Business Associate Agreement (BAA)

A Business Associate Agreement (BAA) is a HIPAA-required contract that governs how a business associate may use, disclose, safeguard, and report on protected health information handled for a covered entity.

A covered entity may need a BAA when another organization performs a service involving PHI on its behalf. Business associates may also need equivalent agreements with subcontractors that handle that PHI. Whether an agreement is required depends on the parties' roles and the service, not on what a vendor calls its product.

A BAA commonly defines permitted uses and disclosures, required safeguards, incident and breach reporting, support for the covered entity's obligations, subcontractor requirements, and what happens to PHI when the relationship ends. The agreement allocates responsibilities, but it does not replace the privacy and security work needed to meet them.

What to review for an AI phone agent

Before sending PHI through a phone agent, a healthcare organization should map every service that can receive it. The path may include telephony, audio processing, transcripts, summaries, integrations, storage, monitoring, and human support. The contractual chain and the technical data flow should match; a BAA with one vendor does not cover an unrelated service that receives the same information.

The review should be specific about data types and purposes. It should address who can access call artifacts, how security incidents are reported, which subcontractors are involved, how long data remains available, and how deletion or return works at termination. If the workflow changes—for example, by adding an integration or retaining transcripts longer—the organization should reassess both the agreement and the operating controls.

A BAA is not a compliance certificate

Signing a BAA does not make an organization or call flow “HIPAA certified,” and it does not authorize every use of PHI. A poorly configured agent can still request unnecessary information, disclose details to the wrong person, send PHI to an unapproved destination, or retain records beyond policy. The covered entity and business associate must each perform their assigned responsibilities.

Procurement teams should confirm that the executed agreement covers the actual service and legal entities in use. Privacy and security teams should then verify that prompts, identity checks, permissions, integrations, retention, and incident procedures implement the arrangement in practice.

Related terms