Business Associate Agreement with HIPAA Compliance
The Standard Business Associate Agreement (BAA) is designed to enable HIPAA covered entities to exchange protected health information with SaaS providers and other business associates. It is part of OLL’s widely trusted library of open, lawyer-vetted standard agreements.
Standard Business Associate Agreement (BAA) (Version 1.0)
Cover Page
By executing this Cover Page, Customer and Business Associate enter into the Business Associate Agreement (BAA) (Version 1.0). The BAA includes the contents of this Cover Page, including the Key Terms any Additional Terms. Capitalized terms not defined in this Cover Page have the meanings given in the BAA.
Key Terms | |
Main Agreement | This BAA is incorporated into the agreement between Customer and Provider identified below: |
[main agreement name/date] | |
BAA Effective Date | [effective date] |
Additional Terms | |
The following additions to or modifications of the BAA are agreed by the parties and control in the event of any conflicts: | |
Signatures | |
Agreed to as of the BAA Effective Date by each party’s authorized representative: | |
Customer: | Business Associate: |
Standard Terms
This Business Associate Agreement (Version 1.0) (“BAA”) is a set of standard terms entered into between Business Associate and Customer by executing a Cover Page.
Definitions.
“Breach”, “Covered Entity”, “Designated Record Set”, “Disclosure”, “Individual”, “Required by Law”, “Secretary”, “Security Incident”, “Unsecured PHI”, “Use”, and any other terms defined in the HIPAA Rules, whether capitalized or not, have the meaning ascribed to such terms in the HIPAA Rules unless otherwise specified.
“Additional Terms” means any additions to or modifications of this BAA that the parties specify on a Cover Page.
“Business Associate” is identified on the Cover Page.
“BAA Effective Date” is specified on the Cover Page.
“Cover Page” means a separate document executed by Customer and Business Associate which specifies the Key Terms and any Additional Terms and causes them to enter into this BAA.
“Customer” is identified on the Cover Page.
“Data Disposition Period” is defined in Section 5.2.
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, and implementing regulations.
“HIPAA Rules” means the Privacy Rule and Security Rule.
“HITECH Act” means the Health Information Technology for Economic and Clinical Health Act, codified at 42 U.S.C. §§ 17921–17954, and implementing regulations.
“HHS” means the Department of Health and Human Services.
“Key Terms” means the BAA Effective Date and Main Agreement.
“Main Agreement” means the separate agreement under which Business Associate is providing a service to Customer to which this BAA relates.
“Privacy Rule” means the standards for permissible uses and disclosures of Protected Health Information codified at 45 C.F.R. Part 160 and Subparts A and E of Part 164.
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








United States note
This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



