# Can a BAA be accepted with a click? What HIPAA actually requires

> For healthcare MSPs and billing companies sending the same BAA to every client: what HIPAA and the ESIGN Act say about electronic acceptance, and how AWS and Google do it.

_By Santi Darmandrail · Published 2026-10-04 · Updated 2026-10-04_

**The short answer**

- HIPAA does not require a wet signature on a BAA. The rules require a written contract with specific required content (45 CFR 164.504(e)), not a particular way of signing it.
- Under the federal ESIGN Act, a contract can't be denied legal effect solely because it is electronic or was formed with an electronic record.
- AWS and Google Workspace both bind customers to their BAAs by electronic acceptance in their admin consoles.
- What carries the weight is the BAA's content, a clear act of acceptance by someone with authority, and a record of which version was accepted, when and by whom.

If you run a healthcare-focused IT MSP or a medical billing company, you probably send the same BAA to every clinic and practice you work with. Each one going out as a Word file or an e-signature envelope is slow, and it is fair to ask whether a client clicking "I agree" on your BAA counts.

This page answers that from the primary sources, for the business associate sending the BAA rather than the covered entity collecting it. If you have just taken on your first healthcare client, start with [what changes when you sign your first BAA](/when/first-baa).

## What does HIPAA require of a BAA?

HIPAA requires a written contract with specific content; it does not say how the parties must sign it. The Privacy Rule says a covered entity's assurances from a business associate "must be documented through a written contract or other written agreement or arrangement with the business associate that meets the applicable requirements of § 164.504(e)" (45 CFR 164.502(e)(2)). The Security Rule has the same documentation requirement for electronic PHI (45 CFR 164.308(b)(3)).

The content requirements are in 45 CFR 164.504(e)(2). HHS summarizes them in ten points. A written contract between a covered entity and a business associate must:

1. Establish the permitted and required uses and disclosures of PHI by the business associate.
2. Provide that the business associate won't use or further disclose the information except as the contract permits or the law requires.
3. Require appropriate safeguards, including the Security Rule's requirements for electronic PHI.
4. Require the business associate to report uses or disclosures the contract doesn't provide for, including breaches of unsecured PHI.
5. Require the business associate to make PHI available for individuals' access, amendment and accounting requests, as the contract specifies.
6. Require compliance with the Privacy Rule for any covered-entity obligation the business associate carries out.
7. Make the business associate's internal practices, books and records available to HHS.
8. Require return or destruction of PHI at termination, if feasible.
9. Require subcontractors with access to PHI to agree to the same restrictions and conditions.
10. Authorize the covered entity to terminate the contract if the business associate violates a material term.

Every item is about what the contract says. The rule's text doesn't specify an execution method, a signature block or ink. HHS also publishes sample provisions, but it states that "use of these sample provisions is not required for compliance with the HIPAA Rules."

**Business associate:** Under HIPAA, a person who, on behalf of a covered entity, creates, receives, maintains or transmits protected health information, or provides certain services to it that involve PHI, other than a member of its workforce. The definition expressly includes "a subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate" (45 CFR 160.103).

## Does "written" mean signed on paper?

Not under federal law. The ESIGN Act provides that, for a transaction in or affecting interstate or foreign commerce:

> (1) a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and (2) a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation.
>
> — 15 U.S.C. § 7001(a)

The state-law counterpart is the [Uniform Law Commission, Uniform Electronic Transactions Act](https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034), which states enact individually.

What ESIGN doesn't do is decide whether a particular click formed a particular contract. That turns on how the acceptance was built, covered below. Whether your BAA with a specific client is enforceable is a question for your counsel.

## How do AWS and Google accept their own BAAs?

Both offer their standard BAA for acceptance in a console, with no paper signature.

**AWS.** In the AWS Artifact console, a customer opens the agreement, reviews it, selects "I agree to all of these terms and conditions" and chooses **Accept agreement**. By default, only users with administrative privileges can accept. The owner of an AWS Organizations management account can accept a BAA on behalf of every account in the organization, and AWS says "all existing and subsequent member accounts are automatically covered." AWS recommends consulting your legal, privacy and compliance team before accepting, and it also lists offline agreements as a separate option.

