Count the vendors that touch protected health information in your practice right now. Most single-location clinics land somewhere between 14 and 40 — billing company, clearinghouse, transcription service, answering service, shredding vendor, IT managed service provider, patient reminder platform, cloud backup, the credentialing consultant who has a login to your practice management system. If you can't produce a signed agreement for every one of them within ten minutes, you need a business associate agreement checklist more than you need another policy binder.

This article covers what HIPAA actually requires in a BAA under 45 CFR 164.504(e), which terms you should negotiate even though the rule doesn't mandate them, who signs and when, and what the documented evidence looks like when OCR or a health plan auditor asks. It is written for the person who signs the contract, not the person whose chart is in it.

What a Business Associate Agreement Checklist Has to Cover

A compliant BAA must do nine things: define permitted uses and disclosures of PHI, prohibit other uses, require appropriate safeguards including Security Rule compliance, require reporting of breaches and security incidents, bind subcontractors to the same terms, support patient access and amendment rights, support an accounting of disclosures, make the business associate's internal practices and records available to HHS, and require return or destruction of PHI at termination. The agreement must also permit termination for material breach.

Anything beyond those nine — indemnification, insurance minimums, audit rights, a 15-day breach notice window — is negotiated leverage, not regulatory floor.

Step One: Build the Vendor Inventory Before You Draft Anything

You cannot check agreements against a list you don't have. Start with three sources: your accounts payable ledger for the last 24 months, your practice management system's user administration screen, and a walk-through with your front desk and billing lead asking "who do you send things to?"

The AP ledger catches contracted vendors. The user admin screen catches the ones nobody remembered granting access to — the former biller whose login is still active, the consultant's account from a 2023 project. The staff walk-through catches the shadow vendors: the free fax-to-email service someone signed up for, the scheduling tool a provider added on a credit card.

Who counts as a business associate

Anyone who creates, receives, maintains, or transmits PHI on your behalf to perform a function or service. That includes vendors who could access PHI even if they say they don't look at it — your IT provider with domain admin rights, your cloud storage vendor, your EHR host. HHS has been explicit that cloud service providers are business associates even when the data is encrypted and the vendor holds no decryption key.

Who doesn't

Pure conduits — the postal service, a courier who carries sealed envelopes, an ISP moving packets. Treating providers you refer to are covered entities in their own right and need no BAA for treatment disclosures. Your janitorial service, if it genuinely has no PHI access, sits outside the definition, though most practices handle that with a confidentiality clause anyway. HHS maintains guidance on the business associate definition that resolves most edge cases.

Document your "not a business associate" determinations in one paragraph each. When someone asks in three years why the landscaping company has no BAA, you want a dated note, not a memory.

The Nine Required Clauses, in Checklist Form

Work every agreement against this list. HHS publishes sample business associate agreement provisions that track the regulatory text — useful for comparison, but the sample is a starting point, not a finished contract.

  1. Permitted uses and disclosures. Specific to the service. "For any lawful purpose" is a red flag. A billing vendor's permitted uses are payment operations, not marketing analytics.
  2. Prohibition on other use or disclosure. Explicit, including a bar on selling PHI and on using it for the vendor's own product development unless de-identified under 164.514 and separately authorized.
  3. Safeguards. The vendor must implement administrative, physical, and technical safeguards and comply with the Security Rule directly. Name the standard if you can — encryption at rest and in transit, MFA on administrative accounts.
  4. Reporting. Breaches of unsecured PHI and security incidents. Note that these are different obligations with different thresholds.
  5. Subcontractors. The vendor must obtain written assurances from any downstream subcontractor. Your billing company's offshore coding partner is your exposure.
  6. Individual access. The vendor must make PHI available so you can meet 164.524 requests. If the vendor holds the designated record set, build the retrieval timeline into the contract.
  7. Amendment and accounting. Support for 164.526 amendments and 164.528 accountings of disclosures.
  8. HHS access. The vendor makes internal practices, books, and records available to the Secretary for compliance determination.
  9. Return or destruction at termination. Plus the infeasibility fallback: if return or destruction isn't feasible, protections extend indefinitely and further use is limited to what makes it infeasible.

Add the termination-for-cause right as a tenth line. It is required by the rule and routinely stripped out of vendor-drafted paper.

