Free HIPAA Business Associate
Agreement (BAA) generator

Generate a HIPAA-compliant Business Associate Agreement (BAA) in minutes using language aligned with the U.S. Department of Health and Human Services (HHS) guidance and 45 CFR §164.504(e) requirements. Customize your agreement, preview it instantly, and download it as an editable Word document or PDF. Everything is processed locally in your browser, with no signup, no tracking, and no data leaving your device.

Agreement details

Parties

Terms

Termination

Legal

Signatories

Preview

HIPAA BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement ("Agreement") is entered into as of [Effective Date] ("Effective Date") by and between [Covered Entity Name], located at [Covered Entity Address] ("Covered Entity"), and [Business Associate Name], located at [Business Associate Address] ("Business Associate"). Covered Entity and Business Associate may each be referred to as a "Party" and collectively as the "Parties."

WHEREAS, Business Associate provides the following services to Covered Entity: [describe the services], and in connection with those services may create, receive, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity; and

WHEREAS, the Parties intend to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the HITECH Act, and their implementing regulations, including the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164 (the "HIPAA Rules");

NOW, THEREFORE, in consideration of the mutual promises below, the Parties agree as follows:

1. Definitions

The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

(a) "Business Associate" shall generally have the same meaning as the term "business associate" at 45 CFR 160.103, and in reference to the party to this Agreement, shall mean [Business Associate Name].

(b) "Covered Entity" shall generally have the same meaning as the term "covered entity" at 45 CFR 160.103, and in reference to the party to this Agreement, shall mean [Covered Entity Name].

(c) "HIPAA Rules" shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.

2. Obligations and Activities of Business Associate

Business Associate agrees to:

(a) Not use or disclose PHI other than as permitted or required by this Agreement or as required by law;

(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement;

(c) Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of unsecured PHI as required at 45 CFR 164.410, and any security incident of which it becomes aware, without unreasonable delay and no later than 30 days after discovery;

(d) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information;

(e) Make available PHI in a designated record set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524;

(f) Make any amendment(s) to PHI in a designated record set as directed or agreed to by Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under 45 CFR 164.526;

(g) Maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528;

(h) To the extent Business Associate is to carry out one or more of Covered Entity's obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s); and

(i) Make its internal practices, books, and records available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.

3. Permitted Uses and Disclosures by Business Associate

(a) Business Associate may only use or disclose PHI as necessary to perform the services set forth above, or as required by law.

(b) Business Associate may use or disclose PHI as required by law.

(c) Business Associate agrees to make uses and disclosures and requests for PHI consistent with Covered Entity's minimum necessary policies and procedures.

(d) Business Associate may not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except for the specific uses and disclosures set forth below.

(e) Business Associate may use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate.

(f) Business Associate may disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided the disclosures are required by law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and be used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

4. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions

(a) Covered Entity shall notify Business Associate of any limitation(s) in the Notice of Privacy Practices of Covered Entity under 45 CFR 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.

(b) Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an individual to use or disclose his or her PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.

(c) Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

5. Permissible Requests by Covered Entity

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except to the extent permitted under Section 3 above for the proper management and administration, legal responsibilities, or data aggregation services of Business Associate.

6. Term and Termination

(a) Term. This Agreement shall be effective as of [Effective Date], and shall terminate on [the date on which all PHI is returned or destroyed], or on the date Covered Entity terminates for cause as authorized in paragraph (b) of this Section, whichever is sooner.

(b) Termination for Cause. Business Associate authorizes termination of this Agreement by Covered Entity if Covered Entity determines that Business Associate has violated a material term of this Agreement and Business Associate has not cured the breach or ended the violation within 30 days.

(c) Obligations of Business Associate Upon Termination. Upon termination of this Agreement for any reason, Business Associate shall return to Covered Entity [or, if agreed to by Covered Entity, destroy] all PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form, and shall retain no copies of the PHI. If such return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains the PHI.

(d) Survival. The obligations of Business Associate under this Section shall survive the termination of this Agreement.

7. Miscellaneous

(a) Regulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

(b) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of the HIPAA Rules and any other applicable law.

(c) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.

(d) Governing Law. This Agreement shall be governed by the laws of the State of [State], except to the extent preempted by federal law.

(e) Notices. All notices and communications required under this Agreement shall be delivered to the following contacts: Covered Entity — [Contact Name] ([email]); Business Associate — [Contact Name] ([email]).

8. Signatures

IN WITNESS WHEREOF, the Parties have executed this Agreement as of the Effective Date.

COVERED ENTITY: [Covered Entity Name]

By: [Name] Title: [Title] Date: _______________

BUSINESS ASSOCIATE: [Business Associate Name]

By: [Name] Title: [Title] Date: _______________

Generated by BlockSurvey

How the HIPAA BAA generator works

1

Fill in the details

Enter the covered entity and vendor names, addresses, the services involved, and key dates in a short guided form.

