Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

Business associate agreements for research vendors

What is a business associate agreement, who counts as a business associate in research, what a BAA must contain, and which vendors will refuse to sign one.

Ask about Business associate agreements for research vendors

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

When the BAA is for signatures · Verified 18 August 2026

Sign.Plus — a BAA on a published price rather than a sales call

Enterprise $49.99/mo (HIPAA + BAA) · free tier for testing

Read the definition below before you buy anything — most people arriving at this page do not need new software at all, they need a determination and a signature. But there is one recurring exception. If the vendor relationship that triggered this whole question is your e-signature tool, because consent forms, delegation logs, data use agreements and the BAA itself all get signed somewhere, Sign.Plus is the pick we keep landing on for research offices. HIPAA support with a Business Associate Agreement sits on Enterprise at $49.99/mo — a published list price you can budget against, rather than the “contact sales” quote that the better-known signature platforms route you into for the same capability. Below that, Professional is $19.99/mo for unlimited signature requests and Business is $29.99/mo. Verified 18 August 2026. The detail that matters for a research office is that the tamper-evident audit trail and eIDAS-compliant signatures are on every tier, including the free plan of three requests — so you can run a real consent or delegation workflow end to end, show it to your privacy office, and only then commit to the tier that carries the agreement. Just be clear about what you are buying: the BAA covers signature documents that contain PHI. It does not turn Sign.Plus into a place to store a study database.

Try Sign.Plus free Opens on the vendor’s site · CASRAI referral link

If the vendor in question is your fax line → — Fax.Plus carries HIPAA and a BAA on Enterprise at $79.99/mo (4,000 pages) and on no tier below it. Verified 18 August 2026.

Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.

In summary

  • A business associate agreement is a contract required by the HIPAA Privacy and Security Rules whenever an outside organisation creates, receives, maintains or transmits protected health information on behalf of a covered entity.
  • IRB approval, informed consent and a data use agreement are all different instruments. None of them substitutes for a BAA, and a BAA does not substitute for any of them.
  • The test is not “is this vendor trustworthy?” but “does PHI reach them, and are they doing it on our behalf?” A cloud host that never opens the data is still a business associate.
  • Subcontractors need their own BAA with the business associate above them, all the way down the chain — your vendor’s vendors are in scope even though you never signed anything with them.
  • Several vendor categories will not sign a BAA at all, and many gate it behind a top tier. Sign.Plus publishes that tier: Enterprise $49.99/mo, with audit trails and eIDAS on every plan including the free one. Verified 18 August 2026.

Is this research vendor a business associate?

A starting point for the determination, not the determination itself — the answer always turns on whether identifiable protected health information actually reaches the vendor, and on your own institution’s policy. Confirm with your privacy office before signing.

Dimension Business associate? Why What to do
Commercial REDCap or eCRF host (vendor-hosted) Yes They maintain PHI on your behalf, even if no employee ever reads a record BAA before a single record is entered; check whether backups and support access are in scope
REDCap hosted by your own institution No No outside organisation is involved — this is internal use by the covered entity No BAA needed; internal policy, access controls and IRB approval still apply
Transcription service for participant interviews Usually yes Recordings of identifiable participants discussing health are PHI in a covered-entity context BAA, plus a written retention and deletion commitment — audio lingers on transcription platforms
Participant recruitment agency Depends on direction of flow Sending them your patient list makes them a business associate; them sending you volunteers who self-identified generally does not Map which way the identifiers move before you assume; many agencies are one and then the other
Cloud storage, backup or file transfer Yes, including “no-knowledge” and encrypted-only providers Merely maintaining or transmitting PHI is enough — the conduit exception is narrow and does not cover persistent storage BAA; confirm which specific products in the suite are named as covered services
E-signature platform holding consent or PHI-bearing documents Yes Signed documents containing identifiers sit on their infrastructure BAA — and check which plan carries it, because this is routinely a top-tier feature
External statistician receiving a de-identified dataset No De-identified data is not PHI, so HIPAA’s business associate rules do not attach Use a data use agreement instead; keep the de-identification method documented
External statistician receiving a limited data set No, but not unregulated A limited data set is governed by a data use agreement rather than a BAA Execute a DUA with the required prohibition on re-identification and contact
IRB, ethics committee or accreditation body Generally no Oversight bodies exercising their own regulatory function are not acting on your behalf Do not force a BAA on them; treat as a required disclosure instead
Courier, post or an ordinary telephone line No — conduit exception Transient transport with no access to content and no storage Nothing to sign; note that most digital “conduits” do store, which breaks the analogy
Marketing, advertising and analytics platforms Usually refuse outright Their terms typically prohibit PHI entirely rather than offering an agreement Keep PHI off these systems; assume no BAA is coming and design around it

