHI available so the covered entity can meet a patient's right of access and right to amend, and provide the information needed for an accounting of disclosures.
- To the extent the business associate carries out one of the covered entity's own Privacy Rule obligations, comply with the requirements that apply to the covered entity in doing so.
- Make its internal practices, books, and records relating to PHI available to HHS for determining the covered entity's compliance.
- At termination, return or destroy all PHI if feasible — and, where it is not feasible, extend the agreement's protections to the information and limit further use to what makes return or destruction infeasible.
Finally, the contract must authorize the covered entity to terminate it if the covered entity determines the business associate has violated a material term (164.504(e)(2)(iii)). Those are the required bones of the agreement; parties routinely add more — indemnification, insurance, cooperation on patient requests — but the provisions above are what make the document a BAA rather than an ordinary vendor contract.
OCR's sample provisions are a starting point, not a form
Two rules require it: Privacy and Security
It is easy to think of the BAA as a Privacy Rule instrument, because that is where the requirement to obtain a written contract before disclosing PHI lives (45 CFR 164.502(e), 164.504(e)). But the Security Rule imposes a parallel requirement of its own. Whenever a business associate will handle electronic PHI, the covered entity may permit it only after obtaining satisfactory assurances, documented in a written contract, that the business associate will appropriately safeguard the information (45 CFR 164.308(b)).
The Security Rule then specifies what that contract must say (45 CFR 164.314(a)): the business associate will comply with the applicable Security Rule requirements, will ensure that subcontractors handling electronic PHI enter into a contract to do the same, and will report to the covered entity any security incident it becomes aware of, including a breach of unsecured PHI. In practice this is not two separate documents — a single, well-drafted BAA satisfies both rules — but it does mean an agreement that addresses privacy and is silent on security is incomplete whenever electronic data is in play, which in a modern billing operation is always.
| Dimension | Privacy Rule | Security Rule |
|---|---|---|
| What it covers | Protected health information in any form | Electronic protected health information |
| The requirement | Obtain a written contract before disclosing PHI to a business associate (164.502(e)) | Obtain a written contract before a business associate handles electronic PHI (164.308(b)) |
| What the contract must say | The provisions of 164.504(e)(2) | The provisions of 164.314(a) |
One agreement can and normally does satisfy both. The point is that a BAA touching electronic data must carry the security terms as well as the privacy terms.
The chain: subcontractors and flow-down
A business associate rarely works alone. Its own cloud host, its analytics vendor, its document-storage provider — each is a party the business associate delegates work to, and if that work involves PHI the rule follows the data downstream. A subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate is itself a business associate under 45 CFR 160.103, and needs its own agreement.
The obligation to obtain that downstream agreement sits with the business associate, not the covered entity. The rule requires a business associate to obtain satisfactory assurances from its subcontractors on the same terms a covered entity must obtain from the business associate (45 CFR 164.502(e)(1)(ii)), and the content requirements of a BAA apply to the business associate–subcontractor contract to the same extent they apply to the covered entity–business associate contract (164.504(e)(5)). The obligations flow down the chain unchanged; they do not weaken with each link.
What the covered entity is and is not on the hook for
The contract is not the only thing that binds a vendor
For years, a business associate's HIPAA obligations reached it only through its contract with the covered entity — the practice, not the government, was the enforcer. The HITECH Act changed that, and the 2013 Omnibus Rule implemented it: business associates became directly liable to federal enforcement for the HIPAA requirements the statute made applicable to them. A business associate is now bound by regulation as well as by the BAA.
Direct liability reaches specific duties — among them impermissible uses and disclosures of PHI, failing to comply with the Security Rule, failing to notify the covered entity of a breach, failing to make records available to HHS for an investigation, and failing to enter into compliant agreements with subcontractors. It does not turn a business associate into a covered entity for every purpose: obligations that the rules apply to a business associate only through its contract remain a matter for the covered entity to enforce, not the government. HHS publishes a fact sheet enumerating the categories of direct liability, and it is the authoritative place to see the full list.
Why this does not make the BAA optional
Managing agreements over their lifecycle
A BAA is not a document that gets signed once and filed. Applying the rule well is a matter of a few operational habits built around the agreements a practice holds.
Inventory every vendor that touches PHI
List the outside parties that create, receive, maintain, or transmit claim data — billing service, clearinghouse, collections agency, EHR and practice-management systems, hosting and backup vendors — and confirm each has a current signed agreement. The vendors that get missed are usually the software and infrastructure ones, because they feel like tools rather than parties.Execute the agreement before any data moves
Make the signed BAA a precondition of onboarding a vendor, so PHI is never disclosed ahead of the contract the Privacy and Security Rules require (164.502(e), 164.308(b)).Confirm the required terms are actually present
Check the agreement against the provisions the rule requires (164.504(e)(2), 164.314(a)) rather than assuming a vendor's standard form is complete. A missing return-or-destroy clause or a silent security section is a gap even when both parties meant well.Require flow-down to subcontractors
Ensure the agreement obligates the business associate to bind its own subcontractors on the same terms (164.502(e)(1)(ii), 164.504(e)(5)), so the protections follow the data down the chain.Act on a pattern of material breach
If the practice becomes aware of a pattern of activity that is a material breach of the agreement, take reasonable steps to cure it and, if that is unsuccessful, terminate the contract where feasible (164.504(e)(1)(ii)). Knowing of the pattern and doing nothing is itself a compliance failure.Close out the data when the relationship ends
At termination, hold the vendor to the return-or-destroy obligation (164.504(e)(2)(ii)) — and where returning or destroying the PHI is genuinely infeasible, confirm the agreement's protections continue to apply to whatever is retained.
