BAA for Cloud Providers: What Your Practice Must Get
Your vendor inventory has 41 rows. Thirty-eight have a signed business associate agreement on file. The other three are cloud tools someone in billing paid for with a practice credit card — a file-transfer service, an AI note-taking app, and an offsite backup account that has been running since 2021. A BAA for cloud providers is the single piece of paper that separates "documented vendor relationship" from "impermissible disclosure of PHI," and right now you have three of them missing.
This article is for the person who has to close that gap: which cloud vendors legally require an agreement, which clauses to read before signing the vendor's version, what deadlines to negotiate, and what the file folder looks like when OCR or an enterprise client asks to see it.
Does a Cloud Provider Need a BAA? The Short Answer
Yes. If a cloud service provider creates, receives, maintains, or transmits protected health information on your behalf, it is a business associate under 45 CFR 160.103, and you must have a written business associate agreement in place before PHI goes into that system.
Three points that resolve most arguments:
- Encryption does not exempt the vendor. OCR's cloud computing guidance states plainly that a CSP storing only encrypted PHI, without the decryption key, is still a business associate.
- Not looking at the data does not exempt the vendor. "No-view" services are business associates. Maintaining PHI is enough.
- The conduit exception almost never applies. It covers transmission-only services with transient storage — think a telecom carrier or the postal service — not a platform that persistently stores your files.
HHS published this position in its guidance on HIPAA and cloud computing, and it has not softened since. If a sales rep tells you their platform is "HIPAA compliant" but declines to sign, the platform is not usable for PHI at your practice.
Sorting Your Vendor List: Which Cloud Tools Actually Trigger a BAA
Requires a BAA
Cloud storage and file sync where charts, imaging, or claim files land. Offsite backup and disaster recovery. Email and calendar platforms where staff discuss patients. E-fax services. Transcription and ambient documentation tools. Scheduling and intake platforms. Patient texting and reminder services. Billing clearinghouses and revenue cycle portals. Analytics dashboards fed from your EHR. Remote support and RMM tools your IT contractor uses to reach workstations. Password managers that hold credentials to systems containing PHI — treat those as in scope unless you can prove no PHI passes through.
Usually does not require a BAA
An accounting package holding no patient data. A payroll processor. A marketing site with no forms that collect health information. Internet service. A conference-room booking tool.
The gray rows worth a written decision
Website form providers, chat widgets, and analytics scripts on pages where patients request appointments. If a form field can carry a name plus a reason for visit, you are collecting PHI. Document your determination for each gray row — vendor name, what data flows, your conclusion, the date, and who decided. That memo is the artifact an investigator wants when your answer is "no BAA needed."
The Clauses to Check Before You Sign a BAA for Cloud Providers
Most cloud vendors hand you a standardized agreement, often as a click-through attached to their terms of service. Read it against the required elements in 45 CFR 164.504(e). HHS publishes sample business associate agreement provisions that map to each requirement.
- Permitted uses and disclosures. Narrow and specific. Watch for language letting the vendor use "de-identified" or "aggregated" data for product development — that is a business decision, not a compliance one, but you should make it knowingly.
- Safeguards. An express commitment to implement Security Rule administrative, physical, and technical safeguards.
- Subcontractors. The vendor must obtain equivalent written agreements from downstream subcontractors. Your cloud vendor almost certainly runs on someone else's infrastructure.
- Breach and incident reporting. Reporting of security incidents and breaches of unsecured PHI, with a stated deadline.
- Individual rights support. The vendor must make PHI available so you can meet access, amendment, and accounting-of-disclosures obligations — within a timeframe that lets you hit your own 30-day access clock.
- HHS access. The vendor makes its practices, books, and records available to HHS.
- Return or destruction at termination. Get the mechanics: how the export is delivered, in what format, how long you have, and when backups purge.
- Termination for cause. Your right to terminate on material breach.
- Consistency with the service agreement. OCR is explicit that SLA terms — availability, backup, data return, restrictions on use — must not conflict with the BAA. A BAA promising data return alongside an SLA disclaiming all data recovery is a contradiction you will regret during an outage.
When a vendor's form is thin, or when you are the business associate being asked for paper by a hospital client, drafting from scratch wastes a week. A six-step BAA generator that exports signature-ready PDF and DOCX gets you a complete agreement covering all nine elements in an afternoon, one-time purchase, no subscription. Use it for the vendors who shrug and say "send us yours."
