Get Demo
↑

HIPAA Business Associate Agreement (BAA): Template Outline and Checklist

BAA checklist mapped to 45 CFR 164.308(b), 164.314(a), and 164.504(e) — plus post-HITECH direct BA liability.

Published: September 2026 Compliance · HIPAA 8–12 min read

A Business Associate Agreement (BAA) is how covered entities obtain satisfactory assurances from vendors that create, receive, maintain, or transmit PHI on their behalf. This page gives a template outline and checklist — not legal advice. Have counsel finalise language for your jurisdiction and use case.

Related: HIPAA hub · CE vs BA · Offshore BPO.

BAA — Covered entities must obtain satisfactory assurances via a Business Associate Agreement (see 45 CFR 164.308(b), 164.314(a), 164.504(e)). After HITECH / 2013 Omnibus, business associates are directly liable for Security Rule, certain Privacy Rule provisions, and Breach Notification Rule compliance.

HITECH Act (2009) — Strengthened HIPAA with statutory breach-notification duties, higher civil monetary penalties, and direct business-associate liability (implemented via the 2013 Omnibus Rule), alongside EHR/incentive programme context.

BAA Checklist

Template Outline (Headings)

  1. Definitions (PHI, ePHI, Breach, Designated Record Set)
  2. Obligations of Business Associate
  3. Obligations of Covered Entity
  4. Permitted Uses and Disclosures
  5. Security Safeguards and Reporting
  6. Subcontractors
  7. Term, Termination, and PHI Disposition
  8. Regulatory References (164.308(b), 164.314(a), 164.504(e))

No downloadable Word/PDF is attached. Request a working session via contact if you want CyberSilo to help operationalise BA registers in CSA.

How CyberSilo Helps

Operationalise BAAs, Don’t Just Sign Them

Track every BA relationship, flow-down, and incident reporting path next to Security Rule evidence.

Frequently Asked Questions

Is a BAA required?

Covered entities must obtain satisfactory assurances via BAAs for business associate relationships (see 164.308(b), 164.314(a), 164.504(e)).

Are business associates directly liable?

Yes. After HITECH / 2013 Omnibus, business associates are directly liable for Security Rule, certain Privacy Rule provisions, and Breach Notification Rule compliance.

Can we use a vendor’s standard BAA?

Often yes for cloud providers, but counsel should review scope, subprocessors, and breach reporting language against your risk profile.

HIPAA hub · Cloud BAAs · Penalties · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!