HIPAA BAA Generator
Generate a HIPAA business associate agreement draft.
Enter the two parties, pick the provisions that fit the relationship, and get a ready-to-review business associate agreement built on the official HHS sample clauses. Copy it or download it, then have counsel review it. Free, private, and no email required.
The generator
Build your business associate agreement
A signed BAA addresses a contractual requirement. Each party remains responsible for the HIPAA duties that apply to its role. For a business associate subject to the Security Rule, those duties include a risk analysis, applicable safeguards, and a security awareness and training program.
The clauses in this generator follow the sample business associate agreement provisions published by the U.S. Department of Health and Human Services and the required elements of a BAA at 45 CFR 164.504(e), 164.314(a), and 164.410. Nothing you enter is sent anywhere; the document is assembled entirely in your browser. This template is educational, is not legal advice, and should be reviewed and adapted by qualified counsel before use.
What it does
Six things this BAA generator handles for you
HHS provisions
Built on the HHS sample clauses
The draft follows the structure of the sample business associate agreement provisions published by Health and Human Services and the elements at 45 CFR 164.504(e).
Fill and generate
Your names and terms, dropped in
Enter the covered entity, the vendor, the effective date, and the services. The template updates live with your details already in place.
Optional clauses
Toggle provisions after review
Management use, data aggregation, de-identification, and return-or-destroy terms are switches to align with the parties' reviewed facts and instructions from counsel.
Breach window
Set your own reporting deadline
Choose a contractual reporting period that fits the relationship. The HIPAA breach-notification rule has a 60-day outer limit, while the parties may agree to an earlier report.
Copy or download
Take it into your own document
Copy the full agreement to your clipboard or download it as a text file, then paste it into your contract template and have counsel review it.
Private by design
Nothing leaves your browser
The document is assembled entirely on your device. No account, no email, and none of the names or terms you enter are sent anywhere.
The full picture
HIPAA business associate agreements, explained
What a business associate agreement actually is
A business associate agreement documents required assurances between a covered entity and a person or entity that meets the functional business associate definition in 45 CFR 160.103. A business associate performs specified functions or services for or on behalf of a covered entity that involve protected health information. Sections 164.502(e) and 164.504(e) require written assurances and contract terms when that relationship exists, subject to the definition's exceptions.
The point of the agreement is to carry HIPAA obligations beyond the four walls of the covered entity. Protected health information does not stop being protected when it lands on a business associate's server. The BAA sets permitted uses and disclosures and assigns safeguards, reporting, subcontractor, individual-rights support, and termination duties. Business associates are also directly subject to specified HIPAA provisions. The covered entity and business associate remain responsible for the requirements that apply to their respective roles.
Who needs to sign one
The test is functional, not about job titles. An outside party that creates, receives, maintains, or transmits protected health information on a covered entity's behalf may be a business associate, subject to the regulatory definition and its exceptions. Examples can include billing and coding companies, claims processors, IT support and managed service providers, cloud hosting and storage vendors, electronic health record and practice management software companies, transcription services, answering services, document destruction companies, data analytics firms, and professional advisers that handle PHI while performing covered work.
The chain does not stop at the first vendor. A business associate that hands the same protected health information to a subcontractor must sign a BAA with that subcontractor, and that subcontractor must obtain the required assurances from any further subcontractor that handles the PHI on its behalf. Each link must agree to the restrictions, conditions, and requirements that apply to the business associate with respect to that PHI. The definition also excludes or excepts certain relationships, including treatment disclosures between providers, specified plan-sponsor arrangements, government programs whose eligibility is determined by law, workforce members, and true conduits that provide only transient transmission services. Determine the function, data handling, and any exception rather than assuming that every vendor relationship requires a BAA.
The elements the rule requires
A business associate agreement is not free-form. The implementation specifications at 45 CFR 164.504(e) spell out what the contract must contain, and the Department of Health and Human Services publishes sample provisions that map to each requirement. This generator follows those sample provisions. At a minimum, the agreement must establish the permitted and required uses and disclosures of PHI by the business associate, and it must provide that the business associate will not use or disclose the information beyond what the contract or the law allows.