**Google Workspace.** The BAA is accepted from a super administrator account under Admin console → **Account settings** → **Legal and compliance**. Google's help page says the BAA "is made available to customers for electronic acceptance via their Admin console," and adds:

> Such an electronic agreement is as binding as a paper-based agreement—i.e., it has the same legal effect.
> — Google Workspace Admin Help, HIPAA compliance with Google Workspace and Cloud Identity

The same page tells customers they can demonstrate acceptance by producing a screenshot of the acceptance shown in that section. Even Google's process ends with the question of evidence.

To be precise about what this shows: these are two of the largest business associates in the market running their own BAAs by click. HHS hasn't issued guidance endorsing click-through BAAs, and neither vendor's practice is a regulator's statement.

## What makes a click-accepted BAA hold up?

A click holds up when the acceptance was built to the standard courts apply to clickwrap, and you can prove it. In practice that comes down to three things:

- **Notice of the full text.** The person accepting can read the whole BAA before agreeing, not a link buried in a footer or an email signature.
- **An unambiguous act.** A deliberate step, such as ticking "I agree" and pressing Accept, by someone with authority to bind the client. AWS and Google both limit acceptance to administrators.
- **A record you can produce.** Which version of the text was accepted, when, and by whom, kept in a form that shows the text hasn't changed since.

Our [legal standing page](/legal-standing) covers the case law behind this, including the clickwrap decisions courts have enforced and the browsewrap patterns they haven't.

## Do your subcontractors need a BAA too?

Yes, the rule runs downstream. A business associate may let a subcontractor create, receive, maintain or transmit PHI on its behalf only with satisfactory assurances, documented in a written contract (45 CFR 164.502(e)(1)(ii) and 164.308(b)(2)–(3)). Section 164.504(e)(5) applies the same content requirements to that contract "in the same manner" as to a covered entity's.

For an MSP that can mean backup, remote monitoring or help-desk vendors, if they handle PHI on your behalf. Whether a given vendor does is a call for your compliance lead or counsel. The point here is narrower: nothing in the rule requires those agreements to be signed on paper either, and many large vendors already offer theirs by electronic acceptance.

## How do you send one BAA to every client as a link?

E-signature suits a contract you negotiate once. The same standard BAA going to 40 clinics is a different job, and it's the one Pacts is built for. You publish your BAA once and send each client a link. The client's contact reads the full text, enters their name, email and organization, ticks "I have read and agree to these terms" and accepts. They don't need an account.

- **A certificate per acceptance.** Each one records the document and version, the accepting company and the time, with a SHA-256 hash of the exact text accepted. Anyone holding the certificate link can check it on a public verification page, which re-hashes the stored text and confirms it hasn't changed.
- **A coverage board.** One view shows which clients are on your current BAA, which accepted an older version, which are still pending and which have no agreement.
- **Reminders.** On paid plans, pending acceptances are reminded automatically, by default 3, 7 and 14 days after you send.
- **A starting text, if you want one.** The template library hosts HHS's sample BAA provisions as published, with their source. Pacts doesn't draft or vet legal text, so have counsel review whatever you send.

No PHI enters Pacts: it holds the agreement and who accepted it, never your clients' patient data. Bundled evidence packs per client are on the Scale plan. For how this fits a healthcare MSP's whole client book, see [Pacts for healthcare MSPs and billing companies](/for/healthcare-msp).

**Common questions**


### What if a client's lawyer wants to change our BAA?

Then it's a negotiated contract rather than your standard one. Agree the redline and execute that version the way you both prefer, which is usually e-signature. Click acceptance suits the standard version that most clients take as is; one negotiated client doesn't change how you send it to the rest.

