BAA HIPAA Rules: Who Needs One and What Goes In It
A document scanning company backed a van up to your records room on a Tuesday, took 340 paper charts, and returned them digitized eleven days later. Nobody at your practice can find a signed agreement with them. That single gap — a missing BAA, HIPAA's required contract with any vendor that touches protected health information — is one of the fastest ways a routine complaint turns into a multi-year corrective action plan. This article covers which vendors need a business associate agreement, the nine provisions the regulation actually mandates, the breach-notification clocks your contract sets, and the documented evidence an investigator will ask for first.
What a BAA Is Under HIPAA — and Who Has to Sign One
A business associate agreement is a written contract required by 45 CFR 164.502(e) and 45 CFR 164.308(b) between a covered entity and any person or organization that creates, receives, maintains, or transmits protected health information on the covered entity's behalf. The covered entity must obtain satisfactory assurances, in writing, that the vendor will safeguard PHI. A business associate must in turn obtain the same assurances from its own subcontractors.
Three things follow from that definition, and operators miss all three regularly:
- The trigger is function, not job title. If the vendor performs a service for you that involves PHI, it is a business associate — regardless of whether it calls itself a "technology partner" or a "consultant."
- Access counts, even without use. A vendor that could view PHI while performing maintenance is a business associate even if its staff never opens a chart.
- Since 2013, business associates are directly liable. The HITECH Act and the Omnibus Rule made vendors subject to OCR enforcement on their own, independent of your contract.
HHS maintains detailed guidance on business associates that walks through the boundary cases. Read it once a year; it settles most internal arguments.
The Vendors on Your List That Need a BAA — and the Ones That Don't
Pull your accounts payable ledger for the last eighteen months. That list, not your IT inventory, is where your business associates hide.
Almost certainly business associates
Billing and revenue cycle companies. Transcription services. Answering services and after-hours triage lines. Shredding and document destruction vendors. Off-site record storage. Collection agencies. IT managed service providers with remote access to workstations. Cloud hosting and backup providers. Email and secure messaging platforms that carry PHI. Practice consultants who review charts. Outside coders. Data analytics firms. Marketing agencies that handle patient lists. Release-of-information vendors.
Usually not business associates
Conduits. The postal service, private couriers that only transport sealed packages, and internet service providers that merely transmit data qualify for the narrow conduit exception. HHS has been explicit that this exception is limited to transmission-only services with transient access. A cloud provider that stores your data is not a conduit — it is a business associate, even if the PHI is encrypted and the vendor holds no key. HHS said so directly in its cloud computing guidance.
Treatment relationships. A specialist you refer to is not your business associate. Disclosures for treatment between covered entities do not require a BAA.
Workforce members. A part-time biller on your payroll is workforce, governed by your policies and sanctions, not a contract.
Janitorial, landscaping, and building maintenance generally do not need a BAA — but if your cleaning crew empties bins containing PHI in exam rooms and the front office, you either need a BAA or a hard rule that all PHI goes to locked shred consoles the vendor never opens. Write down which choice you made and when.
The Nine Provisions Every BAA HIPAA Requires
A compliant agreement is not a one-page letter of assurance. The regulation at 45 CFR 164.504(e) requires that the contract:
- Describe the permitted and required uses and disclosures of PHI by the business associate, and prohibit any use or disclosure the covered entity itself could not make.
- Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
- Require reporting of any use or disclosure not permitted by the contract, including security incidents and breaches of unsecured PHI.
- Bind subcontractors to the same restrictions and conditions through written agreements.
- Provide access to PHI in a designated record set so the covered entity can satisfy a patient's right of access within the 30-day window.
- Make amendments to PHI when directed, so the covered entity can meet its amendment obligations.
- Maintain and furnish an accounting of disclosures.
- Make internal practices, books, and records available to HHS for compliance determination.
- Return or destroy all PHI at termination where feasible, and extend the protections indefinitely if return or destruction is not feasible.
The agreement must also authorize termination if the business associate materially breaches it. HHS publishes sample business associate agreement provisions covering all nine — useful as a benchmark, though the sample is deliberately generic and leaves the operational terms blank.
Blank is where practices get hurt. The sample does not set a notification deadline, does not define "security incident" in a way that stops your vendor from reporting every failed login, does not allocate breach notification costs, and does not require the vendor to carry cyber liability coverage. Those terms are yours to negotiate, and they matter far more at 9 p.m. on the night of an incident than the boilerplate does. If you are papering vendors from scratch, a tool that generates a signature-ready business associate agreement through a guided six-step wizard — with PDF and DOCX export on a one-time purchase — will get you a defensible baseline in an afternoon instead of a legal-review cycle per vendor.
