Healthcare Contracts & HIPAA: A Plain-English Guide
Understand HIPAA Business Associate Agreements, healthcare vendor contracts, and the compliance requirements every covered entity and business associate needs to know.
Generate a services agreement in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
Why Healthcare Contracts Are Different
Every industry has legal documents, but healthcare contracts carry a layer of regulatory obligation that most don't. When PHI — Protected Health Information — flows between organizations, federal law requires specific written agreements before that exchange can happen. Get those contracts wrong, skip them entirely, or fail to update them when vendors change, and the consequences land fast: six-figure fines, corrective action plans, and the kind of press coverage no healthcare organization wants.
This guide breaks down the contracts HIPAA requires, who needs them, what every key clause must cover, and what happens when something goes wrong.
The HIPAA Foundation: Who It Applies To
HIPAA (the Health Insurance Portability and Accountability Act, enacted in 1996 and significantly expanded by the HITECH Act in 2009) creates a two-tier framework of regulated entities.
Covered Entities
Covered entities are the organizations HIPAA regulates directly:
- Health plans: health insurance companies, HMOs, Medicare, Medicaid, employer-sponsored group health plans
- Healthcare clearinghouses: entities that process non-standard health information into standardized formats
- Healthcare providers: any provider that transmits health information in electronic form — hospitals, clinics, physician practices, dentists, pharmacies, nursing homes, labs
If you're a covered entity, HIPAA's Privacy Rule (45 CFR Parts 160 and 164, Subparts A and E) and Security Rule (Subparts A and C) apply to everything you do with PHI.
Business Associates
The category that catches more organizations off guard: business associates are vendors, contractors, and subcontractors that create, receive, maintain, or transmit PHI on behalf of a covered entity. The HITECH Act (2009) extended direct HIPAA liability to business associates — they're no longer just contractually bound, they're independently regulated.
Common business associates include:
| Type | Examples |
|---|---|
| Technology vendors | EHR platforms, patient portals, cloud storage, IT support |
| Administrative services | Medical billing and coding companies, claims processors |
| Professional services | Law firms with PHI access, accountants, consultants |
| Infrastructure | Data backup providers, email hosting, managed security services |
| Clinical services | Lab testing companies, pharmacy benefit managers, transcription services |
If your organization falls into any of these categories and you handle PHI for a covered entity, you are a business associate — and you need BAAs with each covered entity you serve, plus downstream BAA agreements with any subcontractors you bring in.
The Business Associate Agreement (BAA): HIPAA's Core Required Contract
A Business Associate Agreement is the written contract that HIPAA mandates between covered entities and their business associates. Under 45 CFR § 164.504(e), a BAA must exist before any PHI changes hands — not after the relationship starts, not when someone flags it in an audit.
What a Compliant BAA Must Include
The HHS Office for Civil Rights (OCR) is specific about what a BAA needs to cover:
1. Permitted Uses and Disclosures
The BAA must define exactly what the business associate is and isn't allowed to do with PHI. This should match the service being provided — a billing company can use PHI for billing functions; it cannot use that same PHI for its own marketing. Any uses beyond what the covered entity authorizes are prohibited.
2. Appropriate Safeguards
The business associate must implement safeguards to prevent uses and disclosures beyond what's permitted. For electronic PHI (ePHI), this means compliance with the full HIPAA Security Rule — administrative safeguards (policies, workforce training, access management), physical safeguards (facility access controls, workstation security), and technical safeguards (encryption, audit controls, automatic logoff, user authentication).
3. Breach Reporting
This is one of the most operationally important clauses. The BAA must require the business associate to notify the covered entity of any breach of unsecured PHI without unreasonable delay and no later than 60 days from discovery. The notification must include, to the extent possible:
- The identities of affected individuals
- A description of what happened and what PHI was involved
- Steps the business associate is taking to investigate and mitigate
The 60-day limit runs from the date the business associate discovers the breach — not the date it reports it. Covered entities need that notice quickly, because their own notification obligations (to individuals and to HHS) also carry a 60-day clock.
4. Subcontractor Flow-Down
If the business associate uses subcontractors that handle PHI, those subcontractors must execute their own BAAs with the business associate. The liability chain has to be complete — a subcontractor breach is traceable back to the business associate that failed to get a proper agreement in place.
5. Individual Rights Assistance
When a patient exercises their HIPAA rights — requesting access to their records, asking for an accounting of disclosures — the covered entity may need the business associate's help to respond. The BAA must require the business associate to cooperate with those requests in a timely way.
6. Audit and Inspection Rights
The covered entity (and HHS, in an investigation) must be able to verify the business associate's HIPAA compliance. The BAA should give the covered entity the right to inspect the business associate's books, records, and systems relevant to PHI handling.
7. Termination Provisions and PHI Disposition
If the business associate materially breaches the BAA, the covered entity should be able to terminate the agreement. On termination — or at contract end — the business associate must return or destroy all PHI it holds. If return or destruction isn't feasible (because PHI is embedded in a system that can't be easily purged), the business associate must extend the BAA's protections indefinitely to that remaining data.
