Business Associate Agreement
Business Associate Agreement
Use this document to identify each company’s roles, rights, and obligations with protected health information. The Cover Page includes any subcontracting, offshoring, de-identification, or aggregation limitations.
What is a Business Associate Agreement?
A BAA is a contract between a covered entity and an outside services provider (the business associate) that ensures the business associate follows the Health Insurance Portability and Accountability Act’s (HIPAA) rules about safeguarding protected health information (PHI). In software, it is often the case that a vendor signs a BAA with a customer who is a covered entity in order to use or disclose PHI for the customer.
How do I use this agreement?
To execute an agreement using the Common Paper Business Associate Agreement, first download a copy of the Cover Page in your preferred format. Then finalize the terms of the agreement with your counterparty and input those terms into the corresponding bracketed section of the Cover Page. Finally, sign your Cover Page with your counterparty.
The Cover Page is the only part of the agreement that you fill in and amend, as this incorporates the Standard Terms by reference to complete the executed agreement. You may change the Cover Page any way you like, such as adding a company branding or logo and editing the text. However, you are required to keep the license information and link to the Standard Terms.
All modifications to the Standard Terms should be made by addendum on the Cover Page. Incorporating the Standard Terms by reference from the Common Paper website gives both sides assurance that all key details and modifications are explicitly called out in the Cover Page.
The version of this agreement on GitLaw includes the Standard Terms, but please bear in mind these may change over time. You can keep the copy of the Standard Terms at the end of the agreement but we recommend checking that these are the most recent terms. You do not have to include these terms, however, as the Cover Page incorporates newer versions of the Standard Terms on the Common Paper website by reference as long as the link to the Standard Terms is active and clickable.
Versions of the agreement
This agreement is hosted online by Common Paper. Version 1 will remain unchanged at commonpaper.com/standards/business-associate-agreement/1.0, but Common Paper will create and post new versions to accommodate changes to the law and additional use cases. Any new versions will not change agreements that incorporate prior versions.
This Business Associate Agreement (BAA) has 2 parts:
The Key Terms on the Cover Page
The Common Paper BAA Standard Terms Version 1.0 (posted at https://commonpaper.com/standards/business-associate-agreement/1.0), incorporated by reference.
Any modifications to the BAA Standard Terms should be made on the Cover Page. If there is any inconsistency between the parts of the BAA, the Cover Page will control over the BAA Standard Terms. Capitalized words have the meanings or descriptions given in the Cover Page or Standard Terms.
Cover Page
Key Terms
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








United States note
This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



