Your billing company just told you its clearinghouse subcontractor had a ransomware incident. Before you can answer a single question about whose patients were affected, you need two documents: your signed agreement with the billing company, and proof that the billing company had its own agreement with the clearinghouse. If either one is missing or eight years out of date, the exposure stops being the vendor's problem and becomes yours. That is why business associate agreement requirements exist, and why they are one of the most commonly cited failures in HIPAA enforcement.

This is a working checklist for the person who signs vendor contracts and answers the regulator's questions. It covers what the agreement must say, who needs one, which clocks it starts, and what documented evidence looks like when someone asks.

What Must a Business Associate Agreement Include?

A compliant BAA must, at minimum, do all of the following. This list tracks 45 CFR 164.504(e) and 164.314(a):

  • Describe the permitted and required uses of protected health information by the business associate — specifically, not "as needed to perform services."
  • Prohibit further use or disclosure except as permitted by the contract or required by law.
  • Require appropriate safeguards, including compliance with the Security Rule's administrative, physical, and technical safeguard requirements for electronic PHI.
  • Require reporting of any use or disclosure not permitted by the contract, including breaches of unsecured PHI and security incidents.
  • Flow obligations down to subcontractors that create, receive, maintain, or transmit PHI on the business associate's behalf.
  • Require the business associate to make PHI available so your practice can satisfy patient right-of-access, amendment, and accounting-of-disclosures obligations.
  • Require the business associate to make internal practices, books, and records available to HHS for compliance determinations.
  • Address return or destruction of PHI at termination, or, if return is infeasible, extend the protections for as long as the vendor retains it.
  • Authorize termination by your practice if the vendor materially breaches the agreement.

HHS publishes sample business associate agreement provisions covering these elements. Read it as a floor, not a template — the sample intentionally leaves blanks where you must make business decisions.

Business Associate Agreement Requirements Start With Knowing Who Is a Business Associate

The clause list is the easy part. The harder question is which of your 40-odd vendors actually triggers the obligation.

A business associate is any person or entity, outside your workforce, that creates, receives, maintains, or transmits PHI to perform a function or activity on your behalf. Function matters more than industry. Your shredding company is one. Your answering service is one. Your cloud file-storage provider is one even if everything you upload is encrypted and the provider holds no key — HHS made that explicit in its cloud computing guidance.

Vendors that usually do need a BAA

Billing and revenue cycle firms. Transcription services. IT managed service providers with server or workstation access. Cloud hosting, backup, and file-sharing platforms. Email and secure-messaging providers. Document shredding and record storage. Answering services and after-hours triage lines. Consultants who review charts. Collection agencies. E-prescribing and clearinghouse intermediaries. Practice management and scheduling platforms. Marketing agencies with access to patient lists.

Vendors that usually do not

The postal service and private couriers — the conduit exception covers entities that only transport information and have transient, incidental access. Your janitorial crew, if incidental exposure is genuinely incidental and they have no access to records systems. A referring physician receiving PHI for treatment purposes; that is a permitted treatment disclosure, not a business associate relationship. Your bank processing ordinary payment transactions. Health plans you bill — they are covered entities in their own right.

The conduit exception is narrower than most administrators assume. A vendor that stores data, even briefly, even without opening it, is not a conduit. If a vendor's servers hold your PHI overnight, get a BAA.

The 1099 gray zone

Independent contractors are the most-missed category. A per-diem coder working from home on a laptop you don't own, a locum provider using their own dictation app, a fractional practice manager on contract — decide deliberately whether each person is workforce (covered by your policies, training, and sanctions) or a business associate (covered by an agreement). Document the decision either way. Do not leave the person in between, which is where most practices actually leave them.

The Subcontractor Chain Is Your Problem Too

Since the 2013 Omnibus Rule, business associates must obtain agreements with their own subcontractors, and those subcontractors are directly liable under HIPAA. Your practice is not required to sign a contract with your billing company's clearinghouse. You are required to have flow-down language in your BAA, and you are well advised to ask for evidence.

Practical move: add a clause requiring the vendor to maintain a current list of subcontractors that touch your PHI and to furnish it within ten business days on request. Then actually request it once a year for your top-tier vendors. Two things happen — you learn where your data physically sits, and you find out fast which vendors cannot answer the question.

HHS's business associate guidance is direct on this: the chain of obligations extends downstream indefinitely, and a gap anywhere is a compliance failure at that link.

The Clocks Your BAA Should Set — Not Leave to the Regulation

The Breach Notification Rule gives your practice up to 60 calendar days from discovery to notify affected individuals. If your vendor discovers a breach on day one and tells you on day 55, you have five days to do work that takes three weeks. Write shorter internal deadlines into the contract.

