BAA Generator
HomeResourcesDoes Epic Sign a HIPAA BAA?
Vendor BAA Guide

Does Epic Sign a HIPAA Business Associate Agreement?

By BAA Generator Editorial  ·  Published Apr 19, 2026  ·  Last reviewed Apr 19, 2026  ·  5 min read

Key Takeaways

Direct answer: Yes — Epic Systems executes HIPAA Business Associate Agreements as part of its standard EHR implementation agreements. The BAA is typically included in the master software agreement and is not a separate opt-in document. Review your implementation agreement for BAA provisions before go-live. Third-party integrations — including App Orchard apps — each require their own independent BAA.

How Epic's BAA Works in Practice

Epic's approach to HIPAA compliance differs from SaaS vendors that offer click-through BAAs. As an EHR vendor, Epic embeds BAA language directly into its master software and services agreement — the comprehensive contract signed by healthcare organizations at the start of an Epic implementation.

This means:

What Epic's BAA Covers

Epic's HIPAA BAA covers the core EHR software and services provided by Epic, including:

What Epic's BAA Does Not Cover: Third-Party Integrations

A critical compliance consideration for Epic customers: Epic's BAA covers Epic's own services only. It does not extend to third-party applications, vendors, or integrations.

Integration Type Covered by Epic BAA? Action Required
Epic core EHR software Yes Confirm BAA language in master agreement
Epic-hosted environment Yes Covered under Epic's BAA
App Orchard marketplace apps No Each ISV app needs its own BAA
HL7 interface partners No Each integration partner needs its own BAA
FHIR API connections No Each connecting application needs its own BAA
Cloud infrastructure (AWS, Azure) No If you self-host or use cloud, separate BAA with cloud provider

Epic App Orchard: BAA Considerations

Epic's App Orchard is a marketplace of third-party applications that integrate with Epic. Epic reviews these applications for interoperability, but App Orchard listing does not mean the ISV has a HIPAA BAA in place with your organization.

For every App Orchard application your organization uses, you must independently:

Frequently Asked Questions

Does Epic sign a HIPAA BAA?

Yes — Epic's HIPAA BAA provisions are embedded in its standard master software agreement. Review your implementation contract for this language. If absent, request it from your Epic account manager.

Where is the BAA in Epic's contract?

The BAA language is typically in the master software and services agreement signed during EHR implementation. Review the agreement with your legal counsel to confirm the BAA provisions are present and adequate.

Do third-party Epic integrations require their own BAA?

Yes — Epic's BAA covers only Epic's services. Every third-party app (App Orchard, HL7 partners, FHIR API connections) requires its own independent BAA. This applies even to applications listed and reviewed on the App Orchard marketplace.

For a broader look at which vendors sign HIPAA BAAs, see our vendor BAA lookup guide.

Note: Vendor BAA policies change. Verify current terms directly with Epic before making compliance decisions.

Need BAAs for your Epic ecosystem vendors?

Epic provides their BAA — but every third-party integration you add needs its own. Generate one in minutes.

Generate BAA for Free →