Where Vendor-Drafted Agreements Go Wrong

When a vendor sends you their BAA template, three things are usually missing or weakened. First, breach notification is set at "within 60 days of discovery" — which leaves you zero working time, because your own 60-day clock to notify patients started on the same discovery date under the Breach Notification Rule. Second, liability is capped at fees paid, often twelve months of a $400/month subscription. Third, the definition of "security incident" is narrowed to exclude unsuccessful attempts, which is fine, but sometimes narrowed to exclude anything the vendor unilaterally deems immaterial.

If you are redlining vendor paper rather than presenting your own, you have already lost the negotiation. Practices that lead with their own signature-ready document close faster and keep better terms. If you don't have a template you trust, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, and it produces the same document every time so your files stay consistent.

Terms Worth Negotiating That HIPAA Doesn't Require

A shortened breach notification window

Ask for notice within five business days of discovery for confirmed breaches, and 24 to 72 hours for security incidents involving your data. Vendors push back; meet at ten days. Put the required content in the clause — what happened, when, whose PHI, what was taken, remediation status — so the first notice is usable instead of a one-line email.

Cost allocation and insurance

Breach response costs money: forensics, notification printing and mailing, credit monitoring, call center, legal. Specify who pays. Require the vendor to carry cyber liability coverage at a stated limit and to name your practice as an additional insured or provide a certificate annually. A vendor with no cyber policy is telling you something.

Subcontractor disclosure

Require a current list of subcontractors with PHI access, updated on change, plus the right to object to a new one. This is how you find out your transcription vendor moved work overseas.

Data location and return format

Specify where PHI may be stored and, at termination, in what format it will be returned — machine-readable export, not a PDF dump of 40,000 pages. Then require written certification of destruction with a date and a signature.

Who Signs, When, and What Evidence You Keep

The BAA must be executed before any PHI moves. Not at go-live, not after the pilot. If a vendor is already handling PHI without a signed agreement, that gap is a disclosure without authorization for every day it persists.

Assign it: the Privacy Officer approves the vendor as a business associate and confirms the clause set; the practice administrator or an officer with contracting authority signs; the office manager files. Two signatures, one file location.

Your evidence file for each vendor should contain the executed agreement with both signature dates, the vendor's countersigned copy, the date PHI access was first granted, the date of last review, and any security documentation you collected — SOC 2 report, security questionnaire, penetration test summary. Store it where a covering administrator can find it without you.

The Termination Step Everyone Skips

When you fire a vendor, three things have to happen and usually only one does. Access gets revoked. The other two — written demand for return or destruction of PHI, and receipt of a signed destruction certificate — get forgotten in the churn.

Build a two-line offboarding checklist and attach it to your termination letter template. Thirty days after termination, if no certificate has arrived, escalate in writing. That escalation letter, filed, is your evidence of reasonable diligence even if the vendor never responds.

Running the Business Associate Agreement Checklist Annually

Set one date a year. Pull the vendor inventory, reconcile it against the AP ledger and the user administration screen again, and confirm every active vendor has a current signed agreement with the nine required clauses. Note any vendor whose scope of service changed — new modules, new data types, new integrations — because scope creep is the most common reason a two-year-old BAA no longer describes reality.

Feed the results into your Security Rule risk analysis. Vendor risk is not a separate exercise; NIST's SP 800-66 Revision 2 treats third-party relationships as a standing input to the risk assessment process, and OCR routinely asks to see how the two connect. If your risk analysis and policy set need the same disciplined treatment, automated HIPAA risk analysis and policy generation will get you to a documented baseline faster than a template pack.

Two regulatory notes for your 2026 planning. HHS proposed significant Security Rule updates in January 2025 that would tighten technical safeguard expectations flowing through business associates; that rule was not final as of this writing, so plan for it but don't contract against text that doesn't exist yet. Separately, the 2024 reproductive health privacy provisions that added attestation requirements were substantially vacated by federal court action in 2025 — confirm current status on the HHS HIPAA professionals page before you amend agreements on that basis.

Start With the Gap, Not the Template

Run the inventory this week. For every vendor missing an agreement or holding one that fails the nine-clause test, put your own paper in front of them — a signature-ready BAA you generate in six steps beats redlining theirs, and it costs less than one hour of outside counsel. Work the business associate agreement checklist once, file the evidence, and calendar the review.