Practical reference

HIPAA BAA Review Checklist

Last verified 2026-09-28. Vendor terms and prices change; every row links to its source.

HIPAA requires every Business Associate Agreement to contain a specific set of terms, listed in 45 CFR 164.504(e)(2), plus three more that the Security Rule adds in 164.314(a). This checklist walks through them one clause at a time, with the citation for each. It keeps what the rule requires apart from what is merely commercial, such as a shorter breach notice period, cost allocation or limits on AI training, and flags the clauses vendors commonly leave out. Tick what you find in the BAA in front of you and copy the summary for your records. It is a review aid, not legal advice: have counsel review the agreement before you sign.

Check your BAA, clause by clause

Tick each term you find in the agreement. For items that start with “If”, tick them when the clause is there or does not apply to your arrangement. Each item links to the regulation paragraph or HHS page it rests on.

HIPAA requires
The regulation says the BAA must contain this. Missing it means the BAA does not meet the rule.
Recommended
Not a listed contract term, but HHS guidance or the rule's own mechanics make it worth writing down.
Negotiable
A commercial point HIPAA leaves to the parties. Worth asking for; not a compliance gap if absent.

1. Scope and permitted uses

0 of 7 ticked

  • A business associate may use PHI only as its BAA permits or the law requires, so this clause defines everything the vendor is allowed to do.

  • The only exceptions the rule allows are the vendor's own management and administration and data aggregation for your operations.

  • This is the core restriction. Without it, nothing in the contract stops uses the permitted-uses clause never mentioned.

  • The rule lets a BAA allow these uses, but disclosures for them must be required by law or made under written confidentiality assurances.

  • Applies when the vendor does work you would otherwise owe patients, such as sending notices. Tick it if the clause is there or no such work is delegated.

  • Minimum necessary already binds business associates under 164.502(b). HHS's sample BAA writes it in; 164.504(e) does not list it.

  • Vendor BAAs often cover a listed subset of products. HHS's sample lets the parties list purposes or point to a services agreement.

2. Safeguards and the Security Rule

0 of 3 ticked

  • The Privacy Rule's safeguard term. It covers PHI in any form, including paper and verbal, not only electronic records.

  • The Security Rule adds its own BAA term. Vendors are also directly liable under it, but the contract must still say so.

  • The rule requires compliance, not a list, and encryption is an addressable specification. Named controls give you something to check.

3. Incident and breach reporting

0 of 7 ticked

  • This is broader than breach reporting: it covers any use or disclosure outside the contract, whether or not it becomes a reportable breach.

  • A separate Security Rule term. The rule does not fix the format or frequency of reports, so routine failed attempts can be covered by a standing notice.

  • Both the Privacy Rule and Security Rule BAA terms tie breach reporting to 164.410, the business associate notification rule.

  • The outer limit set by 164.410(b). It binds the vendor even if the BAA is silent, and a BAA allowing longer conflicts with the rule.

  • This is how the rule starts the 60-day clock. BAAs that start it at the vendor's 'confirmation' of a breach can push notice later.

  • The rule already requires this content from the vendor. Writing it in avoids a bare 'we had an incident' email with nothing you can act on.

  • HHS's sample BAA suggests the parties decide whether the vendor handles these notices for you. Deciding in advance saves days during an incident.

4. Subcontractors

0 of 4 ticked

5. Individual rights support

0 of 4 ticked

  • If the vendor holds part of a patient's record, you cannot answer an access request on time without it.

  • A correction you accept has to reach every copy of the record, including the one in the vendor's system.

  • Patients can ask who received their PHI. Disclosures the vendor made are part of that answer.

  • You must act on an access request within 30 days (one 30-day extension allowed). HHS's sample suggests fixing the vendor's timeframes.

6. HHS access to books and records

0 of 1 ticked

  • HHS can investigate how your PHI was handled wherever it sits. This clause makes the vendor's records part of that review.

7. Termination, return or destruction of PHI

0 of 5 ticked

8. Commercial terms worth negotiating

0 of 9 ticked

Red flags

These clauses, or their absence, are worth stopping on before anyone signs. Where the rule is involved, the citation is given.

  • The BAA covers only named services, and the list does not include what you use.

    PHI that reaches an unlisted product or feature, such as a beta, an AI assistant or an add-on, sits outside the agreement.

    What to ask: Which of the products and features we use are in scope, and where is that list published and kept current?

  • The BAA is silent on subcontractors.

    Flowing the same restrictions down to subcontractors is a required term under 164.504(e)(2)(ii)(D) and 164.314(a)(2)(i)(B).

    What to ask: Do all subcontractors that handle our PHI sign BAAs with the same restrictions, and who are they?

  • The vendor reserves the right to use PHI, or data derived from it, for product improvement, analytics or model training.

    A vendor may use PHI only as the BAA permits (164.502(a)(3)). Broad improvement rights can cover uses you never intended to allow.

    What to ask: Strike or narrow the clause, and confirm in writing that our PHI and anything derived from it will not train models.

  • The breach notice period is longer than 60 days, or the clock starts when the vendor 'confirms' a breach.

    164.410(b) sets 60 calendar days after discovery as the outer limit, and 164.410(a)(2) defines discovery as the day it was or should have been known.

    What to ask: Change the period to a fixed number of days from discovery, as 164.410 defines it.

  • Termination clause with no return or destruction of PHI.

    164.504(e)(2)(ii)(J) requires return or destruction at termination if feasible, and continued protection if not.

    What to ask: Add return or destruction, a deadline, written confirmation and what happens to backups.

  • You have no right to terminate for a material breach.

    164.504(e)(2)(iii) requires the BAA to let you terminate if the vendor violates a material term.

    What to ask: Add a termination-for-cause right, with any cure period set by you.

  • The vendor can amend the BAA on its own, for example by updating a web page.

    Terms you reviewed can be narrowed later without your agreement, including scope, notice periods or data-use rights.

    What to ask: Require written agreement from both parties for changes, except those the law requires, with notice before they take effect.

  • Only breaches are reported, not security incidents or other unauthorized uses.

    The BAA must require reporting of security incidents (164.314(a)(2)(i)(C)) and of any use or disclosure the contract does not allow (164.504(e)(2)(ii)(C)).

    What to ask: How are unsuccessful attempts reported, and will successful incidents be reported individually and promptly?

  • The main agreement or online terms override the BAA, or its liability cap covers breaches of the BAA.

    A strong BAA can be undone by a precedence clause or a cap set at a few months of fees in the master agreement.

    What to ask: Add a clause that the BAA controls on PHI in a conflict, and carve BAA breaches out of the general cap.

Before you sign

  1. Map every product and feature that will touch PHI against the vendor's in-scope list, and keep PHI out of anything not on it.
  2. Read the BAA together with the main agreement and any online terms it points to: check which document controls and whether the liability cap swallows the BAA.
  3. Get every negotiated point, such as the notice period, breach costs or subcontractor list, into the signed document rather than a sales email.
  4. Keep the signed BAA, its version and the services it covers with your HIPAA documentation. The Security Rule's documentation standard sets a six-year retention period (45 CFR 164.316(b)(2)(i)).
  5. Have counsel review the BAA before you sign it. This checklist is a review aid, not legal advice.

Sources

Questions this page answers

What does HIPAA require a Business Associate Agreement to contain?

45 CFR 164.504(e)(2) requires the BAA to set the vendor's permitted uses of PHI, bar other uses, require safeguards, require reporting of unauthorized uses and breaches, flow the terms down to subcontractors, support patients' access, amendment and accounting rights, open the vendor's records to HHS, require return or destruction of PHI at termination, and let you terminate for a material breach. 45 CFR 164.314(a)(2)(i) adds Security Rule compliance, subcontractor flow-down for electronic PHI and security incident reporting. These terms are unchanged in the eCFR text current to September 24, 2026; the Security Rule changes HHS proposed in January 2025 (90 FR 898) have not been finalized.

Is 60 days the deadline for a business associate to report a breach?

It is the outer limit, not the target. 45 CFR 164.410(b) requires notice without unreasonable delay and no later than 60 calendar days after discovery, and a breach counts as discovered on the first day any employee or agent of the vendor knew or should have known of it. If the vendor acts as your agent, its knowledge can be treated as yours under 164.404(a)(2), so your own 60-day clock to notify patients may already be running. That is why many covered entities negotiate a shorter, fixed notice period.

Does HIPAA require a vendor to allow audits or share a SOC 2 report?

No. HHS's cloud computing guidance says the HIPAA Rules do not expressly require a vendor to provide documentation of its security practices or allow customer audits. You may still require audit rights, a SOC 2 Type II report or other evidence through the BAA or a service agreement, based on your own risk analysis. Treat it as a commercial point to negotiate.

Can a vendor store PHI outside the United States under a BAA?

HIPAA does not prohibit it. HHS's cloud computing guidance says offshore storage is allowed with a BAA and otherwise compliant practices, but notes that risk and enforceability can vary with location and should be covered in your risk analysis. State law, payer contracts or government programs may be stricter, so ask the vendor where PHI is stored and who can access it from where.

Do we need a BAA with a vendor that only stores encrypted PHI and has no key?

Yes. HHS's cloud computing guidance says a cloud provider that stores encrypted electronic PHI without the decryption key is still a business associate and needs a BAA. Encryption lowers the risk of the data being read, but it does not by itself cover integrity, availability or the other safeguards the Security Rule requires.

Do a vendor's subcontractors need their own BAA?

Yes. A subcontractor that creates, receives, maintains or transmits PHI for a business associate is itself a business associate under 45 CFR 160.103. The vendor must get written assurances from it that meet the same contract requirements (164.502(e)(1)(ii) and 164.504(e)(5)). You are not required to sign with the subcontractor yourself; your BAA should require the vendor to do it.