Last updated: March 1, 2025
Already a customer? A signed BAA is required before any protected health information (PHI) is stored in HIPAA Sherpa, and the platform enforces it: evidence uploads, assessment answers, and the rest of the regulated surface stay blocked until the agreement is executed by both parties. Sign it, send it to your own signatory, or upload your own paper for us to countersign, from your BAA page. A countersigned copy is available there for your records.
A Business Associate Agreement (BAA) is a contract required by the HIPAA Privacy Rule (45 CFR § 164.504(e)) between a HIPAA-covered entity (or business associate) and any vendor that creates, receives, maintains, or transmits protected health information on its behalf.
The BAA legally obligates the business associate to safeguard PHI in accordance with HIPAA and limits how PHI may be used and disclosed.
You need a BAA in place with any vendor that will handle PHI on your behalf, including:
At minimum, a valid BAA must address each of the following requirements from 45 CFR § 164.504(e)(2):
The HHS Office for Civil Rights publishes sample BAA provisions you can adapt as a starting point. We strongly recommend having any BAA reviewed by qualified legal counsel before signing.
HIPAA Sherpa customers can manage all of their executed BAAs - including ours - from the Business Associates page in the dashboard.
We are happy to execute our standard BAA with all customers on plans that store PHI. Our BAA covers all of the regulatory minimums above plus additional commitments around encryption, breach-notification timelines, and subprocessor management.
Need a copy before signing up? Email [email protected] and we’ll send one over.
Disclaimer. This page is provided for informational purposes only and does not constitute legal advice. The BAA template and guidance referenced here do not create an attorney-client relationship. Consult qualified legal counsel for advice specific to your situation.