A Business Associate Agreement (BAA) is a contract required by HIPAA. When a HIPAA "covered entity" uses a contractor to handle protected health information (PHI) on its behalf, the law requires written safeguards in the contract. The regulation says a covered entity may disclose PHI to a business associate "if the covered entity obtains satisfactory assurance that the business associate will appropriately safeguard the information," and that those assurances "must be documented through a written contract or other written agreement or arrangement" that meets the requirements of 45 CFR 164.504(e).
The Department of Health and Human Services (HHS) explains that the agreement must describe the permitted uses and disclosures of PHI and prevent the business associate from using or disclosing it any other way, except as required by law. The regulation states that the contract must "Establish the permitted and required uses and disclosures of such information by the business associate". Also, a business associate that hands PHI to a subcontractor needs its own agreement, and the rule applies the same contract requirements to a subcontractor arrangement "in the same manner" as to the first-tier agreement.
Covered entity
Section 160.102(a) says the standards apply to three kinds of entities, "(1) A health plan. (2) A health care clearinghouse. (3) A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Business associates are covered separately in 45 CFR 160.102(b), "Where provided, the standards, requirements, and implementation specifications adopted under this subchapter apply to a business associate."
The third category matters for homeless services, being a "health care provider" is not enough on its own. The regulation defines that term broadly, as "any other person or organization who furnishes, bills, or is paid for health care in the normal course of business," but a provider becomes a covered entity only if it transmits health information electronically in connection with a covered "transaction." Those transactions are things like health care claims, eligibility for a health plan, and referral certification and authorization.
HHS guidance states that if an organization is neither a covered entity nor a business associate, it "does not have to comply with the HIPAA Rules." Not being a covered entity means no HIPAA obligations, and no BAA to sign.
HMIS is not a HIPAA system
The Homeless Management Information System is a database mandated by the U.S. Department of Housing and Urban Development (HUD) that Continuums of Care (CoCs) use to record services, track outcomes, and report to funders. It has its own privacy framework, namely, HUD's 2004 Data and Technical Standards Final Notice. HUD describes the standards as establishing "policies and procedures for addressing the privacy and confidentiality of information collected by HMIS, while allowing for reasonable and responsible uses and disclosures of data".
The final notice states, "Although most homeless programs are not subject to HIPAA, HUD recognizes that the HIPAA privacy rule establishes a national baseline of privacy standards for most health information. Accordingly, the HIPAA privacy rule was used as a guide for developing the HMIS privacy standards." The notice also noted that in several instances, the HMIS baseline requirements "exceed the requirements in the HIPAA privacy rule."
Under those standards, any homeless organization that records, uses, or processes protected personal information (PPI) for an HMIS is a "covered homeless organization" (CHO). The Notice defines a CHO as "any organization (including its employees, volunteers, affiliates, contractors, and associates) that records, uses or processes PPI on homeless clients for an HMIS." CHOs must follow the HMIS Privacy and Security Standards.
However, a CHO is not automatically a HIPAA covered entity. Most CHOs, such as emergency shelters, outreach teams, and rapid re-housing providers, don't bill insurance electronically so for them HIPAA doesn't apply, and a BAA with the HMIS vendor or lead isn't required. HUD said in the Notice, "It is HUD's understanding that very few homeless service providers are 'covered entities' under HIPAA."
It’s also important to note that the final notice doesn't mention business associate agreements. The 2025 HMIS Policies and Procedures Manual used by Missouri's Balance of State, Springfield, Joplin, and St. Joseph CoCs, prepared with the Institute for Community Alliances (ICA) as HMIS Lead, addresses privacy, consent, security, and covered-entity status at length but never mentions a BAA.
Scenario 1: You're not a covered entity
If an organization does not bill Medicaid, Medicare, or private insurance electronically, then it is not a HIPAA covered entity. The HUD Final Notice states, "Where a homeless service provider is not a covered entity under HIPAA, it is subject to the HMIS privacy and security standards. A provider is also subject to applicable state and local privacy laws." This means obligations are governed by HMIS participation agreement, the CoC's policies, and state law.
Under the HUD Final Notice, a CHO must, among other things:
- Post a sign at each intake desk explaining the reasons for collecting information.
- Publish a privacy notice describing how it processes.
- Let individuals inspect and correct their information.
- Establish a procedure for privacy complaints.
- Have each staff member, including "employees, volunteers, affiliates, contractors and associates," sign a confidentiality agreement.
- Meet baseline security requirements.
Uses and disclosures not described in the privacy notice can be made "only with the consent of the individual or when required by law."
"No BAA" does not mean "no rules." Organizations still owe clients privacy notices, consent practices, and reasonable security.
Example: what this looks like in Missouri
Missouri's 2025 HMIS Policies and Procedures Manual (ICA, HMIS Lead for six Missouri CoCs) shows how a local HMIS Lead turns the federal baseline into day-to-day requirements. Partner agencies there must:
- Post a Consumer Notice at each intake desk and publish the HMIS Privacy and Security Notice on the agency website if it has one (manual pp. 12-13).
- Have every staff member, including volunteers and contractors, sign a confidentiality agreement acknowledging the Privacy and Security Notice (p. 13).
- Get a signed Client Informed Consent to Share and Release of Information (ROI) before entering client data. ROIs expire after one year and must be kept for seven years after expiration. Clients who decline get a locked record, and declining does not affect their right to services (pp. 13-14, 22).
- Notify the help-desk of any breach of system security or client confidentiality within 24 hours, with probation and technical assistance following a breach (pp. 17-18).
- Keep personal identifiers out of unencrypted email, using only the HMIS-generated Client ID where client information must be referenced (p. 16).
- Meet password, firewall, physical-access, and hard-copy security requirements (pp. 15-16).
Scenario 2: You are a covered entity
Federally qualified health centers, Health Care for the Homeless programs, hospitals, and behavioral health clinics that bill insurance electronically are covered entities, and many of them also enter data into HMIS. HUD chose to defer to HIPAA for these organizations. The Notice says, "When a homeless service provider is a covered entity, the provider is required to operate in accordance with HIPAA regulations. The final Notice states that such a provider is not required to comply with the HMIS privacy or security standards. Exempting HIPAA covered entities from the HMIS privacy and security rules avoids all possible conflicts between the two sets of rules."
HUD gave three reasons for giving HIPAA precedence: "(1) The HIPAA rules are more finely attuned to the requirements of the health care system; (2) the HIPAA rules provide important privacy and security protections for protected health information; and (3) requiring a homeless provider to comply with or reconcile two sets of rules would be an unreasonable burden."
The Notice also recognizes that "part of a homeless organization's operations may be covered by the HMIS standards while another part is covered by the HIPAA standards." A CHO in that position must describe the non-HMIS information in its privacy notice and "explain the reason the information is not covered," to avoid "giving the impression that all personal information will be protected under the HMIS standards if other standards or if no standards apply."
Example: how a local manual states the exemption
Missouri's manual says that a Partner Agency that is a HIPAA covered entity "is exempt from HMIS Privacy and Security Standards" because the HMIS Standards give precedence to the HIPAA rules (manual p. 12).
When is a BAA needed?
Under 45 CFR 160.103, a business associate is a person who, "On behalf of such covered entity ... creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter."
If the HMIS lead and vendor hosts or processes PHI on an organization's behalf, then a BAA is generally needed. The definition expressly includes "a Health Information Organization, E-prescribing Gateway, or other person that provides data transmission services with respect to protected health information to a covered entity and that requires access on a routine basis to such protected health information."
One exception is that the definition of business associate "does not include" "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual."
The vendor and the lead agency
The HMIS structure has different parts, and the BAA question can arise at each one.
The HMIS vendor hosts the software and data. The HUD Final Notice applies its baseline standards to "any organization (such as a Continuum of Care, homeless assistance provider, or HMIS software company) that records, uses, or processes PPI on homeless clients for an HMIS." So vendors have HMIS obligations even when no BAA is involved. Separately, business associates are directly regulated under HIPAA and are subject to the Security Rule's safeguards and direct HHS enforcement under the HITECH Act, so vendors serving health-sector customers generally have HIPAA-ready practices and BAA templates.
The HMIS lead agency administers the system for the CoC. The HUD Final Notice contemplates shared arrangements, stating, "When PPI is shared between organizations, responsibilities for privacy and security may reasonably be allocated between the organizations." According to one HMIS vendor's summary of HUD's requirements, the HMIS lead and CHOs are jointly responsible for privacy, security, and confidentiality protections. Where a covered-entity partner uses the system, the lead may need a BAA with that partner, and a subcontractor BAA with the vendor. The regulation is what makes the structure work, a "subcontractor" is "a person to whom a business associate delegates a function, activity, or service," and the definition of business associate includes "a subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate." HHS guidance states that a business associate must establish a BAA with its subcontractor before disclosing PHI to it, and all such downstream subcontractors are also business associates.
The CoC lead agency is a separate role. Many communities have one organization playing both, but not all do. The CoC lead handles governance, planning, and funding applications, and unless it handles PHI on behalf of a covered entity, it likely has no BAA obligation. It may still be subject to the HMIS standards if it records, uses, or processes PPI.
Example: the structure in Missouri
Missouri's manual shows the structure. ICA is the HMIS Lead Agency designated by six Missouri CoCs (Balance of State, St. Louis City, St. Louis County, Springfield, Joplin, and St. Joseph). It administers day-to-day operations and manages user licenses, agency onboarding, training, and compliance (manual p. 7). The software is Community Services® (formerly ServicePoint), a WellSky product (p. 3). The CoCs themselves approve the policies (p. 3) and receive violation reports through their board committees (pp. 23-24).
The agreement that governs the relationship is the Agency Partner Agreement between each Partner Agency and the HMIS Lead. It addresses HMIS responsibilities and confidentiality, and it must be signed at least once a year (p. 8).
FAQs
Does using HMIS make my organization subject to HIPAA?
No, HIPAA applies only if you are a covered entity (or a business associate).
What is the difference between a BAA and an HMIS participation agreement?
A BAA is a HIPAA-required contract for handling protected health information, while a participation agreement is the HMIS-specific contract that sets your privacy, security, and data-entry obligations.
Do volunteers and interns need to follow HMIS privacy rules?
Yes, anyone who handles client information is generally expected to sign a confidentiality agreement and follow the same standards.
