Business Associate Agreement: What Your Practice Owes
Pull your accounts payable ledger and your vendor list side by side. Now count how many of those vendors touch protected health information, and how many of those have a countersigned business associate agreement you could produce from a folder in under ten minutes — with a date, both signatures, and the version that's actually in force. In most practices, the second number is smaller than the first by a wide margin. That gap is the single most common finding when the Office for Civil Rights opens an investigation after a breach, and it's the one that's entirely fixable before anything goes wrong.
This article is for whoever owns vendor contracts at your organization: the practice administrator, the privacy officer, the compliance lead. It covers who needs an agreement, what has to be in it, when it has to be signed, and what the documented evidence looks like when someone asks.
The Vendor List Test That Takes an Afternoon
Print your vendor list. Next to each line, write one of three letters: Y (this vendor creates, receives, maintains, or transmits PHI on our behalf), N (never touches PHI), or ? (I'm not sure).
The ? column is where the exposure lives. Your shredding company. The IT contractor with remote access to workstations. The answering service. The billing consultant who requested a read-only EHR login "just for the quarter." The transcription platform your two busiest providers started using without telling you. The cloud backup vendor.
Each ? gets one question: does this vendor need PHI to do the job you hired them for, or could they encounter it incidentally? If they need it, they are a business associate and a signed agreement is required before you disclose anything. If they could encounter it incidentally — the HVAC contractor walking past an open chart — you handle that with workforce policy and physical safeguards, not a BAA.
What a Business Associate Agreement Must Do
A business associate agreement is a written contract, required by 45 CFR 164.502(e) and 164.504(e), between a covered entity and a vendor that handles protected health information on the covered entity's behalf. It obligates the vendor to safeguard PHI, use and disclose it only as the contract and the Privacy Rule permit, report security incidents and breaches back to the covered entity, extend the same terms to its own subcontractors, make records available to HHS, and return or destroy PHI when the relationship ends. It must be executed before PHI changes hands. Without it, the disclosure itself is an impermissible disclosure — regardless of whether any data was ever exposed.
That last sentence is the part operators underestimate. OCR has resolved cases where the vendor did nothing wrong and no patient was harmed; the violation was handing over records with no agreement in place. One well-known resolution involved an orthopedic practice that released years of X-ray films to a vendor for silver recovery without a signed contract. The films were the point. The missing paper was the case.
Who Counts as a Business Associate — and Who Doesn't
HHS maintains guidance on business associate status that's worth reading once a year, because the edges move as vendor models change. The core categories:
- Claims processing, billing, and revenue cycle vendors
- Practice management and EHR platforms, and any hosting provider behind them
- IT support with access to systems containing PHI, including remote-access MSPs
- Document storage, shredding, and records retrieval services
- Transcription, coding, and utilization review
- Answering services, patient outreach, and appointment reminder platforms
- Attorneys, accountants, and consultants who review PHI to do their work
- Data analytics, population health, and quality reporting vendors
Not business associates: other treating providers receiving PHI for treatment purposes, health plans paying claims, your workforce members, and organizations that receive PHI because a patient authorized it.
The conduit exception is narrower than your vendor thinks
Vendors love to invoke the conduit exception. It applies to entities that merely transport PHI without accessing it beyond what's random or infrequent — the postal service, an ISP moving packets. It does not cover a cloud provider storing your data, even encrypted, and even if the provider holds no key. HHS has been explicit on this point. If a vendor persistently maintains PHI, they're a business associate, full stop.
Subcontractors need their own agreements
Your billing company's offshore coding contractor is a subcontractor. Your EHR vendor's data center is a subcontractor. You don't sign agreements with them — your business associate does, and their agreement has to be at least as protective as yours. Your obligation is to require it in writing and, ideally, to ask for confirmation during vendor review. When a subcontractor causes the breach, the notification obligation still flows up to you.
The Provisions Your Business Associate Agreement Has to Contain
HHS publishes sample business associate agreement provisions. They are sample language, not a form contract — you still have to fill in your breach reporting window, your termination terms, and your permitted uses. Every agreement needs, at minimum:
- Permitted uses and disclosures. Specific. "As necessary to perform the services" with the services actually described.
- A prohibition on any use or disclosure the Privacy Rule wouldn't allow you to make yourself, with the narrow exceptions for the BA's own management and legal duties.
- Safeguards. Administrative, physical, and technical, including compliance with the Security Rule as applied to business associates under 164.314(a).
- Reporting. Breaches of unsecured PHI and security incidents, with a stated timeframe.
- Subcontractor flow-down. Written agreements imposing the same restrictions.
- Individual rights support. Access, amendment, and accounting of disclosures — with a turnaround the BA commits to, because your 30-day access clock doesn't pause while you wait on a vendor.
- Availability to HHS. Books, records, and practices available to the Secretary for compliance review.
