Healthcare compliance

HIPAA Business Associate Agreement Generator and Attorney Review

The generator is further down this page and it is free. But the BAA you sign is almost never the one you generate. It is the counterparty's form, and what that form adds on top of 45 CFR 164.504(e) is where the liability sits.

I am Sergei Tokmakov, a California attorney, CA Bar #279869, licensed since 2011. I draft and redline BAAs on either side of the table.

Sergei Tokmakov, Esq., California attorney, CA Bar #279869
Sergei Tokmakov, Esq.
California Bar #279869

The most common way a BAA reaches my desk

You already have a ChatGPT or Claude draft of a BAA

The clause language is probably fine. The required elements of 45 CFR 164.504(e) are public and stable, so a model reproduces them accurately. The risk is the six things it had no way to know, because none of them are in its training data or in your prompt.

1. The form you will actually signThe counterparty usually sends its own. The model drafted the wrong paper.
2. Whether your stack can perform itA 24-hour breach promise is only as good as your logging. The model never saw it.
3. Which cloud services are eligibleYour cloud BAA covers a published list of services, not your whole account.
4. Whether 42 CFR Part 2 appliesA separate federal regime with its own redisclosure limits. Compliance date: 16 February 2026.
5. Whether California's CMIA appliesA health app can be a “provider of health care” under Civil Code 56.06 with no HIPAA in sight.
6. How it interacts with your MSAAn uncapped BAA indemnity outside your MSA cap becomes the largest exposure in the deal.

$750 flat covers one Business Associate Agreement, drafted from your facts or redlined against the counterparty's form, with written comments on the terms that matter and up to three rounds of email revisions. Scope is confirmed in writing after a conflict check. I do not review documents for free, and nothing here creates an attorney-client relationship.

Short answer

45 CFR 164.502(e)(2) requires a written contract before a covered entity lets a vendor touch protected health information. 164.504(e)(2) says what it must contain. That list is shorter than people expect: it requires no indemnification, no insurance, no audit rights, no named encryption standard, no certificate of destruction, and no breach deadline shorter than the 60 calendar days in 164.410(b). Every one of those shows up in real BAAs anyway, because the counterparty put them there. That is the document worth paying for, not the one you generate.

What 45 CFR 164.504(e) actually requires, and what it does notThe full required-elements list against the terms people assume are mandatory but are not

Required by 45 CFR 164.504(e)(2)

  • Establish the permitted and required uses and disclosures of PHI; the contract may not authorize a use that would violate the Privacy Rule if the covered entity did it
  • Not use or further disclose PHI other than as the contract permits or law requires
  • Use appropriate safeguards and comply with the Security Rule for electronic PHI
  • Report uses or disclosures not provided for by the contract, including breaches required to be reported under 164.410
  • Ensure subcontractors agree to the same restrictions and conditions
  • Make PHI available for individual access (164.524), for amendment (164.526), and for an accounting of disclosures (164.528)
  • Carry out the covered entity's own Privacy Rule obligations where it performs them
  • Make internal practices, books, and records available to the Secretary of HHS
  • At termination, return or destroy all PHI if feasible; if not, extend the contract's protections and limit further use
  • Authorize the covered entity to terminate for a material violation

Plus 164.314(a)(2)(i): comply with the Security Rule, flow it down to subcontractors, report security incidents.

Not required by the regulation

  • Indemnification of any kind
  • Cyber liability or errors-and-omissions insurance, at any limit
  • Audit rights, on-site inspection, or a right to test your systems
  • Any breach-notice deadline shorter than 60 calendar days after discovery
  • A named encryption standard, SOC 2, or HITRUST certification
  • A written certificate of destruction
  • Prior approval or a veto over your subcontractors (flow-down is required; a veto is not)
  • A prohibition on storing or accessing PHI outside the United States
  • Breach remediation cost-shifting, credit monitoring, or notification cost allocation

Absent from 164.504(e)(2) and 164.314(a)(2)(i). Every one of them is a negotiated commercial term.

