top of page
falkon sign light.webp

Why a BAA Matters for eSign Tools in Healthcare

Writer: Amila Udowita
Amila Udowita
4 days ago
13 min read


Healthcare practice manager reviewing a business associate agreement for an eSignature tool on a tablet


Quick Answer 

A Business Associate Agreement (BAA) matters for eSign tools because any eSignature platform that creates, receives, stores, or transmits protected health information (PHI) for a healthcare practice is a HIPAA business associate. HIPAA requires a signed BAA before PHI is shared with that vendor. Without one, sending patient forms through the tool is a violation, no matter how secure the software is. 


 

Key Takeaways 


  • An eSign tool that stores signed patient documents is a business associate under HIPAA. 

  • HIPAA requires a written BAA before PHI reaches the vendor, under 45 CFR 164.502(e) and 164.504(e). 

  • The BAA makes the vendor contractually responsible for safeguards, breach reporting, and subcontractor oversight. 

  • Encryption, a "HIPAA compliant" badge, or a well-known brand does not replace a BAA. 

  • OCR has settled cases for $750,000 and $1.55 million where a practice shared PHI without a BAA. 


 

Healthcare practices have moved intake forms, consent documents, and treatment agreements online for good reason. Patients sign from their phones before they arrive, staff stop chasing paper, and records are easier to find. 


But every one of those forms carries patient information. The moment a practice uploads a consent form with a patient's name, date of birth, and treatment details into an eSignature tool, that vendor starts handling PHI. HIPAA has a specific rule for that relationship, and it is called a Business Associate Agreement. 


This guide explains what a BAA is, why eSign tools need one, how it supports legal compliance and liability protection, and how it keeps PHI workflows secure. You will also find a practical checklist for reviewing a vendor's BAA before your first patient signs. 



What Is a BAA for eSign Tools? 



Quick Answer 

A BAA for eSign tools is a written contract between a healthcare practice (the covered entity) and its eSignature vendor (the business associate). It spells out how the vendor may use PHI, which safeguards it must maintain, how fast it must report breaches, and what happens to patient data when the contract ends. 


 

HIPAA calls this contract a "business associate contract." Most people shorten it to BAA. The required contents are listed in federal regulation at 45 CFR 164.504(e), and HHS publishes sample BAA provisions that many vendors use as a starting point. 


Covered Entities and Business Associates Explained 


HIPAA applies directly to covered entities, which are health plans, healthcare clearinghouses, and healthcare providers that conduct certain electronic transactions.


Most medical, dental, therapy, and behavioral health practices are covered entities.

 

A business associate is any outside company that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Billing companies, EHR vendors, cloud storage providers, and IT support firms are common examples. An eSignature platform that stores patient documents fits this definition exactly. 


Which eSign Documents Contain PHI? 


Not every document your practice signs contains PHI, but most patient-facing forms do. Common examples include: 


  • Patient intake forms and medical history questionnaires 

  • Informed consent forms for procedures and treatment 

  • Notice of Privacy Practices acknowledgments 

  • Telehealth consent agreements 

  • Authorizations to release medical records 

  • Assignment of benefits and insurance authorization forms 

  • Financial responsibility agreements tied to a patient's care 

 

If a form identifies a patient and relates to their health, care, or payment for care, treat it as PHI. For more on where eSignatures fit in clinical settings, see our guide on whether electronic signatures are HIPAA compliant. 



Do eSignature Tools Need a BAA Under HIPAA? 



Quick Answer 

Yes. If an eSignature tool stores, processes, or transmits documents containing PHI, HIPAA requires the practice to sign a BAA with that vendor before any patient data is uploaded. The requirement applies whether the vendor is large or small, and whether the plan is paid or free. 


 

The rule comes from 45 CFR 164.502(e), which allows a covered entity to share PHI with a business associate only after obtaining "satisfactory assurances" in writing. The BAA is that written assurance. 


Why the Conduit Exception Does Not Apply 


HIPAA has a narrow exception for "conduits," such as the US Postal Service or an internet service provider, that only transmit data and store it temporarily. Some practices assume eSign tools qualify. 


They do not. An eSignature platform keeps the completed document, the audit trail, and signer details on its servers, often for years. Persistent storage takes it outside the conduit exception, so a BAA is required. 


Why Encryption Does Not Replace a BAA 


Strong encryption is essential, but it does not change the vendor's legal status. HHS guidance on cloud computing states that a cloud provider storing encrypted ePHI is still a business associate, even if it cannot view the data. Encryption lowers risk. The BAA establishes accountability. 


When a BAA Is Not Required 


A BAA is not required for documents that contain no PHI. Examples include an office lease, an employee offer letter, or a supply contract with a vendor. Many practices use one eSign account for everything, however, so the safest approach is to have a BAA in place for the whole account. 



