Downstream Business Associate BAAs: Who Signs What
Your billing company signed a BAA with you in 2019. That billing company stores claim files in a third-party cloud environment, uses an offshore coding contractor, and routes patient statements through a print-and-mail house. None of those three vendors ever signed anything with your practice — and they don't have to. But each one is a downstream business associate, and if the chain of agreements doesn't reach them, the failure lands on your billing company first and on your practice second. This article covers who contracts with whom, what the paperwork has to say, how breach notice moves back up the chain, and what evidence you keep in the file.
What Counts as a Downstream Business Associate
A downstream business associate — the regulation calls it a subcontractor — is any entity that creates, receives, maintains, or transmits protected health information on behalf of a business associate, rather than on behalf of you directly. The definition sits in 45 CFR 160.103, and it has applied since the 2013 Omnibus Rule made subcontractors directly liable under HIPAA.
Three tests, all of which have to be true:
- The entity handles PHI — creates it, receives it, stores it, or moves it.
- It does so on behalf of a business associate, under that business associate's direction.
- It is not a member of the business associate's workforce.
Common examples inside a typical practice's vendor chain: the cloud infrastructure provider behind your patient-engagement platform, the data-destruction company your record storage vendor hires, the interpreter service your telehealth vendor subcontracts, the offshore transcription pool behind a dictation service, and the backup provider your IT managed service provider uses.
Conduits are the narrow exception. The U.S. Postal Service, a package carrier, and an ISP that only transmits data without accessing it in more than a random or infrequent way are not business associates. A cloud provider that stores PHI is — even if the data is encrypted and the provider holds no key. HHS said so explicitly in its 2016 cloud computing guidance, and it has not walked that back.
Why the Chain Doesn't Stop at Your Direct Vendor
Two provisions do the work. Under 45 CFR 164.502(e)(1)(ii), a business associate may disclose PHI to a subcontractor only if it obtains satisfactory assurances — a written contract — that the subcontractor will safeguard the information. Under 45 CFR 164.308(b)(2), the Security Rule requires the same flow-down for electronic PHI, and 164.314(a)(2)(iii) says the subcontractor's contract must contain the same terms the business associate agreed to with you.
The practical result: obligations flow down, but the contracting does not skip levels. You do not sign a BAA with your vendor's vendor. Your billing company signs it. Its cloud host signs one with the billing company. If the cloud host uses a fourth party to handle PHI, that agreement exists at that level. The chain can run four or five deep in a modern revenue-cycle stack.
What you owe is different from what you sign. You owe reasonable diligence — knowing that the flow-down exists, requiring it contractually, and acting when you learn it doesn't. A practice that requires flow-down in writing and verifies it periodically is in a materially different position than one that never asked.
Direct liability applies at every level
Since 2013, a downstream business associate is directly liable to OCR for the Security Rule in full, for breach notification to the entity above it, and for impermissible uses and disclosures. OCR has settled directly with business associates — including a management services company that provided IT support to affiliated hospitals — without the covered entity being the named respondent. Your vendor's subcontractor is not shielded by distance from you.
There is a separate exposure worth knowing: agency. If a business associate acts as your agent under federal common law — meaning you retain the right to control how it performs the work, not just what it delivers — its violations can be attributed to your practice. That analysis turns on the actual terms and the real relationship, not on a label in a contract.
Who Signs What: A Four-Level Worked Example
A 14-provider orthopedic group runs this stack:
- Practice → RCM company. Direct BAA. You negotiate, you sign, you keep the executed copy.
- RCM company → clearinghouse. Subcontractor BAA. Not your signature. Your contract with the RCM company should require it and require notice if it changes.
- Clearinghouse → hosting provider. Another downstream business associate agreement, executed two levels below you.
- Hosting provider → managed backup vendor. Same again.
Four agreements. One of them is yours. The other three are your problem only in the sense that a gap anywhere in the chain means PHI is being disclosed without required assurances — and the entity that discloses it is in violation.
