Do I Need a BAA? A Vendor-by-Vendor Decision Guide
Your office manager forwards you an email at 4:40 on a Friday: the front desk started using a new online appointment-reminder tool three weeks ago, it pulls names and visit times out of your scheduling system, and nobody signed anything. So you ask the question every privacy officer asks a dozen times a year — do I need a BAA for this?
This is a decision guide for that moment. It covers the two-question test that resolves most vendor calls, the categories that genuinely fall outside the requirement, what has to be in the agreement, when it has to be signed relative to the first byte of PHI moving, and what your documentation should look like when a regulator or a cyber insurer asks to see it. Written for the person who signs the contracts, not the patient.
Do I Need a BAA? The Short Answer
You need a Business Associate Agreement when a person or company outside your workforce creates, receives, maintains, or transmits protected health information on your behalf, or provides services to you that involve disclosure of PHI. Two conditions, both required:
- They are not part of your workforce. Employees, volunteers, and trainees under your direct control are covered by your policies and training, not by a contract.
- They touch PHI to perform a function or service for you. Claims processing, data storage, transcription, billing, IT administration, analytics, legal, accounting, consulting, practice management, patient communications, record disposal.
If both are true, get the agreement signed before any PHI moves. If a vendor merely could stumble across PHI while doing unrelated work — a plumber in the exam room, the cleaning crew after hours — that is incidental exposure, not a business associate relationship. Train them on confidentiality, lock the charts, skip the BAA.
The Vendors Where the Answer Is Almost Always Yes
Walk your accounts-payable list and your single-sign-on portal. These categories come up in nearly every practice:
- Cloud hosting, storage, and backup. HHS settled this question years ago in its cloud computing guidance: a cloud service provider that stores encrypted PHI is a business associate even if it holds no decryption key. "We can't read it" is not an exit.
- Billing companies and revenue cycle vendors. Claims, statements, collections, denials work — all PHI, all on your behalf.
- Clearinghouses. Standardizing your 837s is the textbook example.
- Managed IT and MSPs. If they hold domain admin, remote into workstations, or manage your firewall, they have access to PHI whether or not they read it.
- Transcription and AI scribe or documentation tools. Audio of a clinical encounter is PHI. So is the draft note.
- Answering services and after-hours triage vendors.
- Secure messaging, e-fax, and patient communication platforms that store message content on their servers.
- Shredding and record destruction vendors, on-site or off-site.
- Off-site record storage.
- Attorneys, accountants, and consultants who receive PHI to do their work — including the coding consultant reviewing charts and the malpractice defense firm.
- Data analytics, population health, and reporting vendors.
- Translation and interpreter services that are not your employees.
- Answering-machine, appointment-reminder, and marketing platforms that receive names paired with appointment or service details.
That last one is the Friday-afternoon email. A reminder tool receiving patient names, phone numbers, and appointment times is receiving PHI on your behalf. The answer to "do I need a BAA" there is yes, and it needed to be signed three weeks ago.
The Categories Where the Answer Is No
Conduits that only transport
The conduit exception is narrow and people abuse it. The U.S. Postal Service, courier services, and internet service providers that transmit PHI without persistent access are conduits. A vendor that stores your data — even briefly, even as a byproduct — is not a conduit. Duration and persistence of access are the test, not the vendor's marketing copy.
Treatment disclosures to other providers
When you send records to a referring specialist, a hospital, or a pharmacy for treatment purposes, that provider is acting on their own behalf as a covered entity. No BAA. Same for sending imaging to a radiologist who bills independently.
Financial institutions processing payment
A bank clearing a credit card transaction under the payment exception is not a business associate. But a payment platform that also stores your patient ledger, sends statements, or manages a portal has stepped past processing into services performed on your behalf. Read what the product actually does, not what the merchant agreement says.
Your own workforce and staffing arrangements
A locum tenens physician or temp medical assistant who works under your direct control is workforce. Document supervision and training instead. A staffing agency that also handles credentialing files containing PHI is a closer call — evaluate the data flow, not the label.
Required disclosures
Public health reporting, disclosures to OCR during an investigation, court orders, and law enforcement requests under 45 CFR 164.512 are not business associate relationships. Log them; don't paper them.
Downstream: Your Vendor's Vendors
Since the Omnibus Rule took effect in 2013, subcontractors that create, receive, maintain, or transmit PHI are themselves business associates and are directly liable under the Security Rule. Your business associate must have signed agreements with its own subcontractors — and your BAA should say so explicitly.
Practically, this means your billing company's cloud host, your MSP's remote-monitoring platform, and your scribe vendor's speech-recognition engine all sit in the chain. You don't sign with them. You do ask your direct vendor to attest, in writing, that downstream agreements exist. Put that attestation in your vendor file with a date on it.
What Has to Be in the Agreement
45 CFR 164.504(e) sets the required content. HHS publishes sample business associate agreement provisions you can compare your template against. At minimum the agreement must:
- Describe permitted and required uses and disclosures of PHI, and prohibit anything else.