The Deadlines Buried in the Fine Print
HIPAA gives a business associate up to 60 days from discovery to notify you of a breach of unsecured PHI. That is a ceiling, not a target — and it is a terrible number for you, because your 60-day clock for notifying patients runs from the date the breach is discovered, which regulators may treat as the date your business associate discovered it.
Negotiate faster. Ask for notice of a suspected breach within 5 business days and notice of any security incident affecting your tenant within 10. Push for a named human contact, not a support queue. Then write the practical detail into your own incident response plan: who at your practice receives that notice, who logs it, and who starts the risk assessment under 45 CFR 164.402.
Two other timelines to check: how long the vendor keeps data after you cancel (30, 60, 90 days is typical, and backup purge often lags the primary deletion), and how fast the vendor can produce a full export when you switch platforms.
Also on your radar: the proposed Security Rule update
In January 2025, HHS published a notice of proposed rulemaking to strengthen the HIPAA Security Rule. Among the proposals: requiring business associates to give covered entities written verification, on a recurring basis, that required technical safeguards are actually deployed, and requiring faster notice when a vendor activates its contingency plan. It is a proposal, not law, and nothing in it obligates you today. But if you are signing multi-year cloud contracts now, build in a right to request that verification so you are not renegotiating later.
Where a BAA for Cloud Providers Breaks Down in Real Practices
Click-through agreements nobody saved. Someone accepted the vendor's BAA inside an admin console in 2022. There is no PDF, no signature, no date. Log into every cloud console, find the compliance or legal tab, download the executed agreement, and file it. If the platform only shows "accepted," screenshot it with the date and account name.
Shadow IT. A provider uses a personal cloud drive to move a case file home. A front-desk staffer uses a free online PDF converter on a scanned insurance card. Pull your last three months of card statements and your firewall or DNS logs. That is where the unlisted vendors are.
Free tiers. Many vendors sign BAAs only on paid plans. A practice running on a free tier often has no agreement at all, even though the paid version of the same product would be fine.
Vendors who signed and then changed. Acquisitions, new subprocessors, and new regions all shift the picture. Re-verify annually.
What OCR Has Actually Penalized
Missing agreements have been enforced on their own, without any hacker involved. Oregon Health & Science University reached a $2.7 million settlement with OCR in 2016 in a case that included storing PHI on a cloud vendor's server without a business associate agreement. In 2017, Center for Children's Digestive Health settled for $31,000 over a missing agreement with a records storage vendor. The size scales with the organization; the finding is the same — PHI went to a vendor with no contract.
You can see how frequently vendor-side incidents drive large reportable breaches by filtering the OCR breach portal for cases involving a business associate. Note also 45 CFR 160.410: correcting a violation within 30 days of learning about it can support an affirmative defense where the violation was not due to willful neglect. Discovering a missing BAA today and executing one this week is materially better than discovering it during an investigation.
A 30-Day Workflow to Close the Gaps
Days 1–5 — Build the real list. Practice manager pulls 12 months of card and ACH statements. Security Officer pulls a list of SaaS domains from network logs. Each department head names every online tool their team uses. Merge into one sheet: vendor, service, does PHI touch it, BAA on file yes/no.
Days 6–12 — Retrieve what exists. Privacy Officer downloads executed agreements from vendor portals and searches email for signed copies. File everything in one folder, named Vendor — Agreement Type — Execution Date.
Days 13–22 — Chase the gaps. One email per vendor requesting their BAA. If they have none, send yours. If they refuse, escalate to a documented decision: migrate, restrict the data flow, or stop using the tool. Record the decision and the date.
Days 23–30 — Fold it into your risk analysis. Every cloud vendor holding PHI belongs in your Security Rule risk analysis with its own entry: data types, access controls, encryption at rest and in transit, and BAA status. If your risk analysis is a stale document, tools that generate a current risk analysis and policy set will get you to a defensible baseline faster than rebuilding a spreadsheet.
What the Evidence Folder Looks Like
For each cloud vendor handling PHI, an auditor or enterprise client should find: the executed BAA with both signature blocks and a date; the underlying service agreement; a written subcontractor representation; the vendor's current third-party security report — useful as diligence, though no report and no product constitutes government HIPAA certification, which does not exist; your risk analysis entry; the named breach-notification contact; and the annual review date with initials.
For each vendor you decided doesn't need one: a dated memo explaining why.
Set a recurring calendar item — same month every year — to re-run the list. Vendors change, staff sign up for new tools, and the folder goes stale in about eleven months.
If your gap list already has names on it, start with the vendors that refuse to supply paper. Generate a complete, signature-ready business associate agreement, send it for countersignature, and file the executed PDF this week.