Help Center / BAA tracking

BAA tracking

If you handle PHI, every business associate needs a current, complete Business Associate Agreement (HIPAA §164.308(b)). Covenant tracks the BAA lifecycle, checks it against the §164.504(e) required clauses, follows subcontractor flow-down, and keeps a renewal calendar.

The BAA record (vendor detail)

On a vendor's detail page, the Business Associate Agreement (BAA) card holds:

FieldMeaning
BAA statusnone / pending / signed / expired.
Breach-notification SLA (days)How quickly the BA must notify you of a breach.
Executed dateWhen the BAA was signed.
Next review dateDrives the review flag (see below).
Term end (expiry)When the agreement term ends — drives the executed-document expiry flag.

Lifecycle flags

Covenant computes a flag from the status and next-review date, relative to today:

FlagWhenSeverity
BAA required, none on filePHI vendor with no BAAcritical
BAA pending signatureStatus = pendinghigh
Review overdue by N daysReview date in the pastcritical
Review due in N daysWithin 30 dayshigh
Review due in N days31–90 daysmedium
Signed, review in N daysMore than 90 days outinfo
No BAA requiredNon-PHI vendor, no BAAinfo

A missing BAA on a PHI vendor also subtracts −15 from the composite score (see Risk scoring).

§164.504(e) required-clause gap-check

The card lists the eleven HIPAA-required BAA clauses. Tick each clause your executed agreement actually contains. Covenant shows a running count (e.g. "8/11 (3 missing)") and marks the BAA ✓ complete when all required clauses are present.

ClauseCFR
Permitted uses & disclosures§164.504(e)(2)(i)
No further use/disclosure§164.504(e)(2)(ii)(A)
Safeguards§164.504(e)(2)(ii)(B)
Breach reporting§164.504(e)(2)(ii)(C)
Subcontractor flow-down§164.504(e)(2)(ii)(D)
Access to PHI§164.504(e)(2)(ii)(E)
Amendment of PHI§164.504(e)(2)(ii)(F)
Accounting of disclosures§164.504(e)(2)(ii)(G)
Availability to HHS§164.504(e)(2)(ii)(H)
Return/destruction at termination§164.504(e)(2)(ii)(I)
Termination for breach§164.504(e)(2)(iii)
An optional AI Draft gap-check narrative button explains the missing clauses and what to ask the vendor. It is advisory; see Settings & AI.

Subcontractor flow-down chain

HIPAA requires a business associate to flow down BAA obligations to its own subcontractors. Add each subcontractor and mark whether a downstream BAA exists. A subcontractor without a downstream BAA is flagged, so a gap deep in the chain is visible.

  1. Type the subcontractor name.
  2. Tick has downstream BAA if confirmed.
  3. Click Add. Use ✕ to remove one.

Executed-document tracking & expiry

Distinct from the review-date flag, Covenant separately tracks whether the executed BAA file is on record and whether its term is still current:

StateMeaning
missing-docNo executed BAA file attached (and one is required).
currentExecuted BAA on file, term not near expiry.
expiringTerm ends within 60 days.
expiredTerm has ended.
naNo BAA document required.

Attach the executed BAA in the Evidence attachments card (kind = baa) and set Term end to drive the expiry flag. See Evidence attachments.

The BAAs tab: renewal calendar & inventory

Renewal calendar & reminders

The BAAs tab opens with a BAA renewal calendar & reminders panel. It buckets every PHI BAA on a 90/60/30-day cadence and shows:

Deferred: live email/Slack delivery of these reminders runs on the hosted send runner. The cadence and recipients are computed now; the panel shows you exactly what would be sent. See Notifications & offline.

BAA inventory + CSV export

Below the calendar, the BAA inventory lists every PHI vendor and BAA, sorted by urgency (missing and overdue first), with status, executed date, next review, breach SLA, and flag. Click Export BAA inventory (CSV) for an auditor-ready covenant-baa-inventory.csv.