Why this matters more than it sounds. Once you know which obligations are regulatory and which are commercial, the negotiation changes shape. You cannot argue with (A) through (J). You can absolutely argue with a $5 million cyber policy and an unlimited on-site audit right, and you should, because those are the terms that decide whether the deal is economic.

Verified against the current text of 45 CFR 164.504, 164.314, 164.410, and 164.502 on eCFR (title 45, edition of 30 July 2026).

The eight terms that actually get negotiatedTap any card to see what the form usually says and the position that tends to get accepted

These are the terms I spend my time on in a BAA negotiation. The front of each card is the ask. The back is where it usually lands. This is my own experience negotiating these agreements, not a rule of law, and no position is guaranteed to be accepted.

Signing your cloud provider's BAA does not cover your whole accountBoth AWS and Google Cloud scope their BAA to a published list of services. A generated BAA has no idea what is on yours.

This is the single most common gap I find between a BAA a company has signed and the infrastructure it actually runs. The BAA is executed, the compliance box is ticked, and PHI is sitting in a service the provider never agreed to cover.

“If you are a Covered Entity or Business Associate as defined by the Health Insurance Portability and Accountability Act of 1996 (as amended, ‘HIPAA’), you agree not to use these HIPAA Eligible Services for any purpose or in any manner involving Protected Health Information (as defined by HIPAA) without first entering into an AWS business associate agreement.”Amazon Web Services, HIPAA Eligible Services Reference (list last updated 22 July 2026). The same page notes that services not on the list may still be used provided they do not process or store ePHI.
“The Google Cloud BAA covers Google Cloud's entire infrastructure (all regions, all zones, all network paths, all points of presence), and the following products…”Google Cloud, HIPAA compliance guidance, followed by an enumerated list of covered products. The same guidance directs customers not to use pre-general-availability offerings with PHI unless expressly noted.
What this means in practice. Executing the addendum is step one of two. Step two is auditing which services in your account actually touch PHI and confirming each is on the provider's current list. A newly launched service, a preview feature, or a convenient third-party integration can put you outside the addendum without anyone noticing. No generated document can perform that check, because it does not know your architecture.

Quotations retrieved from aws.amazon.com and cloud.google.com. Both lists change; verify against the provider's current page before relying on this.

42 CFR Part 2 and the California CMIA: two overlays a generic BAA missesSeparate regimes with their own redisclosure limits, their own penalties, and in California a product-architecture requirement that no contract clause satisfies

42 CFR Part 2: substance use disorder records

If any of the data is substance use disorder treatment information from a Part 2 program, a standard BAA is not sufficient on its own. The rule was substantially revised in 2024 and the transition period is over.

The compliance date has passed“Effective date: This final rule is effective on April 16, 2024. Compliance date: Persons subject to this regulation must comply with the applicable requirements of this final rule by February 16, 2026.” 89 FR 12472
HIPAA breach notification now applies45 CFR Part 160 and Subpart D of Part 164 apply to Part 2 programs for breaches of unsecured records in the same manner as they apply to a covered entity. 42 CFR 2.16(b)
HIPAA-level penalties now applyViolations are subject to the penalties under sections 1176 and 1177 of the Social Security Act, 42 U.S.C. 1320d-5 and 1320d-6. 42 CFR 2.3(a)
A redisclosure carve-out your BAA does not carryRecords disclosed for treatment, payment, or health care operations may be redisclosed under HIPAA except for use in civil, criminal, administrative, and legislative proceedings against the patient. 42 CFR 2.33(b)(1)
The trap. A standard BAA's permitted-uses clause tracks HIPAA. It says nothing about the litigation carve-out in 2.33(b)(1), nothing about the intermediary disclosure list in 2.24, and nothing about the patient notice in 2.22. If Part 2 data is in scope, that belongs in a schedule to the BAA, not in the boilerplate.

California CMIA: Civil Code section 56 and following

California is the overlay most health-technology founders get wrong, because it can apply when HIPAA does not. There is no BAA to stand behind, because there is no covered entity in the chain.

