Key points
- A BAA is a contract, not a security certification or product feature.
- It must describe permitted and required PHI uses and disclosures.
- It requires safeguards, incident reporting, and flow-down obligations for relevant subcontractors.
- Encryption or lack of a provider-held decryption key does not by itself remove the BAA requirement for a cloud service maintaining ePHI.
Core provisions in a BAA
HHS explains that the agreement must define permitted and required uses, prohibit other uses or disclosures, require appropriate safeguards, require reporting of uses or disclosures not provided for by the contract, and require relevant subcontractors to accept the same restrictions and conditions. [1]
The business associate must support covered-entity duties involving access, amendment, and accounting where applicable. At termination, it must return or destroy PHI when feasible. The agreement must authorize termination if the business associate violates a material term. [1]
Why “we cannot read it” is not a BAA exception
HHS cloud guidance states that a cloud service provider maintaining ePHI is a business associate even when it holds only encrypted ePHI and lacks the decryption key. The parties still need a HIPAA-compliant BAA and must perform risk analysis and risk management. [2]
Zero-knowledge architecture can reduce content-access risk and support technical safeguards. It does not decide whether HIPAA applies, sign the contract, operate the customer’s compliance program, or cover workflows outside the encrypted boundary.
What to evaluate beyond the BAA
Review the actual service scope, security responsibility matrix, identity and access controls, auditability, availability, backups, breach notification, data location and subprocessors, retention and deletion, export, incident response, and whether intended workflows place PHI in fields outside the protected-content boundary.
A signed template cannot make an unsuitable implementation compliant. The covered entity retains its own HIPAA duties and must assess risk in context.
Common questions.
Is a BAA proof that software is HIPAA compliant?
No. A BAA allocates required contractual duties. Compliance also depends on how the service is configured and used, each party’s safeguards, risk analysis, policies, and ongoing operations.
Does an encrypted cloud provider need a BAA if it cannot decrypt ePHI?
HHS says yes when the provider creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate. Lacking the key does not remove business-associate status. [2]
Who signs a BAA?
The relevant covered entity or business associate and the business associate providing the service. A downstream subcontractor handling PHI may also need equivalent contractual restrictions through the chain.
Primary sources
Definitions prefer standards bodies, government guidance, and the first-party SealTask architecture. Links open the complete source.
- 01 HHS: Business Associates Official explanation of business associates and required written assurances.
- 02 HHS: HIPAA and cloud service providers Official guidance on cloud services, ePHI, BAAs, and risk analysis.
- 03 HHS: Summary of the HIPAA Privacy Rule Official overview of protected health information and the Privacy Rule.
- 04 SealTask security architecture Product-specific encryption boundary, server visibility, protocols, and current limitations.