HIPAA Business Associate Agreement Generator and Attorney Review
The generator is further down this page and it is free. But the BAA you sign is almost never the one you generate. It is the counterparty's form, and what that form adds on top of 45 CFR 164.504(e) is where the liability sits.
I am Sergei Tokmakov, a California attorney, CA Bar #279869, licensed since 2011. I draft and redline BAAs on either side of the table.
California Bar #279869
The most common way a BAA reaches my desk
You already have a ChatGPT or Claude draft of a BAA
The clause language is probably fine. The required elements of 45 CFR 164.504(e) are public and stable, so a model reproduces them accurately. The risk is the six things it had no way to know, because none of them are in its training data or in your prompt.
$750 flat covers one Business Associate Agreement, drafted from your facts or redlined against the counterparty's form, with written comments on the terms that matter and up to three rounds of email revisions. Scope is confirmed in writing after a conflict check. I do not review documents for free, and nothing here creates an attorney-client relationship.
Short answer
45 CFR 164.502(e)(2) requires a written contract before a covered entity lets a vendor touch protected health information. 164.504(e)(2) says what it must contain. That list is shorter than people expect: it requires no indemnification, no insurance, no audit rights, no named encryption standard, no certificate of destruction, and no breach deadline shorter than the 60 calendar days in 164.410(b). Every one of those shows up in real BAAs anyway, because the counterparty put them there. That is the document worth paying for, not the one you generate.
What 45 CFR 164.504(e) actually requires, and what it does notThe full required-elements list against the terms people assume are mandatory but are not
Required by 45 CFR 164.504(e)(2)
- Establish the permitted and required uses and disclosures of PHI; the contract may not authorize a use that would violate the Privacy Rule if the covered entity did it
- Not use or further disclose PHI other than as the contract permits or law requires
- Use appropriate safeguards and comply with the Security Rule for electronic PHI
- Report uses or disclosures not provided for by the contract, including breaches required to be reported under 164.410
- Ensure subcontractors agree to the same restrictions and conditions
- Make PHI available for individual access (164.524), for amendment (164.526), and for an accounting of disclosures (164.528)
- Carry out the covered entity's own Privacy Rule obligations where it performs them
- Make internal practices, books, and records available to the Secretary of HHS
- At termination, return or destroy all PHI if feasible; if not, extend the contract's protections and limit further use
- Authorize the covered entity to terminate for a material violation
Plus 164.314(a)(2)(i): comply with the Security Rule, flow it down to subcontractors, report security incidents.
Not required by the regulation
- Indemnification of any kind
- Cyber liability or errors-and-omissions insurance, at any limit
- Audit rights, on-site inspection, or a right to test your systems
- Any breach-notice deadline shorter than 60 calendar days after discovery
- A named encryption standard, SOC 2, or HITRUST certification
- A written certificate of destruction
- Prior approval or a veto over your subcontractors (flow-down is required; a veto is not)
- A prohibition on storing or accessing PHI outside the United States
- Breach remediation cost-shifting, credit monitoring, or notification cost allocation
Absent from 164.504(e)(2) and 164.314(a)(2)(i). Every one of them is a negotiated commercial term.
Verified against the current text of 45 CFR 164.504, 164.314, 164.410, and 164.502 on eCFR (title 45, edition of 30 July 2026).
The eight terms that actually get negotiatedTap any card to see what the form usually says and the position that tends to get accepted
These are the terms I spend my time on in a BAA negotiation. The front of each card is the ask. The back is where it usually lands. This is my own experience negotiating these agreements, not a rule of law, and no position is guaranteed to be accepted.
Signing your cloud provider's BAA does not cover your whole accountBoth AWS and Google Cloud scope their BAA to a published list of services. A generated BAA has no idea what is on yours.
This is the single most common gap I find between a BAA a company has signed and the infrastructure it actually runs. The BAA is executed, the compliance box is ticked, and PHI is sitting in a service the provider never agreed to cover.
“If you are a Covered Entity or Business Associate as defined by the Health Insurance Portability and Accountability Act of 1996 (as amended, ‘HIPAA’), you agree not to use these HIPAA Eligible Services for any purpose or in any manner involving Protected Health Information (as defined by HIPAA) without first entering into an AWS business associate agreement.”Amazon Web Services, HIPAA Eligible Services Reference (list last updated 22 July 2026). The same page notes that services not on the list may still be used provided they do not process or store ePHI.
“The Google Cloud BAA covers Google Cloud's entire infrastructure (all regions, all zones, all network paths, all points of presence), and the following products…”Google Cloud, HIPAA compliance guidance, followed by an enumerated list of covered products. The same guidance directs customers not to use pre-general-availability offerings with PHI unless expressly noted.
Quotations retrieved from aws.amazon.com and cloud.google.com. Both lists change; verify against the provider's current page before relying on this.
42 CFR Part 2 and the California CMIA: two overlays a generic BAA missesSeparate regimes with their own redisclosure limits, their own penalties, and in California a product-architecture requirement that no contract clause satisfies
42 CFR Part 2: substance use disorder records
If any of the data is substance use disorder treatment information from a Part 2 program, a standard BAA is not sufficient on its own. The rule was substantially revised in 2024 and the transition period is over.
89 FR 1247242 CFR 2.16(b)42 CFR 2.3(a)42 CFR 2.33(b)(1)California CMIA: Civil Code section 56 and following
California is the overlay most health-technology founders get wrong, because it can apply when HIPAA does not. There is no BAA to stand behind, because there is no covered entity in the chain.
Civ. Code 56.06(b), (d), (e)Civ. Code 56.13Civ. Code 56.101(c)(1)Civ. Code 56.36(b)(1), (c)(1)Part 2 text verified against eCFR (title 42, edition of 30 July 2026); dates verified against the final rule at 89 FR 12472 on federalregister.gov. California text verified against leginfo.legislature.ca.gov. Section 56.101 as amended by Stats. 2024, ch. 853, sec. 9 (AB 3281), effective 1 January 2025. Whether either regime applies to your data is a fact question I would want to look at before you rely on any of this.
Do you even need a BAA?Three lines in the regulation decide it, and two of them cut the other way from what people assume
| Situation | BAA needed? | Why |
|---|---|---|
| Covered entity discloses PHI to another provider for the patient's treatment | No | The definition of business associate expressly excludes “a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual.” 45 CFR 160.103(4)(i) |
| Your vendor hires a downstream vendor that touches PHI | Yes, and you are the one who signs it | A subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate is itself a business associate. The covered entity is not required to obtain assurances from it; the business associate is. 45 CFR 160.103(3)(iii), 164.502(e)(1)(i) and (ii), 164.504(e)(5) |
| A transmission or connectivity service that needs routine access to PHI | Yes | A Health Information Organization, E-prescribing Gateway, or other person providing data transmission services that requires access on a routine basis is included in the definition. 45 CFR 160.103(3)(i) |
| A consumer health app with no covered-entity customer | Often no BAA, but that is not the end of it | With no covered entity in the chain there is no business associate relationship. California's CMIA can still apply directly under Civil Code 56.06, and other state health-privacy statutes may as well. The absence of a BAA is not the absence of regulation. |
Questions I get about BAAsBreach timing, AI drafts, cloud coverage, and when a BAA is not required
How fast must a business associate report a breach?
45 CFR 164.410(b) requires notice to the covered entity without unreasonable delay and in no case later than 60 calendar days after discovery. Discovery is defined in 164.410(a)(2) as the first day the breach is known, or by reasonable diligence would have been known, to the business associate, including any employee, officer, or agent other than the person who committed it. That 60 days is the regulatory ceiling, not the market term. Most forms compress it, and some start the clock at the incident rather than at discovery, which is a materially harder promise than the rule imposes.
Is an AI-generated BAA safe to sign?
The clause language is usually fine, because the required elements are public and stable. The danger is elsewhere: the model does not know the counterparty's form, cannot tell you whether your infrastructure can perform the obligations it just drafted, and has no way to know whether 42 CFR Part 2 or the California CMIA applies to your data. An AI draft is a reasonable first pass and a poor last one.
