A BAA containing every provision §164.504(e) requires, in two versions: covered entity to BA, and BA to subcontractor.
What is in the download
- Format: DOCX
- Length: 9 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the template
Two complete agreements, because the direction of the relationship changes the drafting. The covered-entity-to-business-associate version is what a practice or health plan sends its vendors; the business-associate-to-subcontractor version is what a health-tech company sends its own downstream providers, carrying the flow-down obligation of §164.308(b) all the way down the chain.
Each version contains the full set of provisions §164.504(e) requires: definitions aligned to the regulatory text; permitted and required uses and disclosures; the safeguards commitment covering Security Rule compliance for ePHI; breach and security incident reporting with a fill-in reporting window; subcontractor flow-down; support for individual access and amendment rights and accounting of disclosures; availability of books and records to HHS; return or destruction of PHI at termination, with the infeasibility fallback; and termination-for-breach rights. Margin notes flag which clauses are regulatory minimums and which are negotiable business terms, and the completed example shows a filled agreement between a fictional clinic and its hosting provider so you can see what sensible answers look like.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
For a contract template, step two translates to: do not promise operational behaviour that will not happen. If the agreement says you report security incidents within five business days, your incident response process needs to actually route vendor-relevant incidents that fast.
How to customise it
Three decisions do most of the work. First, the breach reporting window: the regulation allows business associates up to 60 days, which is far too slow for the party whose own notification clock is running — as the covered entity, negotiate this down and write the number in; as the business associate, commit to what your process can genuinely deliver. Second, the data-handling terms at termination: think through whether return in usable form is actually possible for this vendor’s service before signing a clause that assumes it. Third, permitted uses: strike or deliberately accept any language granting the vendor rights to de-identified or aggregated data — that is a commercial decision, not boilerplate. Beyond those, fill in the parties and governing law, and have counsel review the result; this template gives you a sound structure, not legal advice for your situation.
Common mistakes
- Sending it and not chasing the signature. An unsigned BAA is not a BAA. Track outstanding signatures in your vendor register with the same discipline as invoices.
- Signing the vendor’s version without reading it. Large vendors will insist on their paper, which is usually fine — but check the reporting window and the termination terms rather than assuming parity with this template.
- Using the wrong direction. Health-tech companies routinely sign the covered-entity version with their own subcontractors, leaving obligations pointing the wrong way.
- Treating the signature as diligence. A BAA transfers obligations, not competence — pair it with a proportionate security review, as covered in the vendor management guide.
- Losing the signed copy. Six-year retention applies. A register with links to executed copies turns audit requests from an excavation into an export.
Related templates
The BAA is one artefact in the vendor workflow. The risk assessment template is where vendor-held ePHI gets scoped and scored, the annual review checklist includes the yearly BAA register check, and the full policy set contains the vendor management policy this agreement operationalises. For the reasoning behind every clause, the BAA guide walks the requirements provision by provision.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.