Business Associate Agreement (US) by OLL
This HIPAA Business Associate Agreement is for a U.S. healthcare entity engaging a service provider who handles protected health information. It establishes the mandatory regulatory safeguards for data privacy and security required by HIPAA and the HITECH Act.
BUSINESS ASSOCIATE AGREEMENT
HIPAA covered entity to business associate (United States)
Note: Use this Agreement when a health care provider, health plan or health care clearinghouse that is a covered entity under HIPAA engages an outside company that will create, receive, maintain or transmit protected health information (PHI) on its behalf. Typical examples are a software vendor hosting patient records, a billing company, a scheduling or reminder service, an answering service, a consultant, or a law or accounting firm that sees PHI. The Privacy Rule requires a written contract with that company before any PHI is shared (45 C.F.R. Section 164.502(e)), and this Agreement contains every term that 45 C.F.R. Sections 164.504(e)(2) and 164.314(a)(2) require.
Note: Three choices drive most of the negotiation. How quickly the Business Associate must report a breach (Section 4.2). Whether it may keep de-identified or aggregated data for its own use (Sections 2.5 and 2.6). And who pays when a breach happens (Section 10). Each has Option blocks or a fallback note. The rest of the Agreement is regulatory text that both sides should expect to leave alone.
Note: This Agreement sits alongside, and does not replace, the commercial contract for the services. Put the price, service levels and general liability terms in that contract and name it in Exhibit A. If there is no separate contract, describe the services in Exhibit A and this Agreement stands on its own for HIPAA purposes.
This Business Associate Agreement (this "Agreement") is entered into as of [Effective Date e.g. October 15, 2026] (the "Effective Date") between:
(1) [Full Legal Name of the Covered Entity], [Entity Type and State of Organization of the Covered Entity e.g. a Texas nonprofit corporation], with its principal place of business at [Principal Business Address of the Covered Entity] (the "Covered Entity"); and
(2) [Full Legal Name of the Business Associate], [Entity Type and State of Organization of the Business Associate e.g. a Delaware corporation], with its principal place of business at [Principal Business Address of the Business Associate] (the "Business Associate").
The Covered Entity and the Business Associate are each a "Party" and together the "Parties".
Note: Name each Party exactly as it appears on its formation documents. If the Covered Entity is a hybrid entity (a single legal entity that has designated only part of its operations as its health care component), name the legal entity as the Party, because it stays responsible for its business associate agreements (45 C.F.R. Section 164.105(a)(2)(iii)(C)), and describe in Recital B the health care component the Services support. If the Business Associate's affiliates will also handle PHI, either name them here or require them to sign their own agreement; an affiliate that is not a party is not bound.
RECITALS
A. The Covered Entity is a covered entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations.
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








United States note
This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