The BAA is one instrument inside the larger set of duties the HIPAA Privacy Rule in medical billing creates — the permission to use PHI for payment at all — and it works alongside the minimum necessary standard, which limits what a practice and its business associates disclose even when a BAA is in place. The wider set of regulatory duties sits in the Compliance and Regulations category. Because the rules are revised and their enforcement guidance evolves, agreements should point to the current regulation and be reviewed when it changes.
Educational, not legal advice
Common questions
Do we need a business associate agreement with our clearinghouse?
Almost always, yes. A clearinghouse that processes or reformats claim data is handling PHI to perform a function for the practice, which makes it a business associate that needs a BAA before it receives the data (45 CFR 164.502(e)). The narrow exception is a party acting as a pure conduit — one that merely transmits information and has at most incidental access to it. A clearinghouse that touches the content of a claim is well past that line.
Is a business associate agreement the same as an NDA?
No. A non-disclosure agreement protects confidential information in general terms; a BAA is a specific contract whose required provisions are set by HIPAA (45 CFR 164.504(e)(2), 164.314(a)). A vendor contract can keep information confidential and still fail to be a valid BAA if it omits the required terms — permitted uses, safeguards, breach reporting, subcontractor flow-down, records access for HHS, and return or destruction at termination.
Our billing vendor uses its own subcontractors. Do we need a BAA with each of them?
No — that obligation sits with the business associate, not the practice. A subcontractor that handles PHI on the business associate's behalf is itself a business associate (45 CFR 160.103), and the business associate must obtain a compliant agreement from it on the same terms (164.502(e)(1)(ii), 164.504(e)(5)). The practice's own BAA should require that flow-down explicitly so a failure to secure it is a breach the practice can act on.
What has to be in a business associate agreement?
At a minimum, the provisions listed at 45 CFR 164.504(e)(2): the permitted and required uses and disclosures, appropriate safeguards, a duty to report impermissible uses and breaches, flow-down to subcontractors, making PHI available for patient access and amendment and for an accounting of disclosures, making records available to HHS, returning or destroying PHI at termination, and authorizing the covered entity to terminate for a material breach. When electronic PHI is involved, the Security Rule adds its own terms (164.314(a)).
What happens to the data when we end the relationship with a vendor?
The agreement must require the business associate to return or destroy all the PHI it holds at termination, if feasible, and to retain no copies (45 CFR 164.504(e)(2)(ii)). Where returning or destroying the information is not feasible, the agreement's protections continue to apply to what is retained, and the business associate must limit further uses and disclosures to the purposes that make return or destruction infeasible.
Can we just use the sample agreement HHS publishes?
It is a good starting point, not a finished form. HHS publishes sample business associate agreement provisions that track the required terms, but the sample is explicitly not mandatory and is meant to be adapted to the actual arrangement between the parties — and adapted again for a business associate's contract with a subcontractor. Use it as a drafting base and confirm it fits the real relationship and any state-law requirements.
Key terms in this article
Defined once, on their own pages.
Continue learning
Where to go next.
The HIPAA Privacy Rule in Medical Billing
The permission a BAA supports — why billing is a payment use of PHI, and who counts as a business associate in the first place.
Applying the Minimum Necessary Standard in Medical Billing
The limit that governs what a practice and its business associates disclose, even when an agreement is in place.
In-House vs. Outsourced Revenue Cycle Management
The decision that creates the business-associate relationship — when billing moves to a vendor, the BAA is part of the move.
Authoritative sources
- HHS Office for Civil Rights — Business Associates (opens in a new tab)
The HHS office that administers and enforces the HIPAA rules. Its guidance explains the business-associate relationship, publishes sample business associate agreement provisions, and describes the direct liability of business associates.
- 45 CFR 164.502(e) — Disclosures to business associates: written-contract requirement (opens in a new tab)
eCFR. Requires a covered entity to obtain satisfactory assurances, documented in a written contract meeting 164.504(e), before disclosing PHI to a business associate, and requires a business associate to obtain the same from its subcontractors.
- 45 CFR 164.504(e) — Business associate contracts: required provisions (opens in a new tab)
eCFR. Sets out what a business associate agreement must contain (164.504(e)(2)), the covered entity's duty to cure or terminate on a known pattern of material breach (164.504(e)(1)), and that the same requirements apply to subcontractor contracts (164.504(e)(5)).
- 45 CFR 164.308(b) and 164.314(a) — Security Rule business associate contracts (opens in a new tab)
eCFR. The Security Rule's own written-contract requirement for electronic PHI (164.308(b)) and the provisions that contract must contain, including Security Rule compliance, subcontractor flow-down, and reporting security incidents (164.314(a)).
- 45 CFR 160.103 — Definitions (opens in a new tab)
eCFR. Defines "business associate" and "subcontractor," including the functions that create the relationship, the inclusion of subcontractors that handle PHI, and the exclusions for treatment disclosures and conduits.