Your app may be a “provider of health care”A business offering software or hardware to consumers, including a mobile application, designed to maintain medical information “shall be deemed to be a provider of health care subject to the requirements of this part.” Subdivisions (d) and (e) extend this to mental health digital services and to reproductive or sexual health digital services. Civ. Code 56.06(b), (d), (e)
Redisclosure is restricted by statuteA recipient of medical information may not further disclose it except under a new authorization meeting section 56.11, or as specifically required or permitted by the chapter or by law. Civ. Code 56.13
Segregation is an engineering requirementA section 56.06 business storing information on sensitive services had to be able, on or before 1 July 2024, to limit access privileges, prevent out-of-state disclosure or processing, segregate information on gender affirming care, abortion and abortion-related services, and contraception from the rest of the record, and automatically disable out-of-state access to it. Civ. Code 56.101(c)(1)
Damages without proof of harmNominal damages of $1,000 are available for a negligent release without the plaintiff showing actual damages, plus an administrative fine or civil penalty of up to $2,500 per violation for negligent disclosure. Civ. Code 56.36(b)(1), (c)(1)
Read section 56.101(c) again. Limiting access, geo-fencing, segregating a category of record, and disabling out-of-state access are things your product either does or does not do. No clause in a BAA creates that capability, and no generated document will tell you that a California statute already required it two years ago.

Part 2 text verified against eCFR (title 42, edition of 30 July 2026); dates verified against the final rule at 89 FR 12472 on federalregister.gov. California text verified against leginfo.legislature.ca.gov. Section 56.101 as amended by Stats. 2024, ch. 853, sec. 9 (AB 3281), effective 1 January 2025. Whether either regime applies to your data is a fact question I would want to look at before you rely on any of this.

Do you even need a BAA?Three lines in the regulation decide it, and two of them cut the other way from what people assume
SituationBAA needed?Why
Covered entity discloses PHI to another provider for the patient's treatmentNoThe definition of business associate expressly excludes “a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual.” 45 CFR 160.103(4)(i)
Your vendor hires a downstream vendor that touches PHIYes, and you are the one who signs itA subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate is itself a business associate. The covered entity is not required to obtain assurances from it; the business associate is. 45 CFR 160.103(3)(iii), 164.502(e)(1)(i) and (ii), 164.504(e)(5)
A transmission or connectivity service that needs routine access to PHIYesA Health Information Organization, E-prescribing Gateway, or other person providing data transmission services that requires access on a routine basis is included in the definition. 45 CFR 160.103(3)(i)
A consumer health app with no covered-entity customerOften no BAA, but that is not the end of itWith no covered entity in the chain there is no business associate relationship. California's CMIA can still apply directly under Civil Code 56.06, and other state health-privacy statutes may as well. The absence of a BAA is not the absence of regulation.
The question I actually get asked. “They sent us a BAA. Do we have to sign it?” Usually the better question is whether you are a business associate at all, because if you are not, signing one voluntarily imports obligations, audit rights, and indemnities you had no legal duty to accept. That analysis takes documents and about an hour. It is worth doing before you sign, not after.
Questions I get about BAAsBreach timing, AI drafts, cloud coverage, and when a BAA is not required
How fast must a business associate report a breach?

45 CFR 164.410(b) requires notice to the covered entity without unreasonable delay and in no case later than 60 calendar days after discovery. Discovery is defined in 164.410(a)(2) as the first day the breach is known, or by reasonable diligence would have been known, to the business associate, including any employee, officer, or agent other than the person who committed it. That 60 days is the regulatory ceiling, not the market term. Most forms compress it, and some start the clock at the incident rather than at discovery, which is a materially harder promise than the rule imposes.

Is an AI-generated BAA safe to sign?

The clause language is usually fine, because the required elements are public and stable. The danger is elsewhere: the model does not know the counterparty's form, cannot tell you whether your infrastructure can perform the obligations it just drafted, and has no way to know whether 42 CFR Part 2 or the California CMIA applies to your data. An AI draft is a reasonable first pass and a poor last one.

We signed our cloud provider's BAA. Are we covered?

Only for the services the provider actually scoped in. AWS publishes a HIPAA Eligible Services Reference and conditions PHI use on executing its business associate agreement; services not on that list may be used only if they do not process or store ePHI. Google Cloud scopes its BAA to its infrastructure plus an enumerated product list and tells customers not to use pre-general-availability offerings with PHI. Executing the addendum is necessary. It is not sufficient.

