Skip to content
English
  • There are no suggestions because the search field is empty.

Business Associate Agreements (BAAs): What They Are and When We Sign One

A plain-English explanation of BAAs and when one is needed.

If you work in healthcare, you've probably encountered the term BAA. If you haven't, here's the plain-English version: a Business Associate Agreement is a contract that HIPAA requires whenever one organization handles protected health information (PHI) on behalf of another. This article explains what it is and when it comes into play with us.

What a BAA actually does

Under HIPAA, a healthcare organization (a "covered entity") that lets a vendor handle PHI must have that vendor sign a BAA. The agreement is essentially a formal promise: the vendor commits to protecting the PHI according to HIPAA's rules, spells out how the data may and may not be used, and establishes accountability if something goes wrong. It's how the chain of responsibility for sensitive health data stays intact as that data moves between organizations.

Why it exists

The logic is straightforward. Protected health information is exactly that, protected, and HIPAA doesn't want that protection to evaporate the moment data is handed to a vendor. The BAA ensures everyone who touches PHI is contractually bound to the same standard of care, so responsibility follows the data rather than stopping at the first organization's door.

When BrightReach signs one

If your work with us involves PHI, and you're a covered entity or otherwise subject to HIPAA, a BAA is part of doing it properly, and we'll handle it. If your work doesn't involve PHI, a BAA generally isn't necessary. We'll help you figure out which situation you're in; it comes down to whether protected health information is actually flowing through the systems we're working on.

BAAs with the platforms too

It's not just us. When PHI lives in a platform like HubSpot, a BAA with that platform is part of the picture as well. HubSpot offers a BAA for eligible customers, and it activates as part of properly enabling the platform's sensitive-data features, an important detail we cover in "How HubSpot Supports HIPAA Compliance." Getting all the BAAs in place, with us and with the platforms, is part of building a genuinely compliant setup.

The bottom line

A BAA isn't red tape, it's the mechanism that keeps sensitive health data protected as it moves between organizations. If your engagement involves PHI, we treat the BAA as a normal, necessary part of the work, not an obstacle. And if you're unsure whether you need one, just ask; we'd rather sort it out clearly up front than leave any ambiguity around something this important.