
Business Associate Agreements Under HIPAA: Regulatory Necessity and OCR Enforcement Lessons
The HIPAA Privacy Rule permits covered entities to use vendors and service providers that create, receive, maintain, or transmit protected health information (PHI). However, this permission is conditional. Federal law requires covered entities to obtain written โsatisfactory assurancesโ that such third partiesโknown as business associatesโwill appropriately safeguard PHI. These assurances must take the form of a Business Associate Agreement (BAA) that meets the regulatory requirements established by the U.S. Department of Health and Human Services (HHS).
Under 45 C.F.R. ยง 164.502(e), a covered entity may not disclose PHI to a business associate unless it first obtains these assurances in writing. The regulation is unequivocal: in the absence of a compliant BAA, disclosures of PHI to a business associate are impermissible under HIPAA, regardless of whether a breach or misuse ultimately occurs. HHS guidance further clarifies that covered entities are prohibited from sharing PHI with a business associate until such an agreement is in place. [
Required Elements of a HIPAAโCompliant Business Associate Agreement
The mandatory content of a BAA is prescribed directly by regulation at 45 C.F.R. ยง 164.504(e)(2). To satisfy the Privacy Ruleโs requirement for โsatisfactory assurances,โ a Business Associate Agreement must include the following provisions:
1. Permitted and Required Uses and Disclosures of PHI
The agreement must establish the permitted and required uses and disclosures of PHI by the business associate and may not authorize conduct that would violate the HIPAA Privacy Rule if done by the covered entity.
2. Safeguards to Protect PHI
The agreement must require the business associate to use appropriate safeguards to prevent unauthorized uses or disclosures of PHI, including compliance with the HIPAA Security Rule for electronic PHI.
3. Reporting Obligations
The business associate must be required to report to the covered entity any use or disclosure of PHI not permitted by the contract, including breaches of unsecured protected health information.
4. Subcontractor FlowโDown Requirements
The agreement must require the business associate to ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to the same restrictions and conditions.
5. Access to Records by HHS
The agreement must permit the business associate to make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with HIPAA.
6. Return or Destruction of PHI Upon Termination
Upon termination, the agreement must require the return or destruction of PHI when feasible or require continued protection of the information if destruction is not feasible.
7. Termination for Cause
The agreement must authorize the covered entity to terminate the contract if the business associate violates a material term.
If any of these elements are missing, the agreement does not meet HIPAA requirements.
OCR Enforcement and Lessons Learned
The HHS Office for Civil Rights (OCR) has repeatedly enforced the BAA requirement through resolution agreements and corrective action plans. OCR has taken the position that disclosures of PHI made in the absence of a compliant BAA violate the HIPAA Privacy Rule, even when no breach has yet occurred. OCR resolution agreements routinely require covered entities to identify all business associates, execute compliant BAAs, and implement processes to prevent disclosures of PHI without prior agreement.
HHS regulations and OCR enforcement actions make one principle unmistakably clear: a Business Associate Agreement is a prerequisite to lawful disclosure of PHI. Covered entities that fail to execute and maintain compliant BAAs expose themselves to enforcement action, corrective obligations, and significant regulatory risk. In HIPAA compliance, the existence of a valid BAA is not optional, it is required.
Colington Consulting
HIPAA Compliance, Risk Assessment & Management
Our company specializes exclusively in HIPAA compliance, with a focus on helping covered entities and business associates identify risk, implement compliant Business Associate Agreements, and align their operations with HHS and OCR regulatory expectations. Drawing on direct regulatory requirements and realโworld OCR enforcement patterns, we assist organizations with business associate identification, BAA drafting and remediation, vendor management programs, and auditโready compliance documentation. Book a free initial consultation to evaluate your current BAA posture, identify gaps that may expose your organization to enforcement risk, and outline practical, defensible steps to strengthen HIPAA compliance before issues arise.
Helping Organizations Achieve HIPAA Complianceโข