Two failure modes account for most of the trouble here. The first is treating the BAA as a formality and never reading which products in a vendor’s suite the agreement actually names. The second is the reverse — demanding a BAA from an organisation that is not a business associate at all, which delays the contract by weeks and teaches your vendors that your compliance requests are noise.

What a business associate agreement actually is

Three definitions do all the work, and the rest of this page is mechanical.

A covered entity is a health plan, a healthcare clearinghouse, or a provider that transmits health information electronically in connection with certain standard transactions. Most academic medical centres are covered entities, or hybrid entities whose clinical components are covered and whose academic ones are not — which is why a research administrator can end up on either side of this question.

Protected health information is individually identifiable health information held or transmitted by a covered entity or its business associate, in any form. The word doing the work is identifiable: strip the identifiers properly and the data leaves HIPAA’s scope entirely.

A business associate is a person or organisation that creates, receives, maintains or transmits PHI on behalf of a covered entity, for a function the covered entity would otherwise do itself. The business associate agreement, or BAA, is the written contract HIPAA requires before that relationship begins.

Two things follow that surprise people. First, “maintains” and “transmits” are enough on their own: a hosting provider that never decrypts your data and could not read it if it wanted to is still a business associate. Security posture is irrelevant to the classification. Second: a signed BAA is a contract, not a security control. It allocates liability and gives you a remedy when the vendor fails. It does not encrypt anything, configure anything, or stop a breach. It is the paperwork that lets the security work begin, not evidence that it is done.

Who needs a BAA, and who does not

The test has two parts and both must be true. Does protected health information reach this organisation? And are they handling it on your behalf, performing a function you would otherwise perform yourself? If either answer is no, there is no business associate relationship and nothing to sign.

That second clause separates a vendor from a recipient. Send data to another researcher for their own independent study and they are not acting on your behalf — that is a disclosure, governed by consent and usually a data use agreement. Send the same data to a company that will clean and host it for you and it is a BAA. The data is identical; the relationship is not.

The recurring hard cases are worth naming. A commercially hosted study database is the clearest yes. A transcription service is nearly always a yes and is the most commonly missed, because a recording of a participant describing their symptoms is as identifiable as anything in the chart. A recruitment agency depends on which way the identifiers flow: give them a list of your patients to screen and they are a business associate; receive self-identified volunteers from them and generally they are not.

The exclusions matter as much. Your own workforce is not a business associate, nor is another covered entity treating the same patient, nor an oversight body acting in its regulatory capacity. And the conduit exception — why you have no BAA with the postal service — is narrower than vendors imply: it covers transient transmission with no access to content and no storage, which almost every digital service marketing itself as “just a pipe” fails. Our guide to HIPAA-compliant form builders runs the same test across that category.

What the agreement must contain

You are about to go and find the sample text, so here it is. The US Department of Health and Human Services publishes sample business associate agreement provisions alongside its guidance on business associates. Read the source rather than a summary, including this one: the required elements are specific and a vendor’s redline will target exactly them.

In outline, a compliant agreement establishes the permitted and required uses and disclosures of PHI and bars anything beyond them; obliges the business associate to apply appropriate safeguards, including the Security Rule requirements for electronic PHI; requires reporting of any use or disclosure not provided for, including breaches of unsecured PHI; extends the same obligations to subcontractors; requires PHI to be made available for individual access, amendment and accounting-of-disclosures requests; makes records available to HHS; and provides for return or destruction of PHI at termination, with a right to terminate for material breach.

Research contracts go wrong in the clauses HHS does not draft for you. Breach notification timing is the one to negotiate hardest: your own reporting clock can start when your business associate’s discovery is imputed to you, so a template offering notification “without unreasonable delay” and nothing firmer leaves you exposed. Ask for a number in days. Return or destruction at termination collides with research reality, because you may be required to retain study records for years after a vendor contract ends.

