Glossary

BAA (business associate agreement)

A contract HIPAA requires between a covered entity and a vendor that handles its protected health information.

What is a business associate agreement (BAA)?

A business associate agreement, or BAA, is a written contract that HIPAA requires between a covered entity, such as a lab, and a business associate, a vendor that creates, receives, stores or sends protected health information (PHI) on its behalf.

Software, cloud hosting, billing and email providers that handle PHI are common examples of business associates.

What a BAA usually covers

  • How the vendor may use and share the PHI, and nothing beyond that.
  • The safeguards the vendor must keep in place.
  • Reporting breaches and security incidents to the covered entity.
  • Making sure the vendor's own subcontractors agree to the same terms.
  • Returning or destroying PHI when the contract ends.

A BAA does not make a vendor compliant on its own, but using a vendor that handles PHI without one is a common HIPAA problem.

This is a plain-language summary for general information, not legal advice. Check the current rules with a qualified adviser for your lab.

How Lab Desk handles it

Lab Desk signs a BAA with every US lab, and has BAAs in place with the sub-processors that handle patient data. See HIPAA at Lab Desk.

Related terms

  • HIPAA: The US law that sets national rules for protecting the privacy and security of health information.
  • PHI (protected health information): Health information that can identify a person and is held or shared by a HIPAA covered entity or its business associate.
  • UK GDPR: The UK's main data protection law, which sets rules for handling personal data, including health data.

Manage patients. Share results. Get paid. All from one desk.

Join early access and be one of the first labs on Lab Desk.