Remedora
Start building
Remedora
Start building
ARTICLE

What Is a BAA? Business Associate Agreements, Explained for Operators

A plain-English guide to business associate agreements: who needs a BAA, what the contract must contain, what enforcement costs, and a checklist to run before you sign.

RRemedoraRemedora Editorial
August 8, 2026 8 min read
ARTICLE

What Is a BAA? Business Associate Agreements, Explained for Operators

A plain-English guide to business associate agreements: who needs a BAA, what the contract must contain, what enforcement costs, and a checklist to run before you sign.

RRemedoraRemedora Editorial
August 8, 2026 8 min read

A BAA, or business associate agreement, is the contract HIPAA requires before a vendor can handle protected health information on your behalf. If you run a telehealth or D2C health brand, you will sign more of them than you expect. The ones you skip are the ones a regulator asks about first.

This guide covers the definition, who needs one, what the contract must contain, what enforcement has cost companies that got it wrong, and a checklist to run before you sign. It is not legal advice. If you just need the one-paragraph version, our glossary entry has it.

What a business associate agreement is

HIPAA’s Privacy Rule, at 45 CFR 164.502(e), bars a covered entity from sharing PHI with a service provider unless it first obtains written assurances that the provider will safeguard the data. Those written assurances are the BAA. A companion section, 164.504(e), spells out the terms the contract must include, and HHS publishes sample provisions you can compare any vendor’s paper against.

The plain version: HIPAA only binds certain organizations directly. The BAA extends HIPAA’s obligations down the vendor chain by contract, so the intake tool, the hosting provider, and the help desk are all on the hook for the patient data they touch.

Two things a BAA is not. It is not a certification: nobody stamps a company “HIPAA compliant” by signing one. And it is not a substitute for the vendor actually securing the data. It is a contract that makes the obligation enforceable and assigns liability when something breaks.

Since the 2013 Omnibus Rule, business associates are also directly liable under HIPAA, BAA or not. That change cuts both ways for operators: your vendors carry their own regulatory exposure, and if your company handles PHI for a covered entity, so do you.

Who needs a BAA: covered entities vs business associates

Covered entities

HIPAA defines three types: health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically for covered transactions. In a D2C telehealth setup, the medical group whose clinicians see your patients is the covered entity. So is the pharmacy filling the prescriptions.

Business associates

A business associate is any person or company that creates, receives, maintains, or transmits PHI on behalf of a covered entity or another business associate. HHS’s business associate guidance lists examples, and for an e-commerce health brand the roster is longer than the org chart suggests: the telehealth platform, the intake form tool, the e-prescribing network, the cloud host, the help desk software, the email and SMS provider, the billing system, and any analytics tool that sees patient-level data.

Subcontractors count too. If your platform vendor uses a transcription service that touches PHI, that service needs its own BAA with the vendor. The obligation flows all the way down the chain.

Where your brand sits

Most D2C brands are not covered entities themselves. Depending on how the entities are structured, the brand company typically acts as a business associate of its affiliated medical group. That is a question for your healthcare attorney, and the answer shapes who signs what. The operational point holds either way: every vendor in the PHI path needs paper, and someone at your company needs to know where all of it is.

Who will not sign one

Ad platforms, mostly. Meta does not sign BAAs. Google signs them for Workspace and Cloud, but not for Analytics or its ad products. So PHI cannot lawfully flow to those tools, a point OCR underlined in its December 2022 bulletin on online tracking technologies. The practical fix is architectural: pixels and ad integrations should receive conversion events, never intake answers or diagnoses.

What a BAA must contain

The required terms come from 45 CFR 164.504(e). A real BAA must:

  • Define permitted uses and disclosures: what the vendor may do with PHI, which is only what the contract and the law allow.
  • Require safeguards: including compliance with the Security Rule for electronic PHI.
  • Require breach and incident reporting: the vendor must report security incidents and breaches of unsecured PHI to you. The regulation allows up to 60 days for breach reports; competent vendors agree to days, not weeks.
  • Flow down to subcontractors: anyone the vendor hands PHI to must accept the same restrictions in writing.
  • Support individual rights: patients can request access, amendments, and an accounting of disclosures, and the vendor has to make that possible.
  • Open the books to HHS: the vendor must make its practices and records available to regulators.
  • Handle termination: return or destroy PHI when the contract ends, where feasible, and let you terminate if the vendor materially violates the agreement.

That is the regulatory floor. The clauses that decide who pays for a breach live above it: indemnification, audit rights, liability caps, and a current subcontractor list. HIPAA does not require any of those. Your finance model does.

