MAKE THE DOCUMENT WORK FOR YOUR SITUATION
About this hipaa business associate agreement review draft
Build a BAA review draft with permitted PHI use, safeguards, breach reporting, subcontractors, individual-rights support, HHS access, and termination. This editable template brings the key details into one document: services, phi & permitted use, security, incidents & subcontractors, individual rights & oversight, term, termination & data disposition. Complete it online, compare the live preview with your records, and download a blank or completed PDF or editable Word document.
What the template includes
The online builder and downloaded documents use the same fields. A selected state can add relevant research prompts. Complete only applicable items; add explanations for exceptions rather than assuming a blank entry resolves them.
Document details4 inputs +
Set the date, jurisdiction, and your internal reference.
- Document date *
- US state *
- County
- Document reference
People & organizations8 inputs +
Use legal names and current contact information.
- Covered entity or upstream business associate legal name *
- Covered entity or upstream business associate address *
- Covered entity or upstream business associate email
- Covered entity or upstream business associate phone
- Business associate legal name *
- Business associate address *
- Business associate email
- Business associate phone
Services, PHI & permitted use11 inputs +
Document the actual service and data flow, not a generic compliance promise.
- Underlying service agreement *
- Services involving PHI *
- PHI categories and data subjects *
- Systems, locations, and data flow *
- Permitted uses and disclosures *
- Prohibited uses including secondary use *
- Minimum necessary controls
- Any specifically permitted data aggregation
- De-identification permissions or restrictions
- Covered entity privacy contact *
- Business associate security contact *
Security, incidents & subcontractors10 inputs +
Contractual notice targets must not exceed applicable legal deadlines.
- Administrative, physical, and technical safeguards *
- Electronic PHI Security Rule responsibilities *
- Incident and breach definitions for review *
- Negotiated report deadline and trigger *
- Initial notice content and updates *
- Investigation, mitigation, and evidence preservation
- Subcontractor list and approval process *
- Equivalent downstream agreement requirements *
- Data location and cross-border restrictions
- Logging and evidence retention
Individual rights & oversight6 inputs +
Specify handoff contacts and response periods for each request.
- PHI access request support and timing *
- Amendment support and incorporation *
- Disclosure accounting support *
- Covered entity Privacy Rule duties delegated
- HHS access to relevant books and records *
- Contract audit and remediation arrangements
Term, termination & data disposition8 inputs +
Identify backups and legal retention that can affect return or destruction.
- Agreement term *
- Material breach cure and termination rights *
- PHI return or destruction on termination *
- If return or destruction is infeasible
- Backup deletion timetable
- Surviving restrictions
- Insurance and liability arrangements for counsel
- Precedence over service agreement
Additional details & signing7 inputs +
Add attachments, exceptions, and the names of authorized signers.
- Attachments / supporting records
- Exceptions / additional terms
- First signer printed name
- First signer title
- Second signer printed name
- Second signer title
- Signing date
How to complete it
1. Document details
Set the date, jurisdiction, and your internal reference. Review document date, us state, county, document reference against your source records.
2. People & organizations
Use legal names and current contact information. Review covered entity or upstream business associate legal name, covered entity or upstream business associate address, covered entity or upstream business associate email, covered entity or upstream business associate phone and the remaining details against your source records.
3. Services, PHI & permitted use
Document the actual service and data flow, not a generic compliance promise. Review underlying service agreement, services involving phi, phi categories and data subjects, systems, locations, and data flow and the remaining details against your source records.
4. Security, incidents & subcontractors
Contractual notice targets must not exceed applicable legal deadlines. Review administrative, physical, and technical safeguards, electronic phi security rule responsibilities, incident and breach definitions for review, negotiated report deadline and trigger and the remaining details against your source records.
5. Individual rights & oversight
Specify handoff contacts and response periods for each request. Review phi access request support and timing, amendment support and incorporation, disclosure accounting support, covered entity privacy rule duties delegated and the remaining details against your source records.
6. Term, termination & data disposition
Identify backups and legal retention that can affect return or destruction. Review agreement term, material breach cure and termination rights, phi return or destruction on termination, if return or destruction is infeasible and the remaining details against your source records.
7. Additional details & signing
Add attachments, exceptions, and the names of authorized signers. Review attachments / supporting records, exceptions / additional terms, first signer printed name, first signer title and the remaining details against your source records.
Practical tips
- A signed BAA alone does not establish HIPAA compliance.
- HHS sample clauses address HIPAA concepts; ordinary contract terms and state law still require review.
Before signing or submitting
This is a planning and attorney-review draft, not an execution-ready statutory form. It has not been reviewed by a lawyer. State law can require particular wording, notices, witnesses, notarization, capacity, disclosures, or court procedures. Use the linked official form when appropriate and obtain jurisdiction-specific review before signing.