One practical note: your institution has a template, and it is almost always better to start from it than from the vendor’s. The party whose paper you start on wins most of the small clauses by default.

HIPAA, the Common Rule, and why IRB approval is not enough

Human subjects research in the US sits under two regimes that were written separately, use different vocabulary, and are enforced by different bodies. The Common Rule governs ethics and oversight: IRB review, informed consent, risk-benefit assessment, protections for vulnerable populations. HIPAA’s Privacy Rule governs how covered entities may use and disclose protected health information, whether or not any research is happening.

The failure mode is assuming ethics approval settles the vendor question. It does not. IRB approval tells you the study may proceed and on what terms; a BAA tells you a specific outside organisation may handle the data. You can hold a beautifully documented approval and still be non-compliant because a transcription vendor named nowhere in the protocol has been receiving interview audio for four months.

The useful move is to make the two processes talk to each other: when a protocol lists external vendors, that list should reach whoever executes BAAs. Studies get into difficulty when a tool is adopted mid-study by a coordinator solving a real problem quickly, as covered in our note on compliance frameworks for research institutions.

Keep three instruments straight. De-identified data is outside HIPAA and needs no BAA, but the de-identification must follow one of the recognised methods and “we removed the names” is not one of them. A limited data set — which keeps dates and some geography — stays regulated but travels under a data use agreement. Using the wrong instrument is worse than using none.

Your vendor’s vendors are in scope too

A business associate that hands PHI to a subcontractor must itself hold a business associate agreement with that subcontractor, and the obligation runs the whole length of the chain. Your transcription vendor’s cloud host is a business associate, and so is that host’s managed backup provider. Neither has a contract with you, and you remain exposed to what happens there.

Since the HIPAA Omnibus Rule, subcontractors are directly liable for their own compliance rather than merely liable to the party above them. That does not remove your interest: a breach four layers down still produces a notification obligation that reaches you.

What to do, given you cannot audit a supply chain you cannot see. Ask in writing, before signing, which subcontractors will have access to PHI and in which countries they operate — data residency is where this most often becomes live for institutions with international sites or funder conditions. Require notice before new subcontractors with PHI access are added; a refusal is a signal. And read the vendor’s published subprocessor list if it has one, because vendors that maintain one usually have a functioning process behind it.

The realistic ceiling is that you are buying assurance, not control. Prefer vendors whose chain is short and documented, and treat an evasive answer as the finding it is.

Which vendors will not sign — and what to do about it

Before you spend three weeks chasing a signature, know which categories are unlikely to give you one.

Consumer and free tiers, almost universally. A vendor offering a BAA on its enterprise plan will not offer it on the free one, and the personal account your coordinator has been using is not covered by your institution’s agreement with the same vendor. This is the most common quiet gap in academic health settings.

Marketing, advertising and analytics platforms. These typically prohibit PHI outright rather than offering an agreement, and regulators have taken a dim view of tracking technologies in a clinical context.

Small specialist tools with no compliance function. A niche product built by four people may have no legal capacity to take on business associate liability, and will say so — a more useful answer than a signature from someone who has not read it.

Everyone else — but only on the top tier. That is the norm across communications and document tooling, and it is why the price of compliance is usually a plan upgrade rather than a separate line item.

You will want to compare against the platform you already know. DocuSign is the category default for good reasons: the deepest integration ecosystem, the widest institutional familiarity, and a compliance organisation that will engage seriously with a university contracts office. We do not publish its pricing — we only quote figures we have read off a vendor pricing page and date-stamped, and its regulated tiers are quoted rather than listed. That is the whole point for a department-scale purchase: when the BAA-bearing tier has a published number, you can budget it in an afternoon instead of opening a sales cycle over a small monthly subscription. Our e-signature comparison for research offices and the Sign.Plus review go deeper.

Do not buy anything off this page if your institution already holds an enterprise agreement covering the function — Microsoft 365, Google Workspace, DocuSign, an institution-hosted REDCap. Ask your IT or contracts office for the list of in-scope covered services under the BAAs your organisation has already executed. That list exists, most researchers have never seen it, and it routinely turns a procurement into a configuration change.