### Does HHS say a click-through BAA is acceptable?

HHS guidance doesn't address the signing method either way. The rule requires a written contract with specific content (45 CFR 164.504(e)), ESIGN addresses electronic form (15 U.S.C. § 7001), and AWS and Google show how large business associates do it in practice. None of that is an HHS endorsement.

### Do we need a BAA with our cloud backup vendor?

The rule requires one with any subcontractor that creates, receives, maintains or transmits PHI on your behalf (45 CFR 164.502(e)(1)(ii)). Whether your backup vendor's service does that is a question for your compliance lead or counsel. Many large cloud vendors, including AWS and Google, offer their BAA by electronic acceptance.

### Do we have to use the HHS sample BAA?

No. HHS states that use of its sample provisions "is not required for compliance with the HIPAA Rules." The required content comes from 45 CFR 164.504(e). The sample is a starting point that you and your counsel can adapt.

**Sources**

- [45 CFR § 164.504(e), business associate contracts](https://www.law.cornell.edu/cfr/text/45/164.504)
- [45 CFR § 164.502(e), disclosures to business associates](https://www.law.cornell.edu/cfr/text/45/164.502)
- [45 CFR § 164.308(b), Security Rule business associate contracts](https://www.law.cornell.edu/cfr/text/45/164.308)
- [45 CFR § 160.103, definition of business associate](https://www.law.cornell.edu/cfr/text/45/160.103)
- [HHS, Sample Business Associate Agreement Provisions (2013)](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html)
- [ESIGN Act, 15 U.S.C. § 7001](https://www.law.cornell.edu/uscode/text/15/7001)
- [Uniform Law Commission, Uniform Electronic Transactions Act](https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034)
- [AWS Artifact User Guide, Managing agreements](https://docs.aws.amazon.com/artifact/latest/ug/managing-agreements.html)
- [AWS Artifact User Guide, Accepting agreements for your AWS account](https://docs.aws.amazon.com/artifact/latest/ug/accept-single-agreement.html)
- [AWS Artifact User Guide, Accepting agreements for your organization](https://docs.aws.amazon.com/artifact/latest/ug/accept-org-agreement.html)
- [Google Workspace Admin Help, HIPAA compliance with Google Workspace and Cloud Identity](https://knowledge.workspace.google.com/admin/compliance/hipaa-compliance-with-google-workspace-and-cloud-identity)

_Pacts is not a law firm and this page is not legal advice. Speak to a licensed attorney about your situation._

## Sources

- [45 CFR § 164.504(e), business associate contracts](https://www.law.cornell.edu/cfr/text/45/164.504)
- [45 CFR § 164.502(e), disclosures to business associates](https://www.law.cornell.edu/cfr/text/45/164.502)
- [45 CFR § 164.308(b), Security Rule business associate contracts](https://www.law.cornell.edu/cfr/text/45/164.308)
- [45 CFR § 160.103, definition of business associate](https://www.law.cornell.edu/cfr/text/45/160.103)
- [HHS, Sample Business Associate Agreement Provisions (2013)](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html)
- [ESIGN Act, 15 U.S.C. § 7001](https://www.law.cornell.edu/uscode/text/15/7001)
- [Uniform Law Commission, Uniform Electronic Transactions Act](https://www.uniformlaws.org/committees/community-home?CommunityKey=2c04b76c-2b7d-4399-977e-d5876ba7e034)
- [AWS Artifact User Guide, Managing agreements](https://docs.aws.amazon.com/artifact/latest/ug/managing-agreements.html)
- [AWS Artifact User Guide, Accepting agreements for your AWS account](https://docs.aws.amazon.com/artifact/latest/ug/accept-single-agreement.html)
- [AWS Artifact User Guide, Accepting agreements for your organization](https://docs.aws.amazon.com/artifact/latest/ug/accept-org-agreement.html)
- [Google Workspace Admin Help, HIPAA compliance with Google Workspace and Cloud Identity](https://knowledge.workspace.google.com/admin/compliance/hipaa-compliance-with-google-workspace-and-cloud-identity)

Source: https://pacts.io/blog/can-a-baa-be-accepted-electronically
