Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » HIPAA Agreement

HIPAA Agreement

A HIPAA Business Associate Agreement is a contract between a HIPAA-covered entity (like a healthcare provider) and a business or individual that helps with certain functions involving PHI. It’s essentially a written arrangement that outlines how the PHI is used.

HIPAA requires covered entities to work with business associates who demonstrate the prowess to protect PHI. This must be validated using a contract or an agreement.

Also, the Health and Human Services (HHS) can audit business associates and subcontractors for HIPAA compliance, not just the covered entities. All three levels (covered entities, business associates, and subcontractors) must have a Business Associate Agreement (BAA) to meet HIPAA requirements.

What’s included in the agreement?

The Business Associate/Subcontractor Agreement must spell out several important details, as per HHS guidelines:

  • It describes how PHI can be used by the business associate/subcontractor
  • It ensures that the business associate/subcontractor will only misuse or share PHI within what the contract allows or requires by law
  • It mandates safeguards to prevent improper PHI use or sharing

Once these relationships are identified, you must ensure that third parties safeguard the PHI they handle. A signed agreement documents that the business associate understands and commits to handling PHI securely.

Additional reading

Data Governance Policy: Steps to Create, Examples and Templates

TL, DR: A data governance policy is a guiding document on how to manage an organization’s information assets  There can be different types of data governance policies such as data quality policy, data security policy, data privacy policy, data access policy and more To develop a data governance policy you must define your needs and…

12 Best Healthcare GRC software in 2026

The healthcare industry has seen a surge in cyber incidents with over 700 data breaches disclosed publicly in 2022. This pattern is steadily rising since 2019. These breaches have underscored the urgent need for a strong governance, risk, and compliance measures across all organizations, especially the highly regulated ones.  Healthcare GRC software has emerged as…

Best Hyperproof Alternatives in 2026: Compare Top 11 Competitors

TL; DR Hyperproof can be a solid compliance and risk workspace, especially if cross-framework control reuse matters to you. Teams usually start exploring alternatives when day-to-day execution gets noisy: UI friction, slower ownership workflows, and reporting that still needs cleanup. If you want less evidence chasing, broader integrations, and more flexible reporting, these 11 tools…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.