DEFINITION
Business Associate Agreement (BAA)
A HIPAA-mandated contract between a covered entity and a vendor that handles PHI on its behalf, defining each party's privacy and security obligations.
In depth
A Business Associate Agreement (BAA) is required under HIPAA whenever a covered entity (provider, plan, clearinghouse) shares Protected Health Information with a vendor that performs a function on the entity's behalf. The BAA sets out permitted uses, security obligations, breach-notification duties, and termination rights. Most consumer-facing AI services do not sign BAAs with end users; some offer enterprise-tier BAAs only at high price points and with limited scope. In the absence of a BAA, sending PHI to an AI service is a HIPAA disclosure event the covered entity is liable for.
Examples
- A hospital signing a BAA with a clinical-summary AI vendor before piloting it on real patient notes.
- A small practice declining to use a free AI tool because the vendor will not sign a BAA.
- A health plan auditing existing vendor relationships to confirm BAAs are current.
How Locke handles business associate agreement (baa)
Sonomos does not require a BAA because it never receives PHI — detection runs entirely on the user's device. Covered entities can deploy Locke as a runtime control without expanding the chain of business associates.
See the productRelated terms
- HIPAA
The U.S. Health Insurance Portability and Accountability Act, which sets privacy and security rules for individually identifiable health information held by covered entities.
- Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a covered entity, regulated under HIPAA in the United States.
- Data Processing Agreement (DPA)
A GDPR-mandated contract between a controller and a processor that governs how personal data is handled on the controller's behalf.