Glossary

Business Associate Agreement

A Business Associate Agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. Signing one makes the vendor a business associate — directly subject to the Security Rule and to enforcement in its own right.

What a BAA must contain

The required clauses cover permitted uses of PHI, safeguard obligations, breach reporting to the covered entity, subcontractor flow-down (your vendors’ vendors need BAAs too), and return or destruction of PHI at termination. Missing or unsigned BAAs are among the most common findings in OCR investigations — and among the easiest to remediate with a proper vendor inventory.

Related Terms

Data Processing Agreement (DPA) — A DPA is the contract governing how a processor handles personal data on a controller's behalf — required under GDPR whenever a vendor touches personal data.

Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.

Sub-processor — A sub-processor is any third party your company uses to process customer personal data — your cloud host, email provider, analytics. You must disclose them.