When the BAA you need is for signatures

Consent forms, delegation logs and the BAA itself all have to be signed somewhere. Sign.Plus carries HIPAA support and a Business Associate Agreement on Enterprise at $49.99/mo — a published price rather than a sales call — with tamper-evident audit trails and eIDAS signatures on every tier including the free plan of three requests, so you can test the workflow before you commit. Verified 18 August 2026.

From $9.99/mo · unlimited requests at $19.99/mo

See Sign.Plus plans Opens on the vendor’s site · CASRAI referral link

Frequently asked questions

What is a business associate agreement in plain English?

It is a written contract a HIPAA covered entity must put in place before an outside organisation handles protected health information on its behalf. It sets out what the vendor may and may not do with the data, requires safeguards, obliges them to report breaches to you, extends the same duties to their subcontractors, and says what happens to the data when the relationship ends. It is a legal instrument that allocates liability — it does not itself secure anything, which is why signing one starts the compliance work rather than finishing it.

Who needs a BAA?

Any organisation that creates, receives, maintains or transmits protected health information on behalf of a covered entity, performing a function the covered entity would otherwise do itself. Both halves have to be true. A cloud host that never opens your data still qualifies because it maintains PHI for you. A collaborating researcher conducting their own independent analysis generally does not, because they are not acting on your behalf — that relationship runs on a data use agreement instead.

Do we need a BAA for research vendors if the study already has IRB approval?

Yes, where PHI reaches the vendor. IRB approval and a BAA answer different questions under different regimes — the Common Rule governs whether the research may proceed and on what ethical terms, while HIPAA governs whether a specific outside organisation may handle the health information. Approval of a protocol does not authorise a transcription service, a commercially hosted study database or an e-signature platform to hold identifiable data. Equally, a BAA does not authorise a use of data that your protocol and consent do not cover.

What has to be in a business associate agreement?

The permitted and required uses and disclosures of PHI; a commitment not to go beyond them; appropriate safeguards including the Security Rule requirements for electronic PHI; reporting of any unauthorised use or disclosure, including breaches; the same obligations flowed down to subcontractors; making PHI available for individual access, amendment and accounting requests; making records available to HHS; and return or destruction of PHI at termination. HHS publishes sample provisions covering these — read the source text, then negotiate the three clauses it leaves open: breach notification timing in days, what happens to data you must retain after the contract ends, and named subcontractor disclosure.

Is a transcription service or a REDCap host a business associate?

A commercially hosted REDCap or eCRF platform is a clear yes — it maintains identifiable study data on your behalf. A REDCap instance hosted by your own institution is not, because no outside organisation is involved. Transcription services are nearly always a yes and the most commonly missed, since a recording of a participant discussing their health is as identifiable as any chart entry. Recruitment agencies depend on the direction of flow: sending them your patient list makes them a business associate; receiving self-identified volunteers generally does not.

Which e-signature platform should we buy if we need a BAA?

If your institution already has an enterprise agreement with DocuSign or Adobe, use it — a second signature vendor is rarely worth the governance overhead, and those platforms have the deepest integration ecosystems and the most institutional familiarity. For a department buying on its own budget, Sign.Plus is our pick because the BAA-bearing tier has a published price you can approve without a sales cycle: Enterprise $49.99/mo, with Professional at $19.99/mo for unlimited requests and Business at $29.99/mo below it. Verified 18 August 2026. Tamper-evident audit trails and eIDAS-compliant signatures are included on every tier, including the free plan of three requests, so you can run a real consent workflow past your privacy office before spending anything. We do not quote competitor prices anywhere on this site — we only publish figures we have read off a vendor pricing page and date-stamped.

What happens if we discover a vendor has been handling PHI without a BAA?

Stop the flow of new data, then tell your privacy office rather than resolving it inside the study team — the missing agreement is a compliance issue in its own right, separate from whether any data was exposed. Establish what reached the vendor and when, execute the agreement if the relationship should continue, and document the gap and the remediation. The instinct to quietly backdate a signature is the worst option available: it converts a paperwork failure into a misrepresentation, and it is exactly what surfaces during a monitoring visit.

Related on CASRAI

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →