What Is a BAA and When Does Your Practice Need One?

George
By George
7 September 2026
Signed business associate agreement folder

Sooner or later, every medical, dental, or therapy practice hits the question mid-decision: a new vendor is about to touch patient information, someone asks "do we have a BAA with them?", and the room goes quiet. So, what is a BAA? A Business Associate Agreement is the written contract HIPAA requires between your practice and any outside company that creates, receives, maintains, or transmits protected health information on your behalf. No agreement, no patient data, that is the rule, and it applies before the first record moves, not after.

This guide explains the BAA in plain language: who needs one and who does not, what the contract must actually contain, what signing one does and does not accomplish, the mistakes that quietly void the protection, and how to run the vendor inventory that keeps your practice covered.

What Is a BAA, and Where the Requirement Comes From

The BAA meaning is easiest to see from HIPAA's point of view. The law binds covered entities, practices, plans, and clearinghouses, directly. But modern care runs on vendors: someone hosts the records, someone processes the billing, someone manages the computers. HIPAA's answer is to extend the obligations by contract. The regulations, principally 45 CFR 164.308(b) and 164.504(e), require a written agreement before a vendor handles protected health information (PHI) for you, and that agreement is the BAA. It converts the vendor into a business associate with its own legal duties, including direct exposure to enforcement, and it is the single document that makes an outside company lawful to use with patient data. Encryption, reputation, and good intentions do not substitute for it; the contract decides.

Who Counts as a Business Associate

The test is function, not industry: does the vendor create, receive, maintain, or transmit PHI on the practice's behalf? In a typical small practice, the yes column is longer than people expect:

  • The EHR or practice management platform hosting the charts
  • The billing company and any collections service working your accounts
  • Your IT provider, because administering systems that hold PHI is handling PHI, and yes, that includes a firm like ours
  • Email, file storage, fax, and phone platforms when patient information flows through them
  • The answering service taking patient calls after hours
  • Transcription, shredding, and records-storage companies
  • Consultants and accountants whose work requires access to records containing PHI

The chain does not stop at your vendors. When a business associate hands PHI to its own subcontractor, a data center, for instance, the rules require an equivalent agreement one level down. Your contract must say so, and a serious vendor will already have that flow-down in place.

Vendors connected to medical practice

The narrow conduit exception

One carve-out exists and it is smaller than vendors like to claim: services that merely transport data without storing it or accessing it in the ordinary course, the way a courier moves a sealed envelope, are conduits rather than business associates. Your internet provider fits. A platform that stores patient files on its servers does not, no matter how briefly it insists it looks at them. When a vendor waves the conduit flag to avoid signing, treat it as a red flag instead.

When a BAA Is Required, and When It Is Not

Requirement follows PHI, so the map is simple to draw. A BAA is required for any vendor whose service involves patient information, even occasionally, even "just metadata about appointments," because appointment data tied to identity is PHI. A BAA is not required for your own employees, who are workforce rather than business associates and are governed by training and policy instead. It is not required for vendors whose service never touches PHI, the landscaper, the coffee supplier, the janitorial crew whose incidental exposure to a glimpsed screen is handled by safeguards rather than contracts. And patients themselves are never business associates. The gray areas, a marketing firm running your patient newsletter, a software add-on that reads calendar data, resolve the same way every time: trace where PHI actually flows, and the answer falls out.

What a BAA Must Include

The regulation dictates the skeleton of every legitimate BAA, which is why the documents look similar across vendors. In plain terms, the agreement must:

  • Define permitted uses and disclosures the vendor may use PHI only to deliver the contracted service, not for its own purposes
  • Require appropriate safeguards, including compliance with the Security Rule for electronic PHI
  • Obligate the vendor to report breaches and security incidents to your practice, so your own duties can start on time
  • Flow the same obligations down to any subcontractor that touches the data
  • Support patient rights, meaning the vendor helps you provide access, amendments, and an accounting of disclosures when the data sits on its systems
  • Open its books to regulators, making records available to the Department of Health and Human Services on request
  • Settle the ending — return or destruction of PHI when the relationship terminates, and your right to terminate for a material breach of the agreement

HHS publishes sample business associate agreement provisions that show exactly how regulators expect these elements to read, and comparing a vendor's paper against that sample is a fast sanity check. What the regulation does not standardize, indemnification, liability caps, insurance requirements, audit rights, is where vendor agreements genuinely differ, and those business terms deserve a review by your attorney rather than a signature on autopilot.

