When does a health plan need a business associate agreement (BAA)?
Last updated October 2, 2026
A BAA is required whenever a vendor creates, receives, maintains, or transmits protected health information for the plan — TPAs, brokers with claims access, wellness vendors, data analysts. Without a BAA, sharing PHI with that vendor is itself a HIPAA violation.
HIPAA lets a group health plan share protected health information with service providers only under a business associate agreement that binds the vendor to HIPAA's safeguards, breach reporting, and permitted uses.
Vendors that typically require BAAs include third-party administrators, brokers and consultants who see claims or enrollment data, pharmacy benefit managers, wellness and disease-management vendors, COBRA administrators, and data-analytics providers. Carriers acting as insurers of fully-insured coverage generally do not (they're covered entities in their own right).
Good hygiene: maintain a vendor inventory noting who touches PHI, confirm a signed BAA exists for each, and review BAAs when contracts renew — vendor mergers and service changes have a way of orphaning old agreements. The inventory itself becomes evidence of a managed privacy program.
Thanks for your feedback!