Last updated: June 3, 2026
Already a customer? A signed BAA is required before any protected health information (PHI) is stored in OnlyHIPAA and is executed automatically when your account is activated. You can download a counter-signed copy from Settings → Organization at any time.
A Business Associate Agreement (BAA) is a contract required by the HIPAA Privacy Rule (45 CFR § 164.504(e)) between a HIPAA-covered entity (or business associate) and any vendor that creates, receives, maintains, or transmits protected health information on its behalf.
The BAA legally obligates the business associate to safeguard PHI in accordance with HIPAA and limits how PHI may be used and disclosed.
You need a BAA in place with any vendor that will handle PHI on your behalf, including:
At minimum, a valid BAA must address each of the following requirements from 45 CFR § 164.504(e)(2):
The HHS Office for Civil Rights publishes sample BAA provisions you can adapt as a starting point. We strongly recommend having any BAA reviewed by qualified legal counsel before signing.
OnlyHIPAA customers can manage all of their executed BAAs - including ours - from the Business Associates page in the dashboard.
We are happy to execute our standard BAA with all customers on plans that store PHI. Our BAA covers all of the regulatory minimums above plus additional commitments around encryption, breach-notification timelines, and subprocessor management.
Need a copy before signing up? Email [email protected] and we’ll send one over.
Disclaimer. This page is provided for informational purposes only and does not constitute legal advice. The BAA template and guidance referenced here do not create an attorney-client relationship. Consult qualified legal counsel for advice specific to your situation.