Required provisions of a BAA

Reading a vendor's BAA in ten minutes

Most practices sign whatever paper the vendor sends, and most of the time that paper is fine, but a ten-minute skim catches the exceptions. Check four things first: that breach notification comes with a stated timeframe in days rather than a vague "promptly"; that the subcontractor flow-down clause exists at all; that termination triggers return or destruction of your data rather than silence; and that the permitted-uses section does not quietly grant the vendor broad rights to use "de-identified" or "aggregated" versions of your patients' data for its own purposes, a clause that is common, consequential, and exactly the kind of business term your attorney should see before you agree to it.

What a BAA Does Not Do

Signing the agreement is necessary and wildly insufficient, and both halves of that sentence matter. The BAA does not make your practice compliant; your obligations under the HIPAA Security Rule, risk analysis, safeguards, training, configuration, remain yours with or without any vendor. It does not transfer accountability: if patient data is exposed through a vendor you chose carelessly, the exposure is still your practice's event, with your name in the notification letters. And it does not certify competence: a signature proves willingness, not capability, which is why the agreement is one input into vendor selection rather than the whole decision. The evaluation discipline around that decision is its own subject, and our guide to third-party risk management covers how practices vet the companies behind the signatures.

The Mistakes That Void the Protection

Most BAA failures we find in assessments are not exotic; they are the same short list, repeated across practices.

The vendor everyone forgot

The EHR has an agreement because the EHR salesperson brought one. The email platform, the cloud storage account, and the answering service somehow never did, even though patient information moves through all three daily. The forgotten vendors are almost always the general-purpose tools, precisely because nobody thinks of them as healthcare companies. Where patient data actually sits and travels in a modern practice is broader than the chart system, and our breakdown of patient data in the cloud shows how far the footprint really extends.

One vendor missing a BAA

The consumer-tier account with no BAA path

Free and personal-tier services frequently offer no agreement at all, which makes them unusable for PHI regardless of settings. The fix is structural, not behavioral: move the workload to a business tier where a BAA exists, because policy memos do not stop a convenient tool from being convenient.

Unsigned, expired, or unfindable paper

An agreement someone remembers signing but nobody can produce fails the audit the same way a missing one does. Execution and storage are part of the control: signed copies, one location, retrievable in minutes. Watch for quiet drift, too: when a vendor is acquired or migrates platforms, the entity named on your old agreement may no longer be the company holding your data, and the renewal review is the moment to catch it.

No flow-down, and nobody asked

The vendor signed, then quietly handed your data to a subcontractor with no equivalent agreement. Asking one question during onboarding, "which subcontractors touch our data, and are they under BAA with you?", closes the gap most practices never look at.

The opposite failure: a BAA with everyone

Some practices, once burned, demand agreements from every vendor including the ones that never see PHI. It feels safe and it corrodes the program: the inventory bloats, real business associates blur into noise, and renewals stop being reviewed. Precision is the protection, agreements exactly where PHI flows, and nowhere else.

Building and Keeping Your BAA Inventory

The sustainable version of all this is a small, boring system, and it takes an afternoon to build. List every vendor the practice pays. Mark the ones whose service touches PHI, using the create-receive-maintain-transmit test and following the data rather than the vendor's industry label. Execute agreements where the mark says yes, chase the missing ones this month rather than someday, and store the signed set in one place with the rest of your compliance records. Then put two recurring dates on the calendar: review the inventory when any vendor contract renews, and once a year regardless, because practices add tools faster than they add paperwork. The exercise slots naturally into the annual pass through your HIPAA compliance checklist, and into the risk analysis that the checklist feeds. We run this exact inventory as part of HIPAA compliance engagements for medical offices, therapy groups, and dental practices from Westlake Village across the LA area, and the most common finding is the happy kind: the gap list is short once someone finally writes it down.

BAA inventory with annual review

Frequently Asked Questions

A Business Associate Agreement is the written contract HIPAA requires between a covered entity, such as a medical or dental practice, and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It defines the vendor's permitted uses of the data, its safeguard and breach-reporting duties, and what happens to the information when the relationship ends.
Any vendor whose service involves patient information: EHR and billing platforms, IT providers, covered email and storage services, answering services, transcription and shredding companies, and similar. The vendor's subcontractors that touch the data need equivalent agreements one level down. Employees are workforce, not business associates, and vendors that never handle PHI need no agreement at all.
The required elements come from the regulation: permitted uses and disclosures limited to the service, safeguards including Security Rule compliance, breach and incident reporting to the practice, and flow-down of obligations to subcontractors. The list continues with support for patient access and amendment rights, availability of records to HHS, and return or destruction of PHI at termination alongside a termination-for-breach right.

So, what is a BAA, in the end? It is the one page of paper that decides whether a vendor is lawful to trust with your patients' information, and the inventory of those pages is a control your practice can finish this month.

If you would like the gap list written for you, book a BAA and vendor review with GlobeVM and we will walk your vendor list line by line.

Comments

0 Comments