Skip to main content
← Back to glossary
Compliance & consent

BAA (Business Associate Agreement) lifecycle

Qu'est-ce que BAA (Business Associate Agreement) lifecycle?

Cette entrée n'est actuellement disponible qu'en anglais.

A Business Associate Agreement (BAA) lifecycle is the tracked sequence of states an organization moves through as it executes and renews its HIPAA Business Associate Agreement with a platform: `pending` (PHI is in scope, awaiting a signature), `executed` (signed and within the one-year term), and `expired` (the term lapsed). Because only the `executed` state satisfies the platform's HIPAA-enable and send gates, lapse or pending states reject PHI sends with a dedicated error until the agreement is re-executed.

More detail

The lifecycle is tenant-owned and deliberate. You attest that Protected Health Information is in scope for your organization, preview the agreement template, sign with a type-the-name e-signature, and download the executed copy; the platform supplies the e-sign pipeline and immutable audit anchoring, but the legal determination that PHI is in scope remains yours. Enabling HIPAA mode is a separate opt-in workspace-owner toggle that the gate refuses until an executed BAA is on file.

The status machine is narrow: when PHI enters scope the record moves from `not_required` to `pending` automatically, the signed agreement holds `executed` for a one-year term, and after the term it flips to `expired` — PHI sends gate again from that state. Re-execution opens 60 days before expiry, so renewal never requires a coverage gap. An organization that no longer handles PHI reverts to the platform default rather than letting the agreement lapse silently.

The send gate is fail-closed: when PHI is in scope and the status is anything other than `executed`, traffic is rejected with `HIPAA_BAA_REQUIRED` (or `HIPAA_BAA_INVALID` for a recorded but invalid agreement) rather than silently dropped or delayed, so the lifecycle state is observable desk-side from the rejection itself.

Questions fréquentes

Which BAA status unblocks HIPAA sends?
Only `executed` — a signed agreement inside its one-year term. `pending` (awaiting signature) and `expired` (past the term) both reject PHI sends until the agreement is (re-)executed; `not_required` applies when PHI was never declared in scope.
When should a BAA be renewed?
Before its one-year term ends. The re-execute path opens 60 days ahead of expiry, which gives you a window to renew without the status ever falling back to `expired`; if the term does lapse, PHI sends gate again immediately until you re-execute.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.