- Require appropriate safeguards, including compliance with the Security Rule for ePHI.
- Require the business associate to report security incidents and breaches to you — and this is where you negotiate. "Without unreasonable delay" leaves you holding a 60-day clock you can't meet. Ask for a defined number of calendar days.
- Require flow-down agreements with subcontractors.
- Require the vendor to make PHI available so you can satisfy patient access, amendment, and accounting-of-disclosures requests.
- Make internal practices and records available to HHS.
- Require return or destruction of PHI at termination, or extension of protections if return is infeasible.
- Authorize you to terminate for material breach.
Two additions worth negotiating in 2025: a defined breach-notification window in calendar days, and an obligation to cooperate with your investigation, including log production. If your practice handles reproductive health information, also confirm your template accounts for the attestation requirements HHS added in 2024 for certain disclosures.
If you are staring at a vendor who has no template of their own — common with small IT shops, local shredding companies, and independent consultants — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, which matters when you need one agreement this afternoon rather than a platform commitment.
The Timing Rule: Signed Before the First Byte
The agreement must be in place before PHI is disclosed. Not at go-live. Not during implementation. Before the sandbox gets a test file with real patient names in it.
OCR has enforced exactly this. In 2016, Raleigh Orthopaedic Clinic paid $750,000 after handing X-ray films to a vendor for silver recovery without a business associate agreement in place. In 2017, Center for Children's Digestive Health settled for $31,000 over records stored with a vendor for years without a signed agreement. You can read the resolution agreements on the HHS enforcement page. The pattern is consistent: the missing paper is what gets cited, and the underlying incident is what draws the auditor's attention in the first place.
A worked example
Your practice decides on November 10 to adopt a new imaging-share tool. Here is a defensible sequence:
- Nov 10 — Intake. Office manager submits the vendor to the privacy officer with a one-page data-flow description: what PHI, which direction, stored where.
- Nov 12 — Determination. Privacy officer records the answer to "do I need a BAA" and the reasoning. Yes: vendor stores images and patient identifiers on its infrastructure.
- Nov 14 — Diligence. Request the vendor's security documentation, subcontractor list, breach history, and encryption approach. File the responses.
- Nov 18 — Agreement executed. Both signatures, dated, countersigned copy stored in the vendor file.
- Nov 20 — Risk analysis updated. New system added to your asset inventory and your Security Rule risk analysis.
- Nov 24 — Go-live. First real PHI transmitted. Access provisioned to named users only.
- Nov 24 + 12 months — Review date calendared.
Fourteen days from intake to signature. That is a realistic pace for a small practice, and it produces an audit trail without a compliance department.
What the Documented Evidence Looks Like
A regulator's request is rarely "prove you asked whether you need a BAA." It is "produce your business associate agreements." Your file should contain:
- A vendor inventory with columns for vendor name, service, PHI touched (yes/no/incidental), BAA required (yes/no), determination date, determination reasoning, signature date, agreement location, subcontractor attestation on file, and next review date.
- Fully executed agreements — both signatures, both dates. A vendor's unsigned template in your Dropbox is not evidence of anything.
- Written no-BAA determinations for the vendors you excluded. This is the part practices skip, and it is the cheapest insurance you can buy. Three sentences explaining why the shredding company needs one and the landscaping company does not.
- Termination records showing PHI was returned or destroyed when a contract ended, with a certificate of destruction where applicable.
- Review evidence — dated notes from your annual pass through the inventory.
Assign the owner explicitly. In most practices the privacy officer makes the determination, the practice administrator executes the agreement, and whoever owns procurement is instructed never to enter a PHI-touching contract without routing it. Write those three roles into your policy so the answer isn't "we all sort of handle it."
Three Failure Modes That Show Up in Breach Reports
Scan the OCR breach portal for incidents attributed to business associates and the same shapes repeat.
Shadow IT. A staff member signs up for a free tool with a work email. No procurement record, no agreement, PHI in a consumer account. Fix: quarterly review of expense reports and browser-based app inventory.
The stale agreement. Signed in 2011, never updated for Omnibus, still on file, still cited as coverage. Fix: check every agreement for subcontractor flow-down and direct Security Rule obligations. If they're missing, re-paper.
Scope creep. The vendor you hired for statements now runs your patient portal and text campaigns. Same contract, triple the data. Fix: your annual review asks what changed, not just whether the signature is on file.
Answer the Question, Then Write It Down
Every time someone asks you "do I need a BAA for this," you are making a documented compliance decision. Treat it that way: capture the data flow, record the reasoning, get the signature before PHI moves, and put a review date on the calendar.
If your gap is the paper itself, build the agreement and export it for signature — it takes less time than the email thread you'd otherwise start with the vendor's legal team. If the gap is broader, and your risk analysis and policy set are as thin as your vendor file, the full HIPAA compliance document set is the larger project to schedule for Q1. Start with the vendor list. It is the shortest path to knowing what you actually don't have.