Business Associate Agreement Checklist for Healthcare Software
Use this business associate agreement checklist to review scope, PHI uses, safeguards, incidents, subcontractors, individual rights, return, destruction, and termination.

On this page: Direct answer
Direct answer
Business associate agreement checklist healthcare software: what operators need to know
Use this business associate agreement checklist to review scope, PHI uses, safeguards, incidents, subcontractors, individual rights, return, destruction, and termination. Map the complete PHI flow before reviewing contract language. Define permitted data uses narrowly enough to match the service. Flow applicable restrictions to every PHI-handling subcontractor.
A business associate agreement checklist helps a healthcare organization verify that the contract matches the software's actual PHI relationship. HHS sample provisions address permitted uses and disclosures, safeguards, incidents and breaches, individual-rights support, HHS access, subcontractors, termination, and return or destruction. The service agreement, security terms, and implemented workflow must remain consistent with the BAA.
Use this checklist with qualified privacy and legal counsel. It is an operational review framework, not contract language or legal advice, and additional Part 2, state, international, payer, customer, and risk-specific provisions may apply.
Key takeaways
The short version
- Map the complete PHI flow before reviewing contract language.
- Define permitted data uses narrowly enough to match the service.
- Flow applicable restrictions to every PHI-handling subcontractor.
- Align incident, rights, retention, return, and destruction duties with operational capability.
- Validate the signed agreement against production configuration and evidence.
1. Business associate agreement checklist healthcare software scope
HHS explains that a software company hosting patient information or accessing it during troubleshooting can be a business associate. A narrow product name in the agreement is not enough if integrations, support tools, analytics, or subprocessors also create, receive, maintain, or transmit PHI.
- Covered entity, business associate, affiliates, products, environments, and service components
- PHI/ePHI elements, sources, purposes, users, locations, systems, interfaces, and outputs
- Recordings, transcripts, insurance images, payer data, model inputs and outputs, logs, support, analytics, and backups
- Services performed on behalf of the covered entity and responsibilities carried out for it
- Applicable Part 2, state, contract, and organizational overlays identified for separate review
- Effective date, order of precedence, amendment, renewal, and termination relationship to the service agreement
2. Review required uses, safeguards, and reporting terms
| Term group | Operational question | Evidence to inspect |
|---|---|---|
| Uses/disclosures | What may the vendor do and for which service purpose? | Data-flow and processing inventory |
| Safeguards | How are Privacy and Security Rule duties implemented? | Risk analysis, policies, configuration, tests, logs |
| Incidents/breaches | What is reported, to whom, how fast, and with what support? | Response plan and exercise evidence |
| Individual rights | How will access, amendment, and accounting support work? | Request workflow and export capability |
| HHS access | Can required records and practices be made available? | Retention and evidence ownership |
| Termination | How is PHI returned, destroyed, retained, or protected? | Deletion and exit test |
3. Trace business-associate subcontractors
HHS says a cloud provider that maintains ePHI for a covered entity or business associate can itself be a business associate even if it lacks the decryption key. The BAA framework also requires applicable restrictions and conditions to flow to subcontractors that create, receive, maintain, or transmit PHI.
Obtain a current list covering infrastructure, databases, storage, communications, transcription, AI models, observability, support, backup, security, and other services. Record entity, service, PHI role, location, agreement status, data use, retention, deletion, incidents, owner, and change-notification process.

4. Align the BAA with security and service terms
- 01
Compare
Reconcile the BAA with the master agreement, SLA, security addendum, privacy notice, data-processing terms, order form, and subprocessor page.
- 02
Resolve
Address conflicting incident clocks, use rights, retention, audit evidence, availability, support access, indemnity, limitation, and termination terms with counsel.
- 03
Configure
Implement customer isolation, roles, access, logging, retention, training-use restrictions, backups, exports, and deletion as contracted.
- 04
Test
Exercise an access request, amendment support, incident, subprocessor change, service termination, data return, and secure deletion.
- 05
Approve
Record privacy, legal, security, business, and technical approval plus residual risks and conditions.
