The BAA is HIPAA’s contract layer: it extends the law’s obligations to vendors who handle PHI on a covered entity’s behalf. Typical terms define permitted uses of the data, require administrative, physical, and technical safeguards, obligate breach notification up the chain, govern subcontractors, and specify what happens to PHI when the relationship ends. No BAA, no PHI — a covered entity that shares patient data without one is itself out of compliance.
If your product stores, processes, or transmits identifiable health data for a healthcare customer, expect their procurement team to require a BAA before any PHI flows — and expect to sign your cloud providers’ BAAs in turn, since they hold the data underneath you. Signing is the easy half; the agreement commits you to a real security program, which is why a BAA usually arrives alongside a request for HIPAA evidence. What that program looks like at seed stage is covered in HIPAA for startups.
Your counsel owns the contract — negotiating liability, indemnification, and notification terms is legal work. What your security program owns is making the promises true: access controls, encryption, logging, training, and an incident process that can actually meet the notification commitments your lawyer agreed to. Treat every signed BAA as a standing obligation your program has to keep evidencing.