Reasonable numbers to negotiate:

  • Security incident or suspected breach notice to you: 5 calendar days from vendor discovery, with an initial notice even if the scope is unknown.
  • Complete forensic detail — individuals affected, data elements, mitigation steps: 15 calendar days.
  • Response to a patient right-of-access request routed through the vendor: 10 business days, so you can meet your own 30-day deadline under 164.524.
  • Accounting-of-disclosures data: 20 business days.
  • Return or certified destruction of PHI at termination: 30 days after the last service date, with written certification.

Also decide, in writing, who pays for notification. If the vendor causes the breach, your practice still sends the letters, staffs the phone line, and files with OCR. Cost-allocation and indemnification language is not part of the minimum business associate agreement requirements, but it is the clause you will care most about at 9 p.m. on a Friday.

Where Practices Actually Get Cited

Enforcement history is consistent on this point. In 2016, Raleigh Orthopaedic Clinic paid $750,000 to settle allegations that it handed X-ray films to a vendor for silver recovery without a business associate agreement in place. The same year, Care New England Health System paid $400,000 in a case that turned in part on a business associate agreement that had not been updated to reflect post-Omnibus requirements.

The pattern in both: the agreement was either absent or stale. Not defective in some subtle drafting sense — simply not there, or written years before the rules changed. You can review resolution agreements and current breach reports on the OCR breach portal, and a meaningful share of large reported breaches list a business associate as the reporting or involved entity.

Note also that HHS issued a proposed Security Rule update in January 2025 that would, among other things, require business associates to provide written verification of their technical safeguards on a defined cycle. That rule is not final as of December 2025. Do not rewrite your contracts around it yet, but if you are drafting new agreements now, building in an annual attestation obligation costs you nothing and positions you ahead of it.

The Evidence an Investigator Will Ask You to Produce

When OCR opens an investigation — usually triggered by a complaint or a breach report — the data request is predictable. Assemble this now, not then.

  1. A vendor inventory listing every third party with PHI access: vendor name, service, PHI categories touched, systems accessed, BAA status, execution date, and contract owner on your staff.
  2. Executed agreements with signatures and dates for every vendor on that list. Countersigned. Not a draft, not an unsigned PDF in a shared drive.
  3. Evidence of post-2013 currency — either an execution date after September 23, 2013, or an amendment that brings pre-Omnibus language current.
  4. Your due diligence file: security questionnaires, SOC 2 reports, penetration test summaries, or whatever you collected before signing.
  5. Termination records: for former vendors, the certification of PHI return or destruction.
  6. A review log showing who checked the inventory, when, and what changed.

The review log is the item practices skip and the one that most efficiently demonstrates a functioning program. A single spreadsheet tab with dated entries beats a beautifully drafted policy nobody follows.

A 30-Day Plan to Close the Gaps

Week 1 — Build the list from money, not memory

Pull twelve months of accounts payable and every recurring credit card charge. Every payee gets a yes/no/maybe on PHI access. Do not rely on the privacy officer's recollection; software gets bought by clinicians and office managers without anyone telling compliance.

Week 2 — Triage

Sort into three buckets: signed and current; signed but pre-2013 or missing required clauses; nothing on file. The third bucket is your urgent list. Rank it by volume of PHI and depth of system access — the IT vendor with domain admin credentials outranks the shredding company.

Week 3 — Paper the gaps

Send agreements to every vendor in buckets two and three. Use your own document rather than accepting the vendor's, when you have leverage; vendor-drafted BAAs routinely cap liability, stretch breach notice to 30 or 60 days, and grant de-identification and data-aggregation rights you did not intend to give. If you need a clean starting document, you can generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export — one-time purchase, so you are not adding another subscription to a practice that already has too many.

Week 4 — Assign owners and set the calendar

Every vendor gets a named person on your staff responsible for the relationship. Set an annual review date. Add a rule to your purchasing process: no new vendor with PHI access gets paid before a countersigned BAA is on file. Enforce it once and it becomes culture.

Termination Is Where the Files Go Missing

When you switch billing companies, the old vendor keeps your data. Sometimes for years, sometimes forever, usually because nobody asked. Your BAA obligates them to return or destroy it, or to extend protections if destruction is infeasible.

Add offboarding to your termination checklist: written demand for return or destruction, a certification signed by the vendor, revocation of every credential and VPN account, removal from your inventory's active list with the date recorded. Keep the certification for six years alongside the agreement itself, matching HIPAA's documentation retention period.

Your Next Step

Take the AP report, build the list, and count the vendors with no signed agreement. That number is your actual risk position, and most practices find it higher than expected. Close the highest-access gaps first — you can produce a compliant agreement in a single sitting, and if your broader policy set and risk analysis documentation are also thin, automated HIPAA risk analysis and policy generation covers the rest of the file an investigator asks for.

Meeting business associate agreement requirements is not a project with an end date. It is a list you maintain, an owner per vendor, and a calendar reminder that fires every year whether or not anything has gone wrong.