Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    [email protected]

Business Associate Agreement for data destruction services (HIPAA)

A two-page HIPAA Business Associate Agreement written around what a destruction vendor actually does: custody of PHI only between receipt of the media and its destruction, no designated record set, no access to contents, and a ten-business-day breach reporting window. It covers the elements 45 CFR 164.504(e) requires and nothing a destruction vendor cannot honor.

Version 1.0, reviewed 2026-09-19. Free under CC BY 4.0. Not legal or assessment advice.

Who it is for

Covered entities and business associates engaging a destruction vendor for media that has held protected health information: hospitals, clinics, practices, health plans, and their IT and billing contractors. Our version is offered for review; we will also sign yours.

What is inside

  • Definitions and the nature of the services, stating that the vendor does not access, read, image, copy, or retain the contents of media
  • Permitted uses and disclosures, limited to performing the services
  • Safeguards, including tamper-evident custody, witnessed destruction on the client's premises, and destruction of mailed media within five business days
  • Reporting of impermissible uses, security incidents, and breaches within ten business days
  • Subcontractors, individual rights, books and records, term and termination, and governing law

The clause that matters most

Section 2, nature of the services: the vendor's sole function is the physical destruction of media, on the covered entity's premises or at the vendor's receiving location for mailed media, to NIST SP 800-88 or the standard in the services agreement. The vendor does not access, read, image, copy, or retain the contents of media and does not maintain a designated record set. PHI is in the vendor's custody only between receipt and destruction. That paragraph is what makes the rest of the agreement short: access, amendment, and accounting requests are forwarded within five business days because there is no record set to search.

How to adapt it

  1. Fill the effective date and the covered entity's name.

  2. Confirm the reporting window (ten business days) matches your own policy; tighten it if yours is shorter.

  3. Attach it to the services agreement, quote, or purchase order it supplements.

  4. Have counsel review before signing; it is a standard form, not legal advice.

What it rests on

  • 45 CFR 164.504(e)
    The required elements of a business associate contract.
  • 45 CFR 164.410
    Breach notification by business associates.
  • 45 CFR 164.310(d)
    Device and media controls, including disposal.

Primary sources are linked on the Standards page.

Questions

  • Is a BAA required for a shredding vendor?

    If the vendor takes custody of media containing PHI, even for the minutes between receipt and destruction, HHS treats it as a business associate, and a BAA is required. Witnessed on-site destruction does not remove the requirement; it makes the custody window short.

  • Why does it say the vendor never reads the media?

    Because it is true and because it is the basis for the narrow scope. A vendor that does not access contents has no designated record set and no basis for the access and amendment provisions that apply to vendors who do.

  • Will you sign our BAA instead?

    Yes. Send it with the quote request.

More answers on the FAQ.

Other templates

Download the PDF file

Need it tailored, or the destruction it describes?

Request a custom quote