HIPAA wedge · free forever

BAA tracking that an office manager can actually run.

Stop tracking Business Associate Agreements in a spreadsheet. Covenant gives you a BAA library, a §164.504(e) required-clause gap-check, automatic renewal reminders, and subcontractor flow-down tracking — free for up to 10 vendors.

The obligation

Every vendor that touches PHI needs a current BAA

Under HIPAA §164.308(b), a covered entity must obtain satisfactory assurances — in the form of a written Business Associate Agreement — from every vendor that creates, receives, maintains, or transmits PHI. When a BA uses subcontractors, those need downstream BAAs too (§164.504(e)(2)(ii)(D)). Missing or expired BAAs are a top finding in OCR enforcement.

BAA library + lifecycle

Track each BAA's status — signed, pending, expired — with executed date, next-review date, and breach-notification SLA. Flags surface missing, expiring (≤30d), and overdue agreements.

§164.504(e) clause gap-check

Tick off the 11 required clauses against the HIPAA checklist. Covenant tells you instantly whether an executed BAA is complete or what's missing.

Subcontractor flow-down

Record each business associate's subcontractors and whether they hold a downstream BAA — the chain covered entities routinely miss.

Renewal reminders

90/60/30-day review windows and overdue alerts, so a BAA never silently lapses before an audit.

Auditor-ready inventory

Export the whole BAA inventory to CSV in one click — exactly what an OCR investigator or SOC 2 auditor asks for.

Free, forever

BAA tracking and 10 vendors cost nothing, with no card. It's our wedge, not a trial.

FAQ

BAA questions, plainly answered

What is a Business Associate Agreement?

A BAA is a HIPAA-required contract (45 CFR §164.504(e)) between a covered entity and any vendor that handles PHI on its behalf. It binds the vendor to safeguard PHI, report breaches, and flow the same obligations down to its subcontractors.

Do I need a BAA with my MSP / IT company?

Yes, if they can access systems that hold ePHI. Covenant flags PHI vendors as BAA-required and tracks the agreement's lifecycle so you can prove you have one.

Is Covenant a Business Associate itself?

No. Covenant tracks agreements about PHI; it is designed not to store PHI. We ask you to keep PHI out of evidence and the cloud sync carries only structured risk facts.

Ready to get your BAAs in order?

Add your vendors, mark who touches PHI, and let Covenant flag every missing or expiring agreement.

Start free →