BAA vs NDA: Which One Your Vendor Contract Needs
A transcription vendor emails your practice manager a two-page mutual nondisclosure agreement on Monday. She signs it Tuesday. By Friday the vendor has login credentials to your scheduling system and is pulling audio files that include patient names, dates of birth, and clinical narrative. Your practice now has an unwritten business associate relationship and a signed document that does nothing to satisfy HIPAA.
That is the baa vs nda problem in one sentence: the two documents look similar, get signed by the same people, and cover completely different obligations. This article explains which one you need, when you need both, and what an auditor will ask you to produce when a records request or a breach investigation lands on your desk.
BAA vs NDA: The Difference in One Paragraph
A Business Associate Agreement (BAA) is a HIPAA-required contract under 45 CFR 164.504(e) that permits a covered entity to disclose protected health information to a vendor, and binds that vendor to specific safeguard, breach-reporting, subcontractor, and PHI-return obligations enforceable by HHS. A Nondisclosure Agreement (NDA) is a private confidentiality contract that protects information from disclosure, enforceable only by the parties who signed it. An NDA never satisfies HIPAA. A BAA covers PHI but usually says nothing about your pricing, your algorithms, or your unreleased product roadmap. Most vendor relationships that touch PHI need both.
What an NDA Actually Buys You
An NDA is a promise not to tell. It defines confidential information, sets a term, carves out exceptions for publicly known material, and gives you a private cause of action if the other side leaks.
That is genuinely useful. Your NDA is the document that protects your fee schedule when you're negotiating with a billing company, your referral-pattern data during a practice acquisition, or your operational workflows when you pilot a new scheduling tool.
What the NDA does not do: it does not impose HIPAA's Security Rule on the vendor, it does not make the vendor directly liable to HHS, it does not require the vendor to report security incidents to you on a defined clock, and it does not force the vendor to flow obligations down to its own subcontractors. If OCR asks whether you had a compliant agreement in place, an NDA is not an answer.
The Ten Provisions a BAA Must Contain That Your NDA Won't
Pull your standard NDA template and check it against 45 CFR 164.504(e)(2). HHS publishes sample business associate agreement provisions that track the regulation. A compliant BAA must:
- Establish the permitted and required uses and disclosures of PHI by the business associate.
- Prohibit use or disclosure other than as permitted by the contract or required by law.
- Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
- Require the business associate to report to you any use or disclosure not permitted by the contract, including breaches of unsecured PHI and security incidents.
- Require the business associate to bind its subcontractors to the same restrictions.
- Make PHI available so you can meet a patient's right of access under 164.524.
- Make PHI available for amendment under 164.526.
- Provide the information you need to produce an accounting of disclosures under 164.528.
- Make internal practices, books, and records available to HHS for compliance review.
- Require return or destruction of PHI at termination, where feasible, and authorize you to terminate for material breach.
Ten items. A typical mutual NDA covers zero of them. That's not a drafting oversight — the documents were built for different purposes.
The Breach Clock Is the Provision That Bites
Under HIPAA's breach notification requirements, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Your own 60-day clock to notify affected patients runs from your discovery — and if the business associate is your agent under federal common law, its discovery is imputed to you.
Read that twice. If your vendor sits on a breach for 55 days and your BAA permits it, you have five days left to identify individuals, draft letters, staff a call line, and file with HHS. Negotiate the reporting window down. Ten calendar days for confirmed breaches and five business days for suspected incidents is a defensible ask, and most competent vendors will accept it.
BAA vs NDA Is Rarely Either/Or
The common mistake is treating this as a choice. In practice, a vendor with access to PHI and to your business information needs both documents, or a single agreement with both sets of terms clearly separated.
Think about which direction the information flows:
- PHI flows from you to the vendor — you need a BAA. Non-negotiable.
- Your confidential business information flows to the vendor — you need NDA terms protecting you.
- The vendor's confidential information flows to you — the vendor needs NDA terms protecting them, which is why they send mutual NDAs.
- All three — the normal case. Execute a BAA and an NDA, or a master services agreement that incorporates both.
One structural note: keep the BAA as a standalone exhibit or separate document rather than burying HIPAA provisions inside a 40-page services agreement. When OCR requests "the business associate agreement," you want to hand over a discrete, signed, dated document — not highlight paragraphs 14.3 through 14.9 of a contract that also covers uptime credits.
Which Vendors Need a BAA
The test is function, not job title. A business associate is a person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity, or provides listed services involving PHI disclosure. HHS's business associate guidance is the authority.
Vendors that almost always need a BAA: billing and revenue cycle companies, transcription services, cloud EHR and practice management hosts, offsite backup and document storage, shredding companies that handle records before destruction, IT support with server or workstation access, answering services, claims clearinghouses, patient communication and reminder platforms, collections agencies, coding auditors, and outside counsel reviewing charts.