How a BAA Supports Legal Compliance 


 

Quick Answer 

A BAA supports legal compliance by satisfying HIPAA's written assurance requirement and binding the eSign vendor to the Privacy, Security, and Breach Notification Rules. It turns a vendor's security promises into enforceable contract terms that auditors and OCR investigators expect to see.


 

eSignature Validity vs HIPAA Compliance 


Two separate laws answer two separate questions. The federal ESIGN Act and state UETA laws decide whether an electronic signature is legally valid. HIPAA decides whether the PHI inside that signed document was protected properly. 


A signature can be perfectly valid and still create a HIPAA problem if the platform that collected it had no BAA. Our breakdown of the difference between UETA and the ESIGN Act covers the validity side in detail. 


What HIPAA Requires Every BAA to Contain 


Under 45 CFR 164.504(e), every BAA must address specific obligations. Here is how each one applies to an eSignature vendor. 


Required BAA Element 

What It Means for an eSign Tool 

Permitted uses and disclosures 

The vendor may use PHI only to deliver the signing service, not for marketing or analytics resale. 

Appropriate safeguards 

The vendor must follow the HIPAA Security Rule for ePHI, including encryption, access controls, and audit logs. 

Reporting of breaches and incidents 

The vendor must report unauthorized uses, security incidents, and breaches of unsecured PHI to your practice. 

Subcontractor flow-down 

Any hosting or storage subcontractor that touches PHI must agree to the same restrictions. 

Individual rights support 

The vendor must help you fulfill patient requests for access, amendment, and an accounting of disclosures. 

HHS access to records 

The vendor must make its practices and records available to HHS during an investigation. 

Return or destruction at termination 

When the contract ends, the vendor must return or destroy signed documents and PHI where feasible. 

Termination for material breach 

Your practice must be able to end the contract if the vendor violates a material term. 


 

How a BAA Provides Liability Protection 


 

Quick Answer 

A BAA protects a practice by allocating HIPAA responsibilities in writing. It makes the eSign vendor contractually accountable for protecting PHI, and it removes the separate violation a practice commits when it shares PHI with a vendor that never signed a BAA.


 

Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for certain HIPAA violations. HHS summarizes those obligations in its fact sheet on business associate direct liability. That does not let covered entities off the hook, though. Your practice is still responsible for getting a BAA in place. 


What Happens Without a BAA 


OCR has made clear that a missing BAA is an enforcement issue on its own. Two well-known cases show the cost: 


  • Raleigh Orthopaedic Clinic agreed to pay $750,000 after handing PHI for about 17,300 patients to a vendor without first executing a BAA. The arrangement had been agreed over the phone. 

  • North Memorial Health Care agreed to pay $1.55 million for failing to have a BAA with a major contractor and failing to complete an organization-wide risk analysis. 

 

In announcing the Raleigh settlement, the OCR director noted that obtaining a BAA is "more than a mere check-the-box paperwork exercise." The same logic applies to eSignature vendors. If your eSign provider suffers a breach and no BAA exists, your practice faces the breach and the missing contract. 


Vendor risk is not theoretical. According to HIPAA Journal's 2025 Healthcare Data Breach Report, 35.8% of large healthcare data breaches in 2025 occurred at business associates. 


HIPAA Penalty Tiers in 2026 


HHS adjusted HIPAA civil monetary penalties for inflation in a Federal Register notice. The amounts below apply to penalties assessed on or after that date. 


Tier 

Level of Culpability 

Per Violation 

Calendar-Year Cap 

1 

Did not know and could not reasonably have known 

$145 to $73,011 

$2,190,294 

2 

Reasonable cause, not willful neglect 

$1,461 to $73,011 

$2,190,294 

3 

Willful neglect, corrected within 30 days 

$14,602 to $73,011 

$2,190,294 

4 

Willful neglect, not corrected within 30 days 

$73,011 to $2,190,294 

$2,190,294 

 

OCR continues to apply a 2019 enforcement discretion policy that lowers the annual caps for Tiers 1 to 3. Even so, knowingly using an eSign tool with PHI and no BAA is hard to defend as anything other than willful neglect. 


What a BAA Does Not Cover 


A BAA is a foundation, not a full shield. It does not: 


  • Replace your practice's own security risk analysis, policies, and staff training 

  • Automatically make the vendor pay your costs after a breach, since indemnification is negotiated separately and not required by HIPAA 

  • Protect PHI that staff send through tools outside the agreement, such as personal email 

  • Cover products from the same vendor that the BAA does not list 

  


Looking for an eSign Tool That Signs a BAA? 


