When does a health plan need a business associate agreement (BAA)?

Last updated October 2, 2026

A BAA is required whenever a vendor creates, receives, maintains, or transmits protected health information for the plan — TPAs, brokers with claims access, wellness vendors, data analysts. Without a BAA, sharing PHI with that vendor is itself a HIPAA violation.

HIPAA lets a group health plan share protected health information with service providers only under a business associate agreement that binds the vendor to HIPAA's safeguards, breach reporting, and permitted uses.

Vendors that typically require BAAs include third-party administrators, brokers and consultants who see claims or enrollment data, pharmacy benefit managers, wellness and disease-management vendors, COBRA administrators, and data-analytics providers. Carriers acting as insurers of fully-insured coverage generally do not (they're covered entities in their own right).

Good hygiene: maintain a vendor inventory noting who touches PHI, confirm a signed BAA exists for each, and review BAAs when contracts renew — vendor mergers and service changes have a way of orphaning old agreements. The inventory itself becomes evidence of a managed privacy program.

Thanks for your feedback!

Put these answers to work

Fiduciary In A Box walks your team through every one of these requirements step by step — documenting decisions, organizing files, and keeping your plan compliant year-round.

See how FIAB works