The Minimum Necessary Standard
Even within permitted uses, HIPAA's minimum necessary standard (45 CFR § 164.502(b)) applies. Business associates should access, use, and disclose only the minimum amount of PHI reasonably necessary to accomplish the permitted purpose. This principle should be reflected in how the BAA describes permitted uses — not just "for billing purposes" but with enough specificity to prevent scope creep.
Beyond the BAA: Other Healthcare Contracts That Matter
The BAA is HIPAA's headline contract requirement, but healthcare organizations rely on a broader ecosystem of agreements.
1. Healthcare Services Agreement
A services agreement between a healthcare organization and a vendor covers the commercial relationship — scope of services, fees, deliverables, SLAs, intellectual property, and liability. When PHI is involved, the BAA usually operates as an addendum to the services agreement rather than a standalone document. The two agreements together define both the business relationship and the HIPAA compliance obligations.
Create a services agreement with Pactlio →
2. Non-Disclosure Agreement (NDA)
Healthcare NDAs serve the same purpose as any NDA — protecting confidential information — but the definition of confidential information must be drafted carefully. PHI has its own separate regulatory framework under HIPAA, and an NDA shouldn't create confusion about which protections apply to which data. A well-drafted healthcare NDA distinguishes between general business confidential information and PHI, notes that PHI is governed by the BAA, and avoids any language that might inadvertently create a broader or narrower protection than HIPAA requires.
3. Independent Contractor Agreement for Healthcare
Healthcare organizations frequently engage contractors — locum tenens physicians, traveling nurses, IT consultants, medical coders. When those contractors access PHI as part of their work, they qualify as business associates and need a BAA. The contractor agreement itself should define scope, compensation, compliance obligations, and IP ownership. One important distinction: contractors who provide services to patients under the direction of the covered entity (like a physician providing treatment) are typically treated as part of the covered entity's workforce for HIPAA purposes and don't need a BAA — but this distinction turns on the specific facts of the arrangement.
4. Data Use Agreement (DUA)
A DUA is required under HIPAA when a covered entity shares a Limited Data Set — PHI that has been partially de-identified but still includes certain date elements and geographic information. Limited Data Sets are often used in research and public health contexts where full de-identification would make the data less useful. The DUA must restrict how the recipient uses the data, require appropriate safeguards, prohibit re-identification, and prevent disclosure to unauthorized parties.
HIPAA Enforcement: What the Penalties Look Like
The HHS Office for Civil Rights enforces HIPAA through investigations, audits, and corrective action plans. OCR has dramatically increased enforcement activity since the HITECH Act created a mandatory audit program and strengthened penalties.
Civil Penalties (2024 Adjusted Figures)
| Culpability | Per Violation | Annual Cap Per Category |
|---|---|---|
| Did not know | $141 – $28,282 | $28,282 |
| Reasonable cause | $1,414 – $28,282 | $85,085 |
| Willful neglect (corrected) | $14,141 – $71,162 | $713,040 |
| Willful neglect (not corrected) | $71,162 | $2,134,831 |
Operating without a required BAA — particularly after a breach — is routinely found to constitute willful neglect, which means the highest penalty tier applies. The annual caps per violation category mean a pattern of non-compliance multiplies quickly.
Notable OCR Enforcement Actions
- Premera Blue Cross (2020): $6.85 million settlement for a breach exposing 10.4 million individuals' PHI — partly attributed to failures in risk analysis and inadequate vendor management.
- CHSPSC LLC (2020): $2.3 million settlement after a breach of 6 million individuals' ePHI; the investigation found failures in technical safeguards.
- Banner Health (2021): $1.25 million settlement covering multiple HIPAA violations including inadequate risk analysis and missing policies.
- Elevance Health (2024): Ongoing OCR scrutiny following disclosures about third-party vendor breaches illustrating the continued enforcement focus on business associate oversight.
Beyond monetary penalties, corrective action plans require organizations to update their policies, train their workforce, and submit compliance reports to OCR for periods often running one to two years. The cost of a CAP — in staff time, legal fees, and consulting — often exceeds the fine itself.
State Laws That Go Further
HIPAA sets a federal floor, not a ceiling. Several states have enacted health privacy laws that impose stricter requirements:
- California: The Confidentiality of Medical Information Act (CMIA, California Civil Code § 56 et seq.) applies to a broader set of health information than HIPAA and carries statutory damages of $1,000 per violation regardless of actual harm.
- New York: SHIELD Act provisions complement HIPAA for health data breaches; NY's Department of Health has its own patient data regulations.
- Texas: The Texas Medical Records Privacy Act (Texas Health & Safety Code Chapter 181) goes beyond HIPAA in several respects, including broader scope for who must comply.
- Washington: The My Health MY Data Act (2023) applies to consumer health data outside HIPAA's scope and creates a private right of action.