Does my subcontractor need its own BAA?

Yes, and you are the one who signs it. 45 CFR 160.103 includes a subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate within the definition of business associate. Under 164.502(e)(1)(i) the covered entity is not required to obtain satisfactory assurances from that subcontractor; under 164.502(e)(1)(ii) you are, and 164.504(e)(5) applies the same contract requirements downstream.

Can I just use the free generator below?

For a low-risk vendor relationship where you control the paper and there is no Part 2 or CMIA question, a generated BAA plus a careful read is a defensible starting point, and I built the generator so that it would be. Where I would not rely on it: when the counterparty sends its own form, when your product is the thing holding the data, when substance use disorder or California sensitive-services data is in scope, or when the BAA sits next to an MSA whose liability cap it might override.

Free BAA generator: a starting point, not a signable documentFill the form and the document builds in place. Export to Word, PDF, or print is a separate paid unlock shown inside the tool. Use it to build your own paper before the counterparty sends theirs.
Read this before you use the output. This generator produces a standard BAA addressing the required elements of 45 CFR 164.504(e). It does not know your counterparty's form, your vendor stack, or whether 42 CFR Part 2 or the California CMIA applies to your data. It is not legal advice and using it does not make me your attorney.

Work with me on it

If a single BAA is all you need, buy the single BAA. Plenty of companies have a good MSA, a real privacy policy, and one vendor relationship that needs papering. That is a $750 job and I will tell you so rather than sell you a stack you do not need.

One Business Associate Agreement

$750

Drafted from your facts, or redlined against their form. Either side of the table.

  • Attorney drafting or redline of one BAA
  • Written comments on the terms that matter: breach timing, audit rights, indemnity, insurance, subprocessors, data return
  • How the BAA interacts with the liability cap in your underlying agreement
  • Up to three rounds of email revisions
Request the BAA, $750
When one document is not enough

Healthcare SaaS Legal Package

$2,500

For a product that is the thing holding the data, where the documents have to agree with each other.

  • MSA and order form, Terms of Service, Privacy Policy, DPA framework
  • HIPAA BAA, with a 42 CFR Part 2 or CMIA schedule where your data needs one
  • HIPAA applicability analysis for your actual data flows, including the BAA-versus-no-BAA question
  • Compliance gap memo across the vendor stack: hosting, email, payments, AI
  • Two consolidated revision rounds
Request this package, $2,500
Why coordination is a real thing and not an upsellFour ways a BAA drafted in isolation contradicts the documents around it

A BAA drafted on its own routinely fights the paper around it. Its indemnity escapes the MSA's liability cap. Its permitted-uses clause allows something the privacy policy promises you will not do. Its subcontractor flow-down does not match the subprocessor list in the DPA. Its data-return deadline is shorter than the retention period in the terms of service. Each is survivable alone. Together they are what a procurement team finds and what a plaintiff's lawyer reads first. If your documents came from four different sources, that is the problem worth paying to fix. If they did not, buy the $750 BAA.

Side-by-side comparison of the two routes on the Healthcare SaaS Legal Package page. Narrower question first? A $240 Written Attorney Consultation gets a written answer on one issue. No free consultations, case evaluations, or document review.

See a BAA negotiated, not just generated

This is how I actually work through a BAA with a client: live preview with surgical highlighting, click-any-clause comments, and track-changes style suggestions. Change a breach-notice window and watch the room flag the consequence. Fictional demo data.

Disclaimer. Everything on this page is general legal information, not legal advice, and it is not a substitute for advice about your own situation. Using the generator, reading this page, or emailing me does not create an attorney-client relationship; that requires a conflict check and a written engagement agreement. Regulations and California statutes change, and the citations here were verified on the dates noted. I make no claim that any document generated here, or drafted by me, results in HIPAA “certification,” and I do not guarantee any outcome. I do not carry professional liability (malpractice) insurance, and I give you that disclosure in writing with every engagement agreement.

Sergei Tokmakov, Esq. · California Bar #279869 · owner@terms.law