Business Associate Agreement by Common Paper
The Common Paper Business Associate Agreement (BAA) is designed to enable HIPAA covered entities to share protected health information with SaaS providers and other business associates. It is part of CommonPaper’s widely trusted library of open, lawyer-vetted standard agreements.
Business Associate Agreement
USING THIS BAA
This BAA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper BAA Standard Terms Version 1.0 posted at https://commonpaper.com/standards/business-associate-agreement/1.0, which is incorporated by reference. Any modifications to the BAA Standard Terms should be made on the Cover Page. If there is any inconsistency between the parts of the BAA, the Cover Page will control over the BAA Standard Terms. Capitalized words have the meanings or descriptions given in the Cover Page or Standard Terms. A copy of the BAA Standard Terms is attached for convenience only.
Key Terms
The key legal terms of this BAA are as follows:
Agreement | This BAA is incorporated into the [main agreement] |
Relationship | Provider is a subcontractor | Business Associate |
Breach Notification Period | Drafting note: this time period cannot be more than 60 calendar days
|
Designated Record Set | Drafting note: select one and delete the other Provider maintains PHI in a Designated Record Set. Provider does not maintain PHI in a Designated Record Set. |
Limitations | The Standard Terms permit all four activities (Sections 1.7 and 3). Delete the entire section to allow these activities as specified in the Standard Terms. To prohibit or place limits on the extent to which these activities can be done, select and specify those that apply. Subcontracting: |
BAA Effective Date | Date of last signature on this Cover Page |
Changes to BAA Standard Terms | [changes to standard terms] |
Other Changes to BAA Standard Terms | [other changes] |
Provider and Company have not changed the BAA Standard Terms except for the details on the Cover Page above. By signing this Cover Page, each party agrees to enter into this BAA as of the BAA Effective Date.
PROVIDER: [provider name] | COMPANY: [company name] | |
Signature | ||
Print Name | [provider print name] | [company print name] |
Title | [provider title] | [company title] |
Notice Address | [provider notice address] | [company notice address] |
Date | [provider date] | [company date] |
Standard Terms
Business Associate Obligations
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








United States note
This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



