A customer is asking us to sign a BAA

If you handle their patient data, you need one. Review it carefully before signing.

  1. 1

    Determine if you qualify as a Business Associate

    If your product or service involves creating, receiving, maintaining, or transmitting protected health information on behalf of a covered entity — you are a Business Associate and must sign a BAA.

  2. 2

    Review the BAA they have sent

    Check for: what PHI you are permitted to use, breach notification timelines, subcontractor requirements, and termination provisions. Have legal counsel review if it is your first BAA.

  3. 3

    Negotiate terms if needed

    BAAs are negotiable. If their breach notification requirement is 24 hours and you cannot operationally meet that, negotiate for a longer timeline.

  4. 4

    Sign and file the BAA

    Keep a copy of every signed BAA. HIPAA requires you to retain BAAs for 6 years. Store them somewhere secure and searchable.

Important

Use our free BAA Generator to create your own compliant BAA template, or to understand what a BAA you have received should contain.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.