Glossary

DEFINITION

Business Associate Agreement (BAA)

A HIPAA-mandated contract between a covered entity and a vendor that handles PHI on its behalf, defining each party's privacy and security obligations.

In depth

A Business Associate Agreement (BAA) is required under HIPAA whenever a covered entity (provider, plan, clearinghouse) shares Protected Health Information with a vendor that performs a function on the entity's behalf. The BAA sets out permitted uses, security obligations, breach-notification duties, and termination rights. Most consumer-facing AI services do not sign BAAs with end users; some offer enterprise-tier BAAs only at high price points and with limited scope. In the absence of a BAA, sending PHI to an AI service is a HIPAA disclosure event the covered entity is liable for.

Examples

  • A hospital signing a BAA with a clinical-summary AI vendor before piloting it on real patient notes.
  • A small practice declining to use a free AI tool because the vendor will not sign a BAA.
  • A health plan auditing existing vendor relationships to confirm BAAs are current.

How Locke handles business associate agreement (baa)

Sonomos does not require a BAA because it never receives PHI — detection runs entirely on the user's device. Covered entities can deploy Locke as a runtime control without expanding the chain of business associates.

See the product