What missing BAAs have cost: the penalty context

Civil penalties under HIPAA are tiered by culpability, from violations the organization could not reasonably have known about up to willful neglect left uncorrected. The dollar figures adjust for inflation each year, and the annual caps at the top tier run to seven figures per provision violated.

The enforcement record makes the point better than the fee schedule. In 2016, OCR settled with Raleigh Orthopaedic Clinic for $750,000 after the practice handed X-ray films containing PHI of roughly 17,300 patients to a vendor with no BAA in place. The same year, North Memorial Health Care of Minnesota paid $1.55 million after a breach traced back to a contractor it had never signed a BAA with. Also in 2016, OCR reached its first settlement directly with a business associate, Catholic Health Care Services of Philadelphia, for $650,000 after a stolen phone exposed nursing home residents’ data.

Notice the pattern: OCR treated the missing contract as a violation in its own right, separate from the breach that exposed it. When OCR investigates, the BAA is one of the first documents requested. “We were about to sign it” has no cash value.

The multi-vendor problem: BAA sprawl vs one-BAA platforms

Count the BAAs in a typical D2C telehealth stack built from point solutions: intake forms, video, EHR, e-prescribing, pharmacy, payments where PHI attaches, help desk, email and SMS, hosting. That is six to ten agreements, and each one carries its own negotiation, its own subcontractor chain to trace, its own breach-notification clock, its own renewal date, and its own security contact to chase when something looks wrong. When an incident spans two vendors, the evidence does too.

Sprawl is not automatically wrong. Large teams with legal and security staff manage it on purpose. But each BAA is ongoing overhead, not one-time paperwork, and the burden lands hardest on small teams at exactly the moment they are trying to launch.

This is the case for consolidating onto a HIPAA-compliant telehealth platform that covers the whole care path under a single agreement. Remedora runs storefront, funnels, intake, licensed providers in all 50 states plus Puerto Rico, e-prescribing, pharmacy fulfillment, payments, and support under one BAA, from $200 a month. One agreement to negotiate, one subcontractor chain to review, one clock when something goes wrong. Marketing tools that never touch PHI, like your ad platforms or Triplewhale, stay outside the boundary and need no BAA at all, provided the data flows are designed that way.

BAA checklist: before you sign

Run this against any BAA that lands on your desk:

  • Match the contract to the services: confirm every product you are buying is named as covered. Vendors sometimes scope the BAA to one module and leave the rest bare.
  • Check the subcontractor clause: ask for the current subcontractor list and for notice when it changes.
  • Read the breach clock: 60 days is the regulatory ceiling, not a norm. Push for notification in days.
  • Confirm Security Rule language: the vendor should commit to the Security Rule for electronic PHI, not to vague “industry-standard security.”
  • Look at termination and data return: know how you get patient data out if you leave, in what format, and on what timeline.
  • Check the liability cap: many vendors cap liability at a few months of fees. A real breach costs more. Negotiate or price the gap.
  • Log it: signed copy, effective date, renewal date, and an owner on your team. Your HIPAA compliance plan should include a register of every BAA in force.

Ten minutes with this list before signing beats ten weeks of cleanup after a breach.

FAQ

Is a BAA legally required?

Yes. A covered entity that shares PHI with a vendor without one is violating the Privacy Rule even if no breach ever happens. Raleigh Orthopaedic’s $750,000 settlement was for exactly that.

Does signing a BAA make my brand HIPAA compliant?

No. The BAA is one required piece. Compliance also depends on safeguards, access controls, training, risk analysis, and the rest of a working HIPAA compliance plan.

Who signs the BAA in a D2C telehealth business?

Typically the covered entity, usually your affiliated medical group, signs with each business associate, and business associates sign with their own subcontractors. Your corporate structure determines where your brand entity sits in that chain, so confirm it with counsel.

Can a vendor refuse to sign a BAA?

Yes, and the refusal is your answer. If a tool will touch PHI and the vendor will not sign, you either keep PHI out of that tool entirely or you drop it.

Keep going with the glossary definition of a business associate agreement, the guide to choosing a HIPAA-compliant telehealth platform, and the walkthrough for building a HIPAA compliance plan.

Ready to build yours?Storefront, doctors, pharmacy, and payments are already wired together. Start building today
R RemedoraRemedora EditorialRemedora is the all-in-one telehealth platform for e-commerce health brands: storefront, intake, licensed providers, pharmacy, and payments in one system.

Keep reading

All articles →
Remedora pill mascot

Launch your telehealth brand
this week.

Storefront, doctors, pharmacy, payments, and compliance, included and ready. The only thing missing is your brand.

LegitScript Certified
HIPAA COMPLIANT · BAA
© 2026 Remedora Inc.