The 60-Day Clock Your BAA Sets — and Why You Should Shorten It
Under the Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. You then have 60 days from your discovery to notify affected individuals.
Do the arithmetic. If your billing vendor takes the full 60 days, and your clock is read as starting when they tell you, patients may not hear anything for four months. If OCR reads the vendor's discovery as your discovery — which it can, where the vendor is your agent under the federal common law of agency — you have already blown the deadline before you knew anything happened.
Fix this in the contract. Standard terms worth insisting on:
- Notice to your privacy officer within five business days of discovery of a suspected breach, by named contact and phone, not a support ticket.
- Notice within 24 hours for ransomware, unauthorized access to a database, or law enforcement involvement.
- A defined content requirement: what happened, when, whose PHI, how many records, what data elements, what the vendor has done.
- The vendor cooperates with, but does not control, your risk assessment under 45 CFR 164.402.
- The vendor bears notification, credit monitoring, and call center costs for breaches caused by its own acts or omissions.
The OCR breach portal is public. Scroll it for ten minutes and note how many entries list a business associate as the source. Your vendor's failure becomes your reportable breach and your name on that page.
Subcontractors: Your BAA Obligations Don't Stop at Tier One
Your billing vendor uses an offshore coding contractor. That contractor uses a cloud file transfer service. Each downstream link needs its own BAA, flowing the same terms. You are not required to sign those agreements — the chain is contractual, not direct — but you are required to have obtained satisfactory assurances at your tier, and you are on the hook if you knew of a pattern of violation and failed to act.
Practical control: require your business associate to maintain a current list of subcontractors with PHI access and furnish it on request within ten business days. Ask for it annually. If the vendor cannot produce the list, that is a finding, and you document it.
A 30-Day Workflow to Close Your BAA Gaps
Assign this to one named owner. Diffuse ownership is why these projects stall.
Days 1–7: Build the inventory
Export vendor payments for 18 months from accounting. Add every SaaS login your staff uses, including anything an individual clinician expensed. Interview the front desk, the biller, and whoever handles IT. Ask one question: "Who outside this practice sees patient information?" You will find a fax-to-email service nobody remembered buying.
Days 8–14: Classify
For each vendor, record: does it create, receive, maintain, or transmit PHI? What kind — full charts, demographics only, claims data? Where does the data live? Mark each as business associate, conduit, or no PHI access. Write a one-sentence rationale for every "no." That sentence is your evidence.
Days 15–24: Paper the gaps
Request executed agreements from every business associate. For missing ones, send your BAA. Do not accept a vendor's terms of service that merely mentions HIPAA — check it against the nine provisions above. Track requests in a spreadsheet with a date sent and a date returned.
Days 25–30: File and calendar
Store signed agreements in one location with named-file conventions including the vendor name and execution date. HIPAA requires six-year documentation retention from creation or last effective date, whichever is later. Set a calendar reminder for each renewal and an annual review of the full list.
What an Investigator Asks For First
In a complaint-driven investigation, the data request typically arrives before anyone visits. Expect to produce, within 30 days:
- A list of all business associates with PHI access during the relevant period.
- Executed BAAs for each, with signature dates.
- Your most recent security risk analysis and risk management plan.
- Policies covering business associate management, breach notification, and sanctions.
- Workforce training records.
Enforcement history is instructive here. In 2016, OCR settled with an orthopaedic practice in North Carolina for $750,000 after it handed x-ray films to a vendor for digitization and silver recovery without a business associate agreement in place. The disclosure itself was routine business. The missing paper was the violation.
NIST's SP 800-66 Revision 2 maps Security Rule requirements to concrete safeguards and is the most useful free reference for building the risk analysis that sits alongside your BAA file.
What's Coming: The Proposed Security Rule Overhaul
HHS published a proposed rule in January 2025 that would substantially rewrite the Security Rule. Among the provisions relevant to vendor management: business associates would be required to verify their technical safeguards annually through a written analysis by a subject matter expert, with written certification delivered to the covered entity. The proposal would also tighten incident notification timelines for business associates.
As of December 1, 2025, that rule is not final and nothing in it is enforceable. But it signals direction. Contracts you sign now with three-year terms should already contemplate an annual verification obligation — write it in as a right to request evidence, and you will not need to renegotiate later.
Start With the List
The BAA HIPAA requirement is not complicated on paper. It becomes complicated because vendor relationships accumulate quietly and nobody owns the file. Pick the owner, pull the payables ledger, and give yourself 30 days.
When you hit the vendors that need fresh paper, build the agreement in the BAA wizard and export a signature-ready PDF or DOCX the same day. If the gap analysis also exposed a stale risk analysis or missing policies, the broader compliance document set covers that ground. Either way, the deliverable is the same: a folder an investigator can open, with a signed agreement for every name on the list.