Who Doesn't Need One
Conduits — entities that only transport PHI without accessing it other than randomly or incidentally — fall outside the definition. The postal service and most internet service providers qualify. HHS reads this exception narrowly; a cloud storage provider is not a conduit even if it never looks at the data, because it maintains PHI persistently.
Also outside: your workforce members (covered by policies and sanctions, not BAAs), other covered entities receiving PHI for treatment purposes, and vendors with genuinely no PHI exposure. A janitorial service that empties trash in a building where charts are locked in a room it cannot enter is not a business associate. A janitorial service with a key to the records room is a harder call — write a BAA and stop debating it.
If your vendor list has never been sorted this way, that inventory is the first deliverable. Column headers: vendor name, service provided, PHI access yes/no, BAA on file yes/no, execution date, subcontractors disclosed, renewal date, owner on your staff. Anyone identified as a business associate without a signed agreement needs one before the next disclosure. A six-step BAA generator that produces a signature-ready agreement in PDF and DOCX will close that gap faster than routing each one through outside counsel, and it costs a one-time fee rather than a subscription.
What Enforcement Has Looked Like
OCR has settled cases specifically over missing business associate agreements. Raleigh Orthopaedic Clinic paid $750,000 in 2016 after transferring X-ray films containing PHI to a vendor without executing a BAA. Center for Children's Digestive Health settled for $31,000 in 2017 over records stored with a vendor for years with no agreement in place.
Notice the pattern. Neither case turned on a hacker. Both turned on paperwork that should have existed before the PHI moved. The OCR breach portal continues to log incidents where the covered entity's exposure came through a vendor relationship — and the first question in that investigation is always whether an agreement existed and what it said.
Worked Example: Onboarding a Billing Vendor in Ten Business Days
Here's a workflow you can hand to whoever owns vendor contracting.
Days 1–2. Privacy officer completes the PHI-access determination. Documents the answer in the vendor file with a one-line rationale: "Vendor receives full claims data including diagnosis codes and patient demographics. Business associate under 164.502(e)."
Days 3–4. Send your BAA template, not theirs. If you must use the vendor's paper, redline three things: the breach reporting window, the subcontractor flow-down obligation, and the return-or-destroy provision at termination. Vendors frequently soften all three.
Days 5–6. Send the NDA separately. This is where you protect your fee schedule, payer contract terms, and internal workflows — the material the BAA doesn't touch.
Days 7–8. Collect vendor security documentation. Ask for their most recent risk analysis date, their subcontractor list, their encryption posture for data at rest and in transit, and their named security official. Keep the responses in the vendor file. This is your due-diligence evidence.
Days 9–10. Countersign both documents. Log execution dates in the vendor register. Set a calendar reminder for annual review and for the contract renewal date. Only then does the vendor get credentials.
The order matters. Access follows signature. If you find yourself granting access while contracts are "in legal," you have already created the exposure this whole process exists to prevent.
What the Evidence File Looks Like
When someone asks you to demonstrate compliance, produce:
- The current vendor inventory with PHI-access determinations.
- Signed, dated BAAs for every vendor flagged as a business associate.
- Documented rationale for vendors you determined are not business associates.
- Due diligence records — security questionnaires, attestations, subcontractor disclosures.
- Evidence of periodic review, with dates and the name of the reviewer.
- Termination records showing PHI was returned or destroyed when relationships ended.
Item six is the one nobody has. When you fire a billing vendor, someone has to obtain written confirmation that PHI was returned or destroyed. Build it into your offboarding checklist alongside credential revocation.
What's Changing
HHS published a proposed Security Rule update in January 2025 that would, among other changes, require business associates to verify to covered entities — annually, in writing, through analysis by a subject matter expert — that they have deployed required technical safeguards. As of this writing the rule is not final. But the direction is clear: attestation obligations on vendors are tightening, and the era of a signed BAA sitting untouched in a drawer for six years is closing.
Practices that already collect annual security attestations from their vendors will find compliance routine. Practices that treat the BAA as a one-time signature event will be rebuilding their vendor program under deadline.
Get the Agreements Executed
Resolve the baa vs nda question the same way every time: NDA for your business secrets, BAA for patient information, both for any vendor who touches both. Then get the BAAs signed before access is granted, not after.
If your vendor inventory has gaps, generate a compliant Business Associate Agreement through a guided six-step wizard and export it as PDF or DOCX for signature — one purchase, no recurring fee. For the broader document set behind it, including risk analysis and policies, the full HIPAA compliance toolkit covers what auditors ask for after the BAA question.