From there the required terms read like a checklist of safeguards. The business associate must use appropriate safeguards and, for electronic PHI, comply with the Security Rule at Subpart C of 45 CFR Part 164. It must report to the covered entity any use or disclosure not permitted by the contract, including breaches of unsecured PHI and security incidents. It must ensure that any subcontractors agree to the same restrictions and conditions. It must make PHI available so the covered entity can meet individual rights to access, amendment, and an accounting of disclosures. It must make its internal practices, books, and records available to the Secretary of Health and Human Services for compliance reviews. And at termination it must return or destroy the PHI, or, where that is infeasible, extend the protections of the agreement to the information for as long as it is retained. Each of those obligations appears in the document this tool produces.
The optional clauses, and when to include them
Beyond the required elements, the Privacy Rule permits certain additional uses that you can choose to authorize. The generator turns these into switches so you only include what fits the relationship. The first is use for the business associate's own management and administration and to carry out its legal responsibilities. If included, the clause should require the conditions specified in 45 CFR 164.504(e)(4) for disclosures made for those purposes. The second is data aggregation, which lets a business associate combine the PHI of several covered entities to perform health care operations analyses, as permitted at 45 CFR 164.504(e)(2)(i)(B). Include it only if the vendor actually performs that service.
A third option is de-identification. A business associate may de-identify PHI under the standards at 45 CFR 164.514, and once information is properly de-identified it is no longer PHI and falls outside the agreement. Authorize this only if you want the vendor to be able to create de-identified data sets. The last switch governs what happens at termination. The strict version requires the business associate to return or destroy all PHI and keep no copies. The practical version keeps that as the default but allows the vendor to retain the information with continued protections when return or destruction is genuinely infeasible, which mirrors the language in the HHS sample. Choose the setting only after reviewing whether return or destruction is feasible for the systems, backups, and legal holds involved.
The breach reporting window
Section 164.410 requires a business associate to notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Because the covered entity has its own notice duties, the parties may choose an earlier contractual reporting period. The generator lets you set that period. Counsel should define the discovery trigger, the information required with the report, updates when facts are not yet known, and how the clause relates to security incidents and other impermissible uses or disclosures.
Documenting and maintaining required agreements
When a business associate relationship exists, an absent or inadequate agreement can violate sections 164.502(e) and 164.504(e). A generic form may omit required provisions or fail to describe the actual permitted uses and services. Identify the relationship before PHI is handled, obtain the required written assurances, and retain the executed agreement with the related service and vendor records.
Putting the agreement in place is only the first half of the job. The other half is tracking each business associate, retaining the current signed BAA, and reviewing the agreement as services, data flows, or regulations change. A vendor inventory can list each business associate, the data it handles, its agreement date, and its review status. The BAA management checklist linked below explains how to build and maintain that inventory.
Where the BAA fits next to the services contract
A business associate agreement may accompany an underlying services agreement or statement of work that describes the work, price, and commercial terms. The documents serve different purposes. The services agreement describes the service, while the BAA limits uses and disclosures of PHI and assigns required duties. Applicable privacy obligations can outlast the commercial relationship, including duties governing PHI retained after services end.
A services agreement that permits broad use of customer data can conflict with a BAA that limits use of PHI to contracted services. Counsel can address conflicts by specifying how the BAA and underlying agreement interact with respect to PHI. The generator produces a standalone draft that can be reviewed alongside the agreement governing the services.
Terms worth negotiating beyond the required elements
The required elements are the floor, not the ceiling. Organizations that handle a lot of protected health information may negotiate additional terms that the rule does not mandate but that allocate risk. Examples include responsibility for credit monitoring, forensic investigation, notification, and regulatory-response costs. A contract may also address indemnification and cyber liability insurance, subject to applicable law and the parties' commercial agreement.
Other terms worth weighing include audit rights that let the covered entity verify the vendor's safeguards, a requirement that the vendor maintain a recognized security framework or undergo independent assessments, limits on offshoring or storing data outside the country, and a clear process for approving subcontractors before they touch PHI. These terms are not HIPAA-required BAA elements, and they will not fit every relationship. Counsel can weigh them against the service, data sensitivity, applicable law, and the parties' operational capabilities.
