Answers · HIPAA & Tracking

What is the difference between an NDA and a BAA?

Last reviewed: · Strategic AI Architects Data Desk · reviewed by Mike Moore

A non-disclosure agreement (NDA) is a private promise between two parties not to share confidential information, and the parties write whatever terms they like. A Business Associate Agreement (BAA) is a HIPAA-required contract with a fixed list of provisions that a covered entity must have in place before a vendor creates, receives, maintains, or transmits protected health information on its behalf — and signing an NDA does not satisfy that requirement, because the rule at 45 CFR 164.504(e) names specific terms a general confidentiality agreement almost never contains.

The requirement itself is short and worth reading once: a covered entity may let a business associate handle protected health information "if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information" (45 CFR 164.502(e)(1)(i)), and those assurances "must be documented through a written contract or other written agreement or arrangement" meeting 45 CFR 164.504(e) (45 CFR 164.502(e)(2))1. So the question is never whether you have a contract. It is whether the contract you have says the things the regulation lists.

What HIPAA requires a BAA to say — and what an NDA typically says instead

The regulation lists the provisions rather than leaving them to negotiation, which is the whole reason a general confidentiality agreement cannot stand in. Each row below quotes the obligation from 45 CFR 164.504(e)(2) and names the subparagraph it comes from2.

Provisions required of a business associate contract by 45 CFR 164.504(e)(2), compared with a typical mutual NDA
Required of a BAARegulationIn a typical NDA?
Use or disclose PHI only as the contract or law permits164.504(e)(2)(ii)(A)Partly — an NDA restricts disclosure, but rarely restricts use to defined purposes
Use appropriate safeguards and comply with the Security Rule for electronic PHI164.504(e)(2)(ii)(B)No — NDAs seldom reference 45 CFR Part 164 Subpart C at all
Report any use or disclosure not provided for, including breaches of unsecured PHI164.504(e)(2)(ii)(C)No — breach notification duties are a HIPAA construct
Bind subcontractors to the same restrictions164.504(e)(2)(ii)(D)Rarely, and rarely with flow-down of the specific terms
Make PHI available to the individual (access)164.504(e)(2)(ii)(E)No — an NDA creates no individual rights
Make PHI available for amendment, and incorporate amendments164.504(e)(2)(ii)(F)No
Provide the information needed for an accounting of disclosures164.504(e)(2)(ii)(G)No
Comply with the covered entity's own obligations where it performs them164.504(e)(2)(ii)(H)No
Make internal practices, books, and records available to HHS164.504(e)(2)(ii)(I)No — and this one is often the hardest sell to a vendor
Return or destroy all PHI at termination, if feasible, and keep no copies164.504(e)(2)(ii)(J)Sometimes for "confidential information" generally, without the feasibility and extended-protection language
Authorize termination by the covered entity for a material breach164.504(e)(2)(iii)Sometimes, but not tied to HIPAA obligations

Read down that column and the difference stops being a matter of degree. An NDA governs secrecy between two businesses. A BAA governs a regulated data-handling relationship, including duties owed to people who never signed anything — the individual's right of access, amendment, and an accounting of disclosures — plus an inspection right for HHS. A confidentiality clause cannot create those duties by implication.

Two more things an NDA does not do

First, it does not change who is regulated. The definition of a business associate at 45 CFR 160.103 turns on function — a person or company that creates, receives, maintains, or transmits protected health information on a covered entity's behalf — not on what the parties named their contract6. And since the HITECH Act, business associates are directly liable to HHS for a defined set of HIPAA requirements regardless of contract terms; OCR published the list in a fact sheet on May 24, 20193.

Second, it does not fix a vendor that will not sign a BAA. That refusal is a statement about where the product may sit. Google states it does not offer Business Associate Agreements for Google Analytics and directs HIPAA-regulated customers to use it only on pages that are not HIPAA-covered4; Meta offers none for the standard Pixel. An NDA with either changes nothing about the analysis — see is GA4 HIPAA-compliant without a BAA and the Meta Pixel on a Medicare quote form. The tracking-vendor version of this trigger is exactly what HHS OCR's tracking-technology guidance addresses5, and what survived the 2024 court ruling is covered in what that guidance actually says.

When you need which one

  • NDA only: a vendor, contractor, or prospective partner who will see business-confidential material — pricing, book of business, roadmaps, lead lists without health information.
  • BAA (usually alongside an NDA): any vendor that will create, receive, maintain, or transmit protected health information on your behalf — hosting, CRM, analytics, transcription, an AI tool processing member data, a subcontractor of any of those.
  • Neither is sufficient by itself: where the vendor cannot lawfully hold the data at all. No contract makes a tool compliant if the vendor will not accept the obligations.

For reference, we publish our own agreements: the BAA and NDA we make available to enterprise clients. And if the underlying question is which analytics or tracking stack an agency can defensibly run, that is its own page — which analytics tools a health insurance agency can legally use.

Sources

  1. 45 CFR 164.502(e)(1)(i) and (e)(2): a covered entity may disclose PHI to a business associate "if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information," and those assurances "must be documented through a written contract or other written agreement or arrangement." Text verified 2026-08-19. law.cornell.edu.
  2. 45 CFR 164.504(e)(2)(ii)(A)–(J) and (e)(2)(iii): the required provisions of a business associate contract, quoted in the table above; and 164.504(e)(1)(ii), under which a covered entity that knew of a pattern of activity constituting a material breach by the business associate and failed to cure or terminate is itself out of compliance. Text verified 2026-08-19. law.cornell.edu · eCFR.
  3. U.S. Department of Health and Human Services, Office for Civil Rights. "Direct Liability of Business Associates," fact sheet issued 2019-05-24, listing the HIPAA provisions for which a business associate may be held directly liable. hhs.gov. See also HHS's sample business associate agreement provisions. hhs.gov.
  4. Google. "HIPAA and Google Analytics" — Google "does not offer Business Associate Agreements in connection with this service." Verified live 2026-08-17. support.google.com.
  5. U.S. Department of Health and Human Services, Office for Civil Rights. "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates," revised 2024-03-18, portion vacated 2024-06-20 (AHA v. Becerra, N.D. Tex.). hhs.gov.
  6. 45 CFR 160.103, definition of "business associate" — a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits" protected health information for a regulated function or activity, including subcontractors. eCFR.

Related questions

Can one document be both an NDA and a BAA?

Yes. HIPAA cares about the provisions, not the title — a single agreement that contains everything 45 CFR 164.504(e) requires, plus ordinary confidentiality terms, satisfies the rule. Many vendors do exactly this, and many others attach a standalone BAA to a master services agreement that already has an NDA in it. What never works is a confidentiality agreement that simply never addresses the required provisions.

Our vendor will sign an NDA but not a BAA. Is that workable?

Only if that vendor never creates, receives, maintains, or transmits protected health information on your behalf. A refusal to sign a BAA is a statement about what the vendor's product is allowed to touch, so the fix is architectural: keep the vendor off the pages and systems where health information moves. Google, for instance, states it does not offer Business Associate Agreements for Google Analytics and directs HIPAA-regulated customers to use it only on pages that are not HIPAA-covered.

Does a BAA protect the vendor from HIPAA liability?

No, and this is widely misunderstood. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable to HHS for a specific set of HIPAA requirements regardless of what the contract says — OCR published a fact sheet listing them on May 24, 2019. The BAA allocates responsibility between the parties; it does not remove the vendor from the regulator's reach.

Does an insurance agency even need BAAs?

It depends on what the agency is, which is fact-specific and worth an actual legal read. An agency can be a covered entity in some arrangements, a business associate of a carrier or plan in others, and neither in others still. The practical version: if any vendor of yours can see health information your business handles, find out which relationship you are in before you decide that an NDA covers it — and note that the FTC has penalized businesses outside HIPAA entirely for the same data flows.

Want to know where your own site stands? Run the free Audit — a live AEO audit plus a HIPAA tracking scan — or browse all answers.