- Return or destruction at termination, with a documented path when return isn't feasible.
- Termination for material breach.
If you're papering vendors one at a time from a stale Word template someone modified in 2019, you're accumulating version drift you'll have to untangle later. Building each agreement through a structured process — where the permitted uses, notice window, and termination terms are choices you make rather than boilerplate you inherit — is faster and produces a cleaner file. A tool that will generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export handles this in about the time it takes to read the vendor's proposal, and it's a one-time purchase rather than another subscription line item.
Timing: The Clocks Written Into Every Agreement
Before disclosure, not after
The agreement must be executed before PHI moves. In practice this means your procurement workflow has a hard gate: no credentials issued, no interface built, no records released until the countersigned agreement is in the file. Front-desk staff and clinical leads need to know that gate exists, because the pressure to skip it always comes from operations, not compliance.
Sixty days from discovery — and why you should shorten it
Under 45 CFR 164.410, a business associate must notify you of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days from discovery. You then have your own 60-day clock, running from your discovery, to notify affected individuals under the Breach Notification Rule. If your vendor uses the full 60 days, you have essentially none left for investigation, risk assessment, notice drafting, and mailing.
Negotiate the window down. Ten business days for confirmed breaches and immediate notice for suspected incidents affecting your data is a reasonable ask, and most serious vendors will agree. Put the notification contact — a role, not a person's name — in the agreement itself.
Remember the downstream deadlines: breaches affecting 500 or more individuals require notice to HHS and prominent media in the affected jurisdiction within 60 days; smaller breaches are logged and submitted within 60 days after the end of the calendar year. You can see how these play out in public filings on the OCR breach portal, where a striking share of large incidents are attributed to business associates.
What the Documented Evidence Looks Like
An investigator's request is rarely subtle: "Provide all business associate agreements in effect during the period, and documentation of your process for determining business associate status." What should exist:
- A vendor inventory listing every vendor, BA status determination, the reason for that determination, and the date it was made
- The fully executed agreement for each BA — both signatures, dates, and any amendments — retained six years from the later of creation or last effective date
- Dated evidence of pre-engagement diligence: security questionnaires, SOC 2 reports, attestations
- Termination records showing PHI was returned or destroyed, with certificates where applicable
- Review dates showing someone looked at the inventory in the last twelve months
Your risk analysis under 164.308(a)(1)(ii)(A) should reference the vendor inventory directly. NIST's SP 800-66 Rev. 2 maps Security Rule requirements to practical implementation steps and treats third-party relationships as a first-class risk input. If your risk analysis and your vendor list have never been in the same document, that's your next project — and the automated risk analysis and policy set approach exists precisely because reconciling those two by hand eats weeks.
Five Failure Modes I See in Every Review
The one-sided signature. You signed; the vendor never countersigned. Legally ambiguous, practically useless.
The agreement that predates the service. Signed in 2017 for hosting; the vendor now runs analytics on your data. Scope changed, contract didn't.
The vendor's paper, unread. Their template caps liability, disclaims Security Rule obligations, and gives them 60 days to tell you about a breach. You accepted it because it arrived attached to the order form.
The shadow vendor. A department signed up for a scheduling or messaging tool with a credit card. No agreement, no inventory entry, no one in compliance knows.
The orphaned termination. Contract ended, PHI never returned or destroyed, no documentation either way. You're still accountable for data sitting on a vendor's server.
A Workflow You Can Assign This Week
Practice administrator: owns the vendor inventory and the procurement gate. No PHI access without an executed agreement in the file. Reviews the inventory quarterly against AP.
Privacy officer: makes the BA status determination, documents the reasoning, negotiates notification windows, and owns the six-year retention file.
IT lead or security officer: reviews vendor security documentation before signature and confirms access is revoked at termination.
Practice leadership: approves exceptions in writing. There should be almost none.
Set an annual review date. Walk the list, flag scope changes, re-paper anything where the services no longer match the agreement, and record the date you did it. That record is often the most persuasive document in your file — it shows a program, not a stack of PDFs.
What's Sitting on the Horizon
HHS published a proposed rule in January 2025 to strengthen the Security Rule, and several proposed provisions would raise the bar on vendor oversight — including written verification of a business associate's technical safeguards and faster notice when contingency plans are activated. It remains a proposal as of today, not enforceable law. But if you're negotiating multi-year agreements now, build in flexibility to amend as the requirements finalize.
Start With the Gap You Already Know About
You almost certainly have at least one vendor touching PHI with no agreement on file, or an agreement so old it no longer describes what the vendor does. Fix that one first, then work the list. If drafting is the bottleneck, you can build a compliant business associate agreement in six steps and export it for signature the same afternoon — one purchase, no recurring cost, and a document your file will actually survive an inquiry with.