We signed our cloud provider's BAA. Are we covered?
Only for the services the provider actually scoped in. AWS publishes a HIPAA Eligible Services Reference and conditions PHI use on executing its business associate agreement; services not on that list may be used only if they do not process or store ePHI. Google Cloud scopes its BAA to its infrastructure plus an enumerated product list and tells customers not to use pre-general-availability offerings with PHI. Executing the addendum is necessary. It is not sufficient.
Does my subcontractor need its own BAA?
Yes, and you are the one who signs it. 45 CFR 160.103 includes a subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate within the definition of business associate. Under 164.502(e)(1)(i) the covered entity is not required to obtain satisfactory assurances from that subcontractor; under 164.502(e)(1)(ii) you are, and 164.504(e)(5) applies the same contract requirements downstream.
Can I just use the free generator below?
For a low-risk vendor relationship where you control the paper and there is no Part 2 or CMIA question, a generated BAA plus a careful read is a defensible starting point, and I built the generator so that it would be. Where I would not rely on it: when the counterparty sends its own form, when your product is the thing holding the data, when substance use disorder or California sensitive-services data is in scope, or when the BAA sits next to an MSA whose liability cap it might override.
Free BAA generator: a starting point, not a signable documentFill the form and the document builds in place. Export to Word, PDF, or print is a separate paid unlock shown inside the tool. Use it to build your own paper before the counterparty sends theirs.
Work with me on it
If a single BAA is all you need, buy the single BAA. Plenty of companies have a good MSA, a real privacy policy, and one vendor relationship that needs papering. That is a $750 job and I will tell you so rather than sell you a stack you do not need.
One Business Associate Agreement
Drafted from your facts, or redlined against their form. Either side of the table.
- Attorney drafting or redline of one BAA
- Written comments on the terms that matter: breach timing, audit rights, indemnity, insurance, subprocessors, data return
- How the BAA interacts with the liability cap in your underlying agreement
- Up to three rounds of email revisions
Healthcare SaaS Legal Package
For a product that is the thing holding the data, where the documents have to agree with each other.
- MSA and order form, Terms of Service, Privacy Policy, DPA framework
- HIPAA BAA, with a 42 CFR Part 2 or CMIA schedule where your data needs one
- HIPAA applicability analysis for your actual data flows, including the BAA-versus-no-BAA question
- Compliance gap memo across the vendor stack: hosting, email, payments, AI
- Two consolidated revision rounds
Why coordination is a real thing and not an upsellFour ways a BAA drafted in isolation contradicts the documents around it
A BAA drafted on its own routinely fights the paper around it. Its indemnity escapes the MSA's liability cap. Its permitted-uses clause allows something the privacy policy promises you will not do. Its subcontractor flow-down does not match the subprocessor list in the DPA. Its data-return deadline is shorter than the retention period in the terms of service. Each is survivable alone. Together they are what a procurement team finds and what a plaintiff's lawyer reads first. If your documents came from four different sources, that is the problem worth paying to fix. If they did not, buy the $750 BAA.
Side-by-side comparison of the two routes on the Healthcare SaaS Legal Package page. Narrower question first? A $240 Written Attorney Consultation gets a written answer on one issue. No free consultations, case evaluations, or document review.
See a BAA negotiated, not just generated
This is how I actually work through a BAA with a client: live preview with surgical highlighting, click-any-clause comments, and track-changes style suggestions. Change a breach-notice window and watch the room flag the consequence. Fictional demo data.
Disclaimer. Everything on this page is general legal information, not legal advice, and it is not a substitute for advice about your own situation. Using the generator, reading this page, or emailing me does not create an attorney-client relationship; that requires a conflict check and a written engagement agreement. Regulations and California statutes change, and the citations here were verified on the dates noted. I make no claim that any document generated here, or drafted by me, results in HIPAA “certification,” and I do not guarantee any outcome. I do not carry professional liability (malpractice) insurance, and I give you that disclosure in writing with every engagement agreement.
Sergei Tokmakov, Esq. · California Bar #279869 · owner@terms.law