Skip to main content
Guide

What Is a Business Associate Agreement? HIPAA BAA Guide

What a HIPAA business associate agreement (BAA) is, who must sign one, what 45 CFR 164.504(e) requires, and which marketing tools sign a BAA.

9 min read

A business associate agreement (BAA) is the written contract HIPAA requires between a covered entity, such as a health care provider or health plan, and a vendor that creates, receives, maintains or transmits protected health information (PHI) on its behalf. It documents the vendor's promise to safeguard that PHI and must contain the terms in 45 CFR 164.504(e). A vendor that passes the PHI to a subcontractor needs a BAA with the subcontractor too. To check whether a marketing tool signs one, use the BAA Directory from Curve Compliance, which covers 94 tools. Curve Compliance signs a BAA on every plan for its ad tracking.

Book a call. Curve Compliance sends your ad conversions server-side to Meta, Google Ads, TikTok, Microsoft Advertising and LinkedIn, and signs a BAA on every plan. Book a call with Curve.

What is a business associate agreement?

HIPAA applies to covered entities: health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction. The HHS guidance on business associates describes a business associate as, generally, a person or organization that performs functions or activities for a covered entity that involve creating, receiving, maintaining or transmitting PHI, or that provides certain services involving PHI. The covered entity must get "satisfactory assurances" from it, in a contract or other written arrangement that HHS calls a "business associate agreement," or BAA.

HHS's examples include billing, claims processing and data analysis done for a covered entity, a cloud service provider that stores or processes electronic PHI, an EHR vendor or IT contractor that supports systems holding it, and a third-party AI chatbot on a patient portal that handles appointment scheduling. HHS adds that a business associate "is also directly liable for complying with certain provisions of the HIPAA Rules."

The requirement sits in two rules. Under the Privacy Rule, 45 CFR 164.502(e) requires the assurances to be documented "through a written contract or other written agreement or arrangement" that meets 164.504(e). Under the Security Rule, 45 CFR 164.308(b) does the same for electronic PHI, and 45 CFR 164.314(a) sets what that contract must say.

Who must sign a BAA?

RelationshipBAA required?Rule
Covered entity and its business associateYes, for PHI the business associate handles on the covered entity's behalf164.502(e)(1)(i); 164.308(b)(1)
Business associate and its subcontractorYes, for PHI the subcontractor handles on the business associate's behalf164.502(e)(1)(ii); 164.308(b)(2); 164.504(e)(5)
Covered entity and its business associate's subcontractorNo. The covered entity "is not required to obtain such satisfactory assurances from a business associate that is a subcontractor."164.502(e)(1)(i); 164.308(b)(1)

On subcontractors, HHS is direct: "A business associate must establish a BAA with its subcontractor before disclosing PHI to the subcontractor for work to be done for a covered entity." Those subcontractors are business associates too, and 164.504(e)(5) applies the same contract requirements to them. So if a marketing agency is a clinic's business associate, it needs BAAs with the vendors it passes that PHI to.

What a BAA must contain: the 164.504(e) requirements

Under 45 CFR 164.504(e)(2), a BAA must:

  1. Set the permitted and required uses and disclosures of PHI. It may not allow anything the Privacy Rule would bar the covered entity from doing, except the business associate's own management and administration and data aggregation for the covered entity.
  2. Limit use and disclosure to the contract, or as required by law.
  3. Require appropriate safeguards, including Security Rule compliance for electronic PHI.
  4. Require reporting of any use or disclosure the contract does not allow, including breaches of unsecured PHI.
  5. Flow down to subcontractors. They must agree to the same restrictions and conditions.
  6. Support patient rights: access to PHI, amendments, and an accounting of disclosures.
  7. Follow the Privacy Rule when carrying out a covered entity's obligation under it.
  8. Open its books to HHS for determining the covered entity's compliance.
  9. Return or destroy PHI at termination if feasible, or extend the contract's protections to what remains.
  10. Allow termination by the covered entity if the business associate violates a material term.

The Security Rule version in 164.314(a) adds that the business associate will report any security incident it becomes aware of. And if a covered entity knows of a pattern of activity by its business associate that is a material breach of the BAA, 164.504(e)(1)(ii) requires it to take reasonable steps to cure the breach or end the violation and, if those fail, to terminate the contract if feasible.

HHS publishes sample business associate agreement provisions that follow this list. HHS says "use of these sample provisions is not required for compliance with the HIPAA Rules," and that relying on the sample "does not replace consultation with a lawyer." For your own agreements, talk to your counsel.

When you don't need a BAA

The HHS guidance lists cases where PHI can be shared without a BAA, because the recipient is not acting for the covered entity. Examples include:

  • Treatment. A hospital referring a patient to a specialist, or a physician sending PHI to a clinical laboratory for the patient's treatment.
  • Payment. A provider submitting a claim to a health plan.
  • Conduits. The US Postal Service, certain private couriers and their electronic equivalents. HHS limits this to entities that only transmit PHI, and says "Entities that access PHI on a regular or frequent basis to perform a service on behalf of a covered entity are not conduits."
  • Incidental access. A janitorial service or electrician whose work does not involve PHI, with only incidental access, if any.
  • Payment processing. A financial institution processing card payments or fund transfers that pay for health care.

Marketing vendors are not on that list. A form, scheduling or CRM tool that holds patient data for you is closer to HHS's cloud provider example. IntakeQ says it plainly: "Because IntakeQ has access to your clients' Protected Health Information, it's important to have a Business Associate Agreement, or BAA, on file."

BAAs in healthcare marketing: which common tools sign one

Healthcare forms often ask about symptoms or insurance, schedulers hold appointments, CRMs hold patients, and call tracking records calls. The Curve Compliance BAA Directory checks 94 healthcare marketing and operations tools against each vendor's own pages: 26 sign a BAA, 34 sign one only on specific plans or products, 25 do not, and for 9 the directory found no statement to quote. Here are 12 well-known tools, as of the September 29, 2026 check.

