Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.

In this lesson, we'll go over what a Business Associate Agreement (BAA) is, when it is required, what key provisions must be included in the contract, and the specific compliance obligations required for business associates.

What is a Business Associate Agreement (BAA)?

A Business Associate Agreement is a mandatory contract between a covered entity and a business associate who creates, receives, maintains, or transmits Protected Health Information (PHI) or electronic PHI (ePHI) to perform a service on behalf of the covered entity.

Key Elements of a BAA

A BAA explicitly details how both entities are legally responsible for handling sensitive patient information, including protocols for:

  • Mandatory workforce compliance training
  • Periodic risk assessments
  • Financial liabilities and regulatory oversight
  • Responsibilities and reporting procedures in the event of a data breach

Pro Tip: Enforcing Legal Accountability: A signed BAA is legally required and holds business associates directly accountable under federal law to handle all PHI and ePHI safely and securely.

Compliance Obligations for Business Associates

In addition to signing a BAA, business associates are legally required to establish and maintain their own comprehensive compliance programs, which must include:

  • Risk Analysis: Conducting thorough risk assessments to identify potential vulnerabilities to PHI.
  • Staff Training: Providing regular, documented HIPAA compliance training to all employees.
  • Book of Evidence: Maintaining customized policies, procedures, and documentation compiled in a central Book of Evidence.