GlossarySecurity & compliance

HIPAA business associate agreement

A HIPAA business associate agreement (BAA) is the written contract a healthcare provider must have with any vendor that creates, receives, stores or transmits protected health information on its behalf.

  • Security & compliance
  • Updated
  • Written by the Telxpress advisory team

01 In depth

What it is, why it matters and what to ask a vendor

Under HIPAA, a business associate is a person or company that handles protected health information (PHI) for a covered entity such as a clinic, practice or care facility. The rules at 45 CFR 164.504(e) spell out what the contract must contain: permitted uses, safeguards, breach reporting, subcontractor terms and access for patients and regulators.

For a growing practice this decides which tools are allowed. A phone system that stores voicemail transcripts, an AI voice agent that books appointments, a cloud recording service: each one touches PHI and needs a signed BAA before patient data flows through it. A vendor that will not sign one is not an option, however good the product.

Ask every vendor whether they sign a BAA as standard, what it excludes, where PHI is stored and encrypted, how long recordings and transcripts are kept, and how breaches are reported. Ask who their subcontractors are, because the obligations follow the data. Review the agreement with your compliance officer or attorney.

03 At Telxpress

Where this shows up at Telxpress

The pages and articles where this term does real work: what we advise, build and support.

04 Sources

Public references

The standard or law this definition rests on, as published by its owner. Fetched and checked on the review date above.

Next step

Want This Applied to Your Business?

Book a free 30-minute AI readiness consultation. You'll leave with three AI opportunities specific to your business, whether you work with us or not.

Or call 24/7: (949) 861-4500

Last reviewed: . Published by Telxpress, Irvine, CA.