A signed BAA is not compliance
A business associate agreement does not by itself establish compliance. It does not train a workforce, perform a risk analysis, configure safeguards, or create policies. Each party remains responsible for the HIPAA duties that apply to its role, functions, and information.
The substance behind the signature is people who know the rules. A business associate agreement commits a vendor to safeguard PHI, but it is the vendor's trained workforce that actually does the safeguarding, recognizes a phishing attempt, follows the minimum necessary standard, and reports an incident in time to matter. The same is true on the covered entity side. Role-relevant training and retrievable completion records help both parties carry out the duties in the agreement. Generate the agreement here, have counsel review it, and then document training for the people who have to honor it.
Keep going
Guides and tools that back up the agreement
Compliance
Business associate agreement guide
What a BAA is, who needs one, the required elements, and how it fits into the chain of trust between covered entities, vendors, and subcontractors.
Read the guideVendors
BAA management checklist
How to identify business associate relationships, track agreements, and review them as vendors, services, and data flows change.
Get the checklistFree tool
Notice of privacy practices generator
If you are a covered entity with an NPP duty, draft the patient-facing notice based on 45 CFR 164.520 and review the current Part 2 language.
Generate your NPPFree tool
Free HIPAA risk assessment tool
Review cited Security Rule questions and identify answers that may need follow-up. A signed BAA is one control among the duties that apply to each party.
Review safeguardsFree tool
HIPAA violation penalty calculator
Review hypothetical civil penalty ranges by culpability tier and violation count, with the current federal amounts and enforcement caveats.
Estimate exposureFree tool
HIPAA certification cost calculator
Estimate what it costs to train and certify the workforce on both sides of a BAA, so the vendor relationship rests on people who know the rules.
Estimate costFree tool
Free HIPAA practice test
Check whether your team actually understands business associate obligations with a scored practice exam and answer explanations.
Take the testFree tool
HIPAA software compliance checklist
Building software that handles PHI? Review Security Rule questions and determine whether cloud or subprocessor relationships meet the business associate definition.
Build your checklistBAA FAQ
Common questions about business associate agreements
Is this BAA generator free?
Yes. The generator is completely free, runs entirely in your browser, and needs no account or email. Fill in the parties and provisions, and the business associate agreement is assembled instantly. You can copy it or download it as a text file. None of the names or terms you enter leave your device.
What is a HIPAA business associate agreement?
A business associate agreement, or BAA, is a written contract between a covered entity and a business associate, or between a business associate and a subcontractor that is itself a business associate. The functional definition and exceptions are in 45 CFR 160.103. When that relationship exists, sections 164.502(e) and 164.504(e) require written assurances and specified terms. HHS publishes sample provisions that this generator uses as a starting point.
Who needs to sign a BAA?
A BAA is required when an outside person or entity meets the functional business associate definition in 45 CFR 160.103 by performing a listed function or service for or on behalf of a covered entity that involves PHI, unless an exception applies. Treatment disclosures between providers, certain plan-sponsor arrangements, government programs with eligibility determined by law, and true conduits can be outside the definition. A business associate must obtain the required written assurances from a subcontractor that creates, receives, maintains, or transmits PHI on its behalf.
Is a generated template legally sufficient on its own?
Treat the output as a starting point, not a finished contract. The clauses track HHS sample provisions, but the parties must first determine that a business associate relationship exists and then adapt the agreement to the facts. Counsel may recommend provisions on indemnification, insurance, incident costs, review rights, state law, or the underlying services agreement. Have qualified counsel review the document before signature.
How fast must a business associate report a breach?
Under 45 CFR 164.410, a business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI. The parties may agree to an earlier contractual period. The generated clause also addresses uses or disclosures not permitted by the agreement and security incidents, which have related but distinct reporting language in the HHS sample provisions. Counsel should tailor the trigger, information required, and timing.
Does signing a BAA make us HIPAA compliant?
No. A signed BAA addresses a contractual requirement when a business associate relationship exists. It does not train a workforce, perform a risk analysis, configure safeguards, or create policies and procedures. Each party still has the HIPAA duties that apply to its role. Document applicable training and other compliance work separately.
A signed agreement is the start, not the finish. Back it up with HIPAA certification or plan a team rollout for your whole workforce.
Paper plus people