BAA Tracker: What to Collect, When to Renew, and What Happens If You Don't
Missing or expired Business Associate Agreements are one of the top causes of HIPAA enforcement actions. This guide covers exactly who needs a BAA, what it must contain, and how to build a renewal programme that holds up under audit.
What is a Business Associate Agreement?
A Business Associate Agreement (BAA) is a legally binding contract required by HIPAA whenever a covered entity — a healthcare provider, health plan, or healthcare clearinghouse — shares Protected Health Information (PHI) with an external party that performs services on its behalf.
The BAA establishes that the receiving party (the "business associate") understands its obligations under HIPAA, will implement appropriate safeguards, and will report any security incidents or breaches. Without a valid BAA, sharing ePHI with any third party is a HIPAA violation — regardless of whether a breach occurs.
Which vendors require a BAA?
Seven provisions every BAA must include under 45 CFR §164.504(e).
- 01Permitted uses and disclosures of ePHI are clearly defined
- 02Business associate will not use or disclose ePHI beyond what is permitted
- 03Appropriate safeguards will be implemented to prevent unauthorized use or disclosure
- 04Any subcontractors who receive ePHI will be bound by the same obligations
- 05ePHI will be available for amendment if required by the individual
- 06Breaches and security incidents will be reported to the covered entity
- 07On termination, ePHI will be returned, destroyed, or continued safeguards documented
What happens when a BAA is missing or expired.
OCR can assess up to $1.9M per violation category per calendar year under the Penalty Tiers.
Knowingly obtaining or disclosing ePHI without authorisation — including through a non-executed BAA — can result in criminal charges.
If a BA discloses ePHI without a valid BAA, it may constitute a breach requiring notification to individuals, HHS, and potentially media.
Many states have added their own healthcare privacy laws with separate penalty structures that run concurrently with HIPAA enforcement.
Protexa's AI engine continuously monitors your BAA inventory for upcoming expirations, flags vendors where an agreement is missing, and surfaces anomalies between your approved vendor list and your active ePHI flows — each with a direct remediation action. No more renewal tracking in spreadsheets.
Track every BAA.
Automatically.
Protexa monitors your entire vendor inventory for BAA status, expiry dates, and coverage gaps — so your compliance posture never depends on a spreadsheet.