If your practice sends intake forms, consent documents, or treatment agreements online, it helps to start with a platform built for regulated work. See how Falkon Sign handles audit trails, signer verification, and US data residency. 




How a BAA Creates Secure PHI Workflows

 


Quick Answer 

A BAA creates secure PHI workflows by requiring the eSign vendor to protect patient data at every stage, from sending the document to long-term storage and deletion. It sets clear rules for access, encryption, logging, breach reporting, and data return, so gaps do not appear between your practice and the vendor. 


 

Mapping BAA Obligations to Your eSign Workflow 


Think of an eSign workflow as a chain. A BAA and the platform's safeguards should cover every link. 


Workflow Stage 

PHI Risk 

What the BAA and Platform Should Cover 

Upload and send 

Wrong recipient, exposed email content 

Minimum necessary use, secure links, no PHI in email subject lines 

Signer verification 

Someone other than the patient signs 

Identity checks such as email one-time passcodes (learn more) 

Transmission 

Interception in transit 

Encryption in transit such as TLS 1.2 or higher 

Storage 

Unauthorized access to stored forms 

Encryption at rest such as AES-256, role-based access, US data location 

Audit trail 

Undetected changes or disputes 

Tamper-evident logs of views, signatures, and downloads (see why) 

Retention and export 

Records lost or locked in 

Export rights and retention that matches your policy 

Termination 

PHI left on vendor servers 

Return or destruction of PHI at contract end 

 

Breach Notification and Subcontractors 


Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. Many practices negotiate a shorter window in the BAA so they have time to meet their own 60-day patient notification deadline. 


Most eSign platforms run on third-party cloud infrastructure. A good BAA confirms that those subcontractors have signed their own BAAs with the vendor. HIPAA requires this flow-down, and it is one of the areas OCR reviews after a breach.


 

Is a HIPAA Compliant Label the Same as a BAA? 



Quick Answer 

No. HHS does not certify software as HIPAA compliant, so a "HIPAA compliant" badge is a marketing claim. A signed BAA is a legal contract. A platform can have strong security features, but without a BAA, using it with PHI still breaks HIPAA rules. 


 

You will see labels such as "HIPAA ready," "HIPAA capable," and "HIPAA compliant." Each one usually means the vendor has built the technical safeguards HIPAA expects. Compliance itself depends on your practice signing a BAA, configuring the tool correctly, and following your own policies. 


Our article on common eSignature mistakes to avoid covers other assumptions that trip up teams during rollout. 



What Should a BAA With an eSignature Vendor Include? 



Quick Answer 

Beyond the required HIPAA elements, a strong eSign BAA should define a breach reporting window, confirm where data is stored, guarantee export of signed documents and audit trails, list covered products and plans, and explain how PHI is returned or destroyed at termination. 


 

Use this checklist when you review a vendor's BAA: 


  • Covered services: Does the BAA name the specific eSign product and plan you use? 

  • Breach reporting window: Is it shorter than 60 days? Many practices look for 5 to 10 business days. 

  • Security incident definition: Does it separate minor unsuccessful attempts from reportable incidents? 

  • Data location: Are documents stored in the United States? 

  • Audit trail access: Can you export audit logs for investigations and patient disputes? 

  • Retention and export: Can you download all signed documents if you leave? 

  • Subcontractors: Does the vendor confirm BAAs with its hosting providers? 

  • Termination terms: How and when is PHI returned or destroyed? 

  • Plan eligibility: Is the BAA available on your plan, or only at an enterprise tier? 

 

Note: Your attorney or compliance officer should review the final BAA. This article is general information, not legal advice. 



How to Get a BAA From an eSignature Provider 



Quick Answer 

To get a BAA from an eSignature provider, confirm the vendor offers one on your plan, request and review the agreement, sign it before uploading any PHI, configure security settings, and store the signed copy with your HIPAA documentation for at least six years. 


 

  1. List your PHI documents: Identify every form your practice will send for signature that contains patient information. 

  2. Confirm BAA availability: Ask the vendor whether a BAA is included on your plan and at what cost. 

  3. Review the terms: Compare the BAA against the checklist above and the HHS sample provisions. 

  4. Sign before first use: Execute the BAA before any patient document is uploaded. A BAA can be signed electronically. 

  5. Configure the platform: Turn on signer verification, set user roles, and limit who can view completed forms. 

  6. File the agreement: Keep the signed BAA with your HIPAA records. HIPAA documentation rules call for six years of retention. 

  7. Review annually: Revisit the BAA when you change plans, add integrations, or when regulations change. 



Common BAA Mistakes Healthcare Practices Make 


Even careful practices slip up. These are the mistakes that show up most often with eSign tools: 


  • Using a free or personal plan: Many free tiers do not include a BAA. 

  • Signing the BAA after going live: Any PHI sent before the BAA was signed was shared without assurances. 

  • Assuming one BAA covers everything: A vendor's BAA may cover its eSign product but not a separate forms or storage product. 

  • Forgetting integrations: Connected storage, CRM, or automation tools that receive signed forms may need their own BAAs. 

  • Putting PHI in notification emails: Keep diagnosis or treatment details out of subject lines and message bodies. 

  • Losing the paperwork: An executed BAA you cannot produce during an audit is almost as risky as not having one. 



Proposed HIPAA Security Rule Changes That Affect BAAs 


On January 6, 2025, HHS published a proposed update to the HIPAA Security Rule.


Among other changes, it would require covered entities to obtain written verification, at least once every 12 months, that business associates have deployed required technical safeguards. It would also push BAAs to include faster incident reporting.

 

As of September 2026, the rule is not final, and regulatory agenda projections place final action in 2027. It is still wise to choose eSign vendors that can already document their safeguards, so your practice is not scrambling later. 



Choosing an eSignature Platform That Signs a BAA 


When you compare eSign tools for healthcare, put the BAA first and features second.


A vendor that hesitates to sign one, or reserves it for its most expensive tier, tells you a lot about how it treats regulated customers. 


After the BAA, look for tamper-evident audit trails, signer identity verification, encryption in transit and at rest, role-based access, and a clear answer on where data is stored. Our guide to choosing an eSignature tool for your business walks through the wider evaluation. 


Falkon Sign is one option healthcare practices can consider. It offers a BAA, stores documents in US-based data centers, and includes tamper-evident audit logs, email OTP signer verification, AES-256 encryption, and TLS 1.3 in transit. As with any vendor, confirm the BAA terms for your plan before sending patient forms. You can also compare options in our roundup of HIPAA compliant eSignature platforms.


 

Frequently Asked Questions 


What is a BAA in eSignature? 


A BAA in eSignature is a Business Associate Agreement between a healthcare practice and its eSignature vendor. It requires the vendor to protect any PHI in signed documents, limits how that data can be used, and sets rules for breach reporting and data return. 


Is a BAA legally required for eSignature software? 


Yes, when the software handles PHI. HIPAA requires covered entities to obtain a written BAA before sharing PHI with any vendor that stores, processes, or transmits it. If your eSign documents contain no PHI, a BAA is not required for those documents. 


Can I use a free eSignature tool for patient forms? 


Only if the vendor signs a BAA for that free plan, which is uncommon. Most free and personal eSign plans do not include a BAA, so they should not be used for intake forms, consent documents, or any other patient paperwork. 


Does an encrypted eSignature platform still need a BAA? 


Yes. HHS guidance says a vendor that stores encrypted ePHI is still a business associate, even if it cannot read the data. Encryption reduces breach risk, but only a signed BAA meets HIPAA's written assurance requirement. 


Who is liable if my eSignature vendor has a data breach? 


Both parties can face liability. The vendor is directly liable for certain HIPAA violations as a business associate. Your practice remains responsible for having a BAA, completing a risk analysis, and notifying patients. A missing BAA adds a separate violation for your practice. 


Can a BAA be signed electronically? 


Yes. HIPAA specifies what a BAA must contain, not how it must be signed. Under the ESIGN Act and state UETA laws, an electronically signed BAA carries the same legal effect as a paper one. 


How long should a practice keep a signed BAA? 


Keep a signed BAA for at least six years from the date it was created or last in effect, whichever is later. That matches HIPAA's documentation retention requirements and ensures you can produce it during an OCR investigation. 


Does a BAA make my practice HIPAA compliant? 


No. A BAA is one required piece. Full compliance also depends on your security risk analysis, written policies, staff training, correct platform configuration, and ongoing monitoring of how PHI is handled. 



Summary 


A BAA matters for eSign tools because it is the legal line between a convenient signing workflow and a HIPAA violation. It satisfies HIPAA's written assurance requirement, allocates liability between your practice and the vendor, and forces clear rules for how PHI is protected from the moment a form is sent until it is deleted.

 

Before your next patient signs online, confirm three things. Your eSign vendor has signed a BAA. The BAA covers the plan and product you use. Your team has configured the platform and trained staff to use it correctly. Get those right, and electronic signatures become a compliance strength rather than a risk. 


For a closer look at protecting sensitive documents, read our guide on whether eSignatures are safe for confidential documents.



Make Patient Signing Simple and Secure 


When your practice is ready to move intake and consent forms online, choose a platform that signs a BAA and keeps records protected. Compare Falkon Sign plans and find the fit for your team. 



 
 
 

Comments


bottom of page