ToolCategorySigns a BAA?What the vendor says
MetaAd platformNoIts Business Tools Terms bar data that includes or is based on health information.
Google AdsAd platformNoGoogle does not intend its call features to create HIPAA obligations.
Google Analytics 4AnalyticsNoGoogle does not offer a BAA for Google Analytics.
CalendlySchedulingNoNo BAA currently offered; not intended for collecting PHI.
Acuity SchedulingSchedulingSpecific plansPowerhouse and Premium plans, once the account is HIPAA-enabled.
IntakeQSchedulingYesThe account admin signs the BAA inside the account.
JotformFormsSpecific plansGold and Enterprise, once HIPAA features are turned on.
HubSpotCRM and emailSpecific plansEnterprise subscriptions with Sensitive Data turned on.
MailchimpEmailNoIts Data Processing Addendum bars health information.
CallRailCall trackingSpecific plansSigns with each of its Healthcare plan clients.
ZoomTelehealth videoSpecific plansPaid plans such as Pro, Business, Business Plus and Enterprise.
Google WorkspaceWorkspaceYesCovers listed services such as Gmail, Drive and Meet.

Two points stand out. A BAA covers one vendor: Squarespace says its Acuity BAA "doesn't cover other Squarespace features," and a Google Workspace BAA does not extend to Google Ads or Google Analytics. And a BAA with your scheduler or form tool does not cover an ad pixel on the same page, because the pixel sends data to a different company that is not a party to that BAA. See Jotform's patient form risks and Calendly in healthcare scheduling. Vendors change their terms, so confirm them before you send any vendor patient data.

Why Meta, Google Ads and other ad platforms don't sign a BAA

All eight ad platforms in the directory, including LinkedIn Ads and Microsoft Advertising, are listed as not signing one, and their terms tell advertisers not to send health information at all. Meta's Business Tools Terms bar data that "includes or is based on, directly or otherwise, health information," and say event names "must not reflect, imply or be based on" it. In its Google Ads call terms, Google tells covered entities and business associates that they should not accept those terms. For Google Analytics, Google "does not offer Business Associate Agreements in connection with this service." TikTok says it does not "allow advertisers to share information about children, health or financial information."

Yet the booking or form fill your campaigns learn from still has to reach the ad platform, without health information. A browser pixel sends the page address, event name and identifiers with every conversion, and on a healthcare site those can describe a condition or a treatment. See why healthcare sites remove the Meta pixel and Google Ads conversion tracking for healthcare.

How server-side conversion tracking under a BAA fills the gap

Curve Compliance replaces the browser ad pixels with one script and sends conversions from Curve's servers to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn, under a BAA it signs on every plan.

  • A fixed list of fields per platform. Page titles, free text and form answers are never sent.
  • Contact identifiers off by default, and hashed with SHA-256 when switched on.
  • Neutral event names that don't reveal a condition or a treatment.
  • PHI-like pattern detection. Condition names, form answers and emails in URLs are flagged before data reaches an ad platform, so they can be stopped at the source.
  • Event Logs show what Curve sent to each platform and what each accepted.
  • Attribution through booking tools. The ad click is kept through IntakeQ, Calendly, Acuity, Jane App and other schedulers, so a booking made days later still matches the ad.

Like every BAA, Curve's covers the data Curve handles for you, so your scheduler, form builder and CRM each need their own; the BAA Directory shows which sign one. Curve's team does the setup, typically in about a week; timing varies case by case. To see which pixels your site loads today, run the free website scan or read the Curve Compliance FAQ.

Book a call. Curve's team will go through what your site sends to Meta, Google and TikTok today and set up server-side conversion tracking, with a BAA signed on every plan. Book a call with Curve.

Frequently Asked Questions

What is a business associate agreement?

A business associate agreement (BAA) is the written contract HIPAA requires before a covered entity lets a business associate create, receive, maintain or transmit PHI on its behalf. It must contain the terms in 45 CFR 164.504(e).

What is a HIPAA BAA?

BAA stands for business associate agreement: the contract between a covered entity and a business associate, or between a business associate and its subcontractor, that HIPAA requires before PHI is shared.

What are the business associate agreement requirements?

Under 164.504(e)(2), a BAA must set permitted uses and disclosures of PHI, require safeguards and breach reporting, bind subcontractors to the same terms, support patient access and amendments, open the business associate's books to HHS, return or destroy PHI at termination if feasible, and allow termination for a material violation.

Does a business associate need a BAA with its subcontractors?

Yes. HHS says a business associate must establish a BAA with its subcontractor before disclosing PHI to it, and 164.504(e)(5) applies the same requirements. The covered entity does not need its own BAA with the subcontractor.

Who needs to sign a business associate agreement?

A covered entity signs one with each business associate that handles PHI for it, and each business associate signs one with each subcontractor that does. HHS lists exceptions, such as disclosures to a provider for treatment.

Do Meta and Google Ads sign a BAA?

No, according to the BAA Directory. Meta's terms bar health information, Google offers no BAA for Google Analytics, and Google disclaims HIPAA obligations for its Google Ads call features. Send conversions server-side with neutral event names and hashed identifiers instead.

Does a BAA with my scheduling or form tool cover my ad pixels?

No. A BAA covers the data one vendor handles for you. A pixel sends data to Meta, Google or TikTok, and none of them is a party to that BAA.

Does Curve Compliance sign a BAA?

Yes, on every plan, for its server-side conversion tracking. Curve's team does the setup, typically in about a week. Book a call to get started.

Next step

Check your own site

See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.

Or book a tracking audit

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit