A BAA is a legally binding contract between a Covered Entity and a Business Associate.
The agreement ensures that the third party will protect Protected Health Information (PHI) according to HIPAA standards. Without a signed BAA, a healthcare provider cannot legally share patient data with an external provider.