5. Operate the agreement after signature
A signed BAA is a required safeguard when the relationship applies, not proof that the system is configured or operated correctly. Sample production access, logs, data locations, processor inventory, incidents, requests, and deletion results against the agreement.
- Agreement owner, system owner, security contact, privacy contact, and escalation path
- Annual and material-change review with current services and data flow
- Subprocessor additions, mergers, feature releases, new data uses, and hosting changes
- Incident, complaint, rights request, legal demand, retention, and deletion events
- Workforce and support access review plus termination of inactive access
- Contract expiration, renewal, exit readiness, return, destruction, and evidence retention
Common questions
Answers before you build.
When does a software vendor need a BAA?+
HHS says a vendor that needs PHI access to provide its service, such as hosting patient information or accessing it for support, would be a business associate, requiring a BAA before access.
What should a healthcare software BAA cover?+
Review permitted uses and disclosures, safeguards, incident and breach reporting, individual-rights support, HHS access, subcontractors, termination, return or destruction, and other facts specific to the service.
Does signing a BAA make software HIPAA compliant?+
No. The parties must implement the applicable Privacy, Security, and Breach Notification duties, risk management, contracted controls, and correct workflow configuration.
Do cloud and AI subprocessors need BAAs?+
When they create, receive, maintain, or transmit PHI on behalf of a business associate, applicable business-associate restrictions and agreements can apply. Map each relationship with counsel.
Practical closeout
Use this operator checklist.
- Map the complete PHI flow before reviewing contract language.
- Define permitted data uses narrowly enough to match the service.
- Flow applicable restrictions to every PHI-handling subcontractor.
- Align incident, rights, retention, return, and destruction duties with operational capability.
- Validate the signed agreement against production configuration and evidence.
Continue through the cluster
Verified customer case studies are added only with customer permission and supporting evidence; none is implied by these operational examples.
Sources & methodology
Trace the operational claims.
Marsa Health Editorial reviewed the primary and research sources below on July 22, 2026. We translate them into workflow controls, distinguish proposals from final rules, and flag where plan, program, state, contract, or clinical requirements vary.
- 01Business Associate Contracts U.S. Department of Health and Human ServicesOCR explanation and sample provisions covering permitted uses, safeguards, incidents, individual rights, subcontractors, termination, and return or destruction.Accessed or rechecked July 22, 2026
- 02Is a software vendor a business associate of a covered entity? U.S. Department of Health and Human ServicesOCR guidance explaining when software access to PHI creates a business-associate relationship and requires a BAA before access.Accessed or rechecked July 22, 2026
- 03Guidance on HIPAA and Cloud Computing U.S. Department of Health and Human ServicesOCR guidance on cloud business associates, subcontractors, BAAs, risk analysis, shared security responsibilities, SLAs, data return, and breach duties.Accessed or rechecked July 22, 2026
- 04Direct Liability of Business Associates U.S. Department of Health and Human ServicesOCR fact sheet describing provisions of the HIPAA Rules for which business associates can be directly liable.Accessed or rechecked July 22, 2026
- 05Summary of the HIPAA Security Rule U.S. Department of Health and Human ServicesCurrent Security Rule overview covering administrative, physical, and technical safeguards, access controls, risk analysis, and review of ePHI activity.Accessed or rechecked July 22, 2026
- 06Guidance on Risk Analysis U.S. Department of Health and Human ServicesOfficial guidance that risk analysis must cover all ePHI an organization creates, receives, maintains, or transmits.Accessed or rechecked July 22, 2026
- 07Minimum Necessary Requirement U.S. Department of Health and Human ServicesHIPAA guidance on limiting uses, disclosures, and requests for protected health information when the standard applies.Accessed or rechecked July 22, 2026
Organizational author. Editorial review covers source accuracy, search intent, workflow boundaries, and human-oversight requirements. This material is educational and does not provide clinical, legal, coding, or coverage advice.
No named clinical or legal expert reviewer is attributed to this version. Marsa Health does not invent reviewer credentials.
Read our editorial methodRevision history
What changed and when
July 22, 2026
Initial publication, source review, and operational editing.