Practical Checklist: Healthcare Contract Compliance
For Covered Entities
- Identify every vendor, contractor, and service provider that creates, receives, maintains, or transmits PHI on your behalf
- Confirm a signed BAA exists for each one before any PHI is shared
- Verify each BAA covers all required elements under 45 CFR § 164.504(e)
- Review BAAs annually and update them when vendor relationships or data flows change
- Ensure your services agreements reference and incorporate the BAA
- Confirm you have a breach notification protocol that maps to your BAAs' notification requirements
- Audit subcontractor chains — your BAs need their own downstream BAAs
For Business Associates
- Execute BAAs with every covered entity customer before accessing PHI
- Maintain BAAs with all subcontractors who touch PHI on your behalf
- Implement Security Rule safeguards for ePHI (administrative, physical, technical)
- Establish a breach detection and reporting protocol with documented timelines
- Train relevant staff on PHI handling, minimum necessary access, and incident reporting
- Document your security risk analysis under 45 CFR § 164.308(a)(1) — OCR considers this foundational
Common Mistakes to Avoid
Starting work before the BAA is signed. This is the most frequently cited violation. The contract must exist before PHI flows — "we'll get it signed next week" isn't compliant.
Using a generic NDA as a HIPAA substitute. A standard confidentiality agreement doesn't satisfy HIPAA's specific BAA requirements. It needs explicit HIPAA-specific clauses.
Forgetting subcontractors. If your business associate brings in a cloud storage vendor that hosts PHI, that vendor needs a BAA with your BA — and you should confirm it exists.
Vague breach notification timelines. "Prompt" or "reasonable" isn't specific enough. Define the exact window in the BAA so everyone knows when the clock starts.
Terminating without addressing PHI. When a vendor relationship ends, PHI doesn't disappear automatically. The BAA needs an explicit data return or destruction provision, and you should get written confirmation it was carried out.
Missing state law requirements. HIPAA compliance doesn't guarantee state law compliance. If you operate in California, Texas, Washington, or other states with broader health privacy laws, review those requirements separately.
Healthcare compliance isn't a one-time project — it's an ongoing obligation tied to every contract you sign with vendors who touch patient data. The good news is that once your BAA template is solid and your vendor review process is consistent, the compliance burden becomes manageable.
You can draft a professional services agreement with an NDA for healthcare contexts using Pactlio — describe your arrangement in plain English and get a review-ready draft. For data protection agreements in healthcare technology contexts, the DPA template covers overlapping GDPR requirements for organizations operating across US and EU jurisdictions.
This article is for informational purposes. Pactlio generates professional drafts for review — not legal advice.
Frequently Asked Questions
Who is considered a 'covered entity' under HIPAA?▾
Covered entities are the three types of organizations that HIPAA directly regulates: health plans (insurers, HMOs, employer-sponsored plans), healthcare clearinghouses (entities that translate between standard and non-standard health data), and healthcare providers that transmit any health information in electronic form — including hospitals, clinics, doctors, dentists, pharmacies, and nursing homes. If your organization falls into any of these categories, HIPAA applies to you directly.
What is a Business Associate Agreement (BAA) and when is one required?▾
A BAA is a written contract required by HIPAA whenever a covered entity — or another business associate — shares Protected Health Information (PHI) with a vendor or contractor who creates, receives, maintains, or transmits PHI on their behalf. Common examples include cloud storage providers, billing companies, IT support firms, legal counsel with PHI access, and software platforms that handle patient records. The BAA must be in place before any PHI is shared — not after.
What are the HIPAA penalties for missing or non-compliant contracts?▾
HIPAA civil penalties range from $141 to $71,162 per violation (2024 inflation-adjusted figures), capped at $2.134 million per violation category per year. The penalty tier depends on culpability — from 'did not know' (lowest) to 'willful neglect not corrected' (highest). Criminal penalties — including fines up to $250,000 and 10 years imprisonment — can apply to individuals who knowingly obtain or disclose PHI improperly. Operating without a required BAA is an almost automatic finding of willful neglect.
Does HIPAA apply to my app or software if it handles patient data?▾
It depends on whether you're acting as a business associate. If your app or platform receives, stores, or transmits PHI on behalf of a covered entity — say, an EHR integration, patient messaging tool, or billing software — you likely qualify as a business associate and need a signed BAA with each covered entity customer. Pure consumer health apps that store health information for individuals (not on behalf of providers) typically fall outside HIPAA, though they may be subject to FTC rules and state health privacy laws.
What must a HIPAA-compliant BAA include?▾
Under 45 CFR § 164.504(e), a BAA must specify the permitted uses and disclosures of PHI, require the business associate to safeguard PHI and report breaches, obligate them to flow down the same requirements to any subcontractors, allow the covered entity to audit compliance, and require destruction or return of PHI on termination. It should also address HIPAA's Security Rule requirements for electronic PHI (ePHI), including administrative, physical, and technical safeguards.
What happens if a business associate has a data breach?▾
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414), a business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI. The covered entity then has its own notification duties: individual notices within 60 days, media notice for breaches affecting 500+ residents in a state, and annual submission to HHS for smaller breaches. The BAA must spell out exactly how and when the business associate will notify — and failing to do so promptly is itself a HIPAA violation.