2

Review the live preview

Watch the complete agreement assemble in real time, with the right clauses added based on your answers.

3

Download and sign

Export a ready-to-sign PDF or an editable Word file. Nothing you enter ever leaves your device.

Free, secure, and HIPAA-standard by default

Most online BAA generators send your details to their servers or lock the real download behind a paywall. This one is different, and every agreement follows the required elements of 45 CFR §164.504(e)

01

100% in-browser

The agreement is built on your device; nothing is uploaded.

02

No account required

No sign-up, no email wall, no tracking.

03

Free, real download

The complete, signable document at no cost, not a watermarked sample.

Built For Every Healthcare Organization

Whether you're a solo practice or a growing health-tech company, this tool produces a BAA scoped to how you work, and pairs naturally with HIPAA-compliant survey software when you collect health data through forms.

Private practices & clinics

Keep patient-facing paperwork compliant without hiring outside help.

Therapists & behavioral health

Handle sensitive client records with the care HIPAA expects.

Telehealth & digital health startups

Build HIPAA habits into your workflow as you grow.

Dental & specialty practices

Standardize compliance across your front desk and locations.

Medical billing & MSOs

Manage the PHI you handle for the practices you serve.

Health-tech vendors

Meet the HIPAA obligations that come with healthcare clients.

Collecting PHI through forms or surveys?

BlockSurvey is HIPAA-compliant and signs a BAA with you, so the tool you use to gather health data is covered too.

More free HIPAA tools

Explore more

These tools help you document compliance. When you need to collect PHI itself, you need a BAA and encryption in the product: HIPAA-compliant survey software.

Frequently asked questions

What's the difference between a BAA and an NDA?

An NDA (non-disclosure agreement) is a general confidentiality contract that keeps information private, but it does not satisfy HIPAA on its own. A BAA is HIPAA-specific: it includes the regulatory elements HIPAA requires — permitted uses of PHI, safeguards, breach notification, subcontractor obligations, and return or destruction of PHI on termination. An NDA has none of these by default. In many vendor relationships you may sign both: an NDA for general confidentiality and a BAA for HIPAA compliance. If a vendor offers you only an NDA for a service that touches PHI, that does not meet your HIPAA obligations.

Is the generated agreement legally binding?

A BAA becomes binding once both parties sign it. This tool produces a complete draft built on the HHS model provisions, but it is a starting-point template, not legal advice — you should have it reviewed by qualified legal counsel and tailored to your specific vendor relationship before signing.

Do I need a BAA with cloud or SaaS vendors?

Yes, if the cloud or SaaS vendor stores, processes, or transmits PHI for you, it is a business associate and needs a signed BAA, even if it only stores encrypted data and never views it. The one narrow exception is a true "conduit" that only transports data (like a postal service or ISP), which most software vendors do not qualify for.

When does the BAA need to be signed, before or after sharing PHI?

Before. You must have a signed BAA in place before you disclose any PHI to the vendor or let them access it on your behalf. Sharing PHI with a vendor that hasn't signed a BAA can itself be a HIPAA violation, regardless of whether a breach occurs.

What happens if I don't have a BAA in place?

Disclosing PHI to a vendor without a signed BAA is a HIPAA violation and can expose your organization to significant penalties, even absent an actual data breach. Regulators have issued substantial fines specifically for missing BAAs, so having one on file for every PHI-handling vendor is a basic compliance requirement.

Can a BAA be signed electronically?

Yes. A BAA can be executed electronically or with e-signatures; HIPAA does not require a handwritten signature. What matters is that both parties agree to the terms and the signed agreement is retained as part of your compliance records.

How is this different from paid BAA generators?

Most online BAA generators show a free preview but charge (often around $49) to download the usable document, and your details are processed on their servers. This generator is completely free, requires no account, and runs entirely in your browser — your organization's information never leaves your device. You download the same complete Word or PDF agreement at no cost.

Do you store the information I enter?

No. The entire agreement is assembled locally in your browser. Your entity names, addresses, and signatory details are never sent to or stored on any server, which is why no sign-up is required.

Is this a substitute for legal advice?

No. This tool generates a starting-point draft based on the U.S. Department of Health and Human Services (HHS) sample Business Associate Agreement provisions, but it is not legal advice and is not guaranteed to be complete or suitable for your specific situation. Every vendor relationship is different, and state law may add requirements. Have the agreement reviewed by qualified legal counsel and tailored to your circumstances before signing.
Scripts are blocked. This site won’t work properly. If you’re using Brave, click the Shields icon and turn off Block scripts. Otherwise disable your ad blocker for this site.