Now flip it. If your practice is itself a business associate — say your group provides billing services to a hospital-owned clinic, or your medical director consults for an ACO — then you are the party that must execute subcontractor BAAs with your own vendors, and those terms must be at least as protective as the ones you accepted upstream. Plenty of practices sit on both sides and only paper one.
The Breach Clock Runs Backward Through the Chain
Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. A downstream business associate owes that same notice to the business associate above it. The covered entity's own 60-day clock to notify individuals under 164.404 starts at its discovery.
Here's the failure mode. A downstream vendor discovers an incident on March 1 and uses its full 60 days, notifying your billing company on April 29. Your billing company takes its own 60 days and notifies you on June 28. You now have 60 days to notify patients — nearly six months after the original discovery, and well past the point where affected patients could have acted.
Contract the clock down. Standard language in a well-built BAA: notice to the tier above within a defined short window — many practices use 5 to 10 business days from discovery of a suspected incident, with a hard requirement that the terms be mirrored downstream. Pair it with a duty to provide the individual-notification data set (names, addresses, PHI involved) within a stated number of days so your notice letters aren't held up waiting on a spreadsheet.
If you want a sense of how these cascade in practice, browse the OCR breach reporting portal and filter to incidents involving business associates. The 2024 Change Healthcare incident — roughly 190 million individuals affected — is the extreme version of a single downstream node touching thousands of covered entities at once.
Contract Language That Actually Controls Subcontractors
A BAA that only recites the regulatory minimum leaves you blind. Five clauses that earn their space:
- Flow-down with equivalence. The business associate must bind every downstream business associate to terms no less restrictive than these, in writing, before any PHI is disclosed.
- Subcontractor disclosure and notice of change. A current list of subcontractors that handle PHI, provided on request, plus written notice before a new one is added or PHI moves to a new jurisdiction.
- Offshore restriction or consent. If PHI will be accessed outside the United States, you want to know and to have the option to object. HIPAA does not prohibit it; your risk analysis and your state law may complicate it.
- Compressed breach notice. Days, not the statutory ceiling, and an obligation to cooperate with your investigation and notification.
- Audit or attestation rights. The right to request evidence — a current risk analysis date, penetration test summary, SOC 2 report, or written attestation — annually.
If your existing agreements predate 2013 or were assembled from a vendor's one-page template, they almost certainly lack the subcontractor terms. Rather than redlining a decade-old file, generate a clean baseline: this six-step Business Associate Agreement builder produces a signature-ready BAA with flow-down and breach-notice provisions, exports to PDF and DOCX, and is a one-time purchase rather than a subscription. Use it as the document you hand vendors first, so the negotiation starts from your terms.
What the Evidence File Looks Like
When OCR opens an investigation, it asks for documents, not descriptions. Build the file now, per vendor:
- Executed BAA, signed and dated by both parties, with the effective date visible.
- The contract's flow-down clause, flagged so you can find it in 30 seconds.
- Most recent subcontractor list or vendor attestation, with the date you requested it.
- Security documentation received — SOC 2 Type II, HITRUST report, or a written attestation naming the framework used. Note that no product or report is a government HIPAA certification; HHS does not certify or endorse compliance vendors.
- Your own review notes: who reviewed, when, what was flagged, what was resolved.
- Termination and data-return records for vendors you dropped, including confirmation that downstream copies were destroyed.
Assign a named owner. In most practices the privacy officer owns the BAA inventory and the practice administrator owns the annual refresh. Put the review date on the same calendar as your Security Rule risk analysis — NIST SP 800-66 Rev. 2 treats third-party dependencies as a standing input to that analysis, and reviewing both at once cuts the work roughly in half.
Where Practices Get This Wrong
Assuming the vendor's BAA covers its own vendors
A signed BAA with your vendor says nothing about whether the vendor executed agreements below it. Ask. Put the answer in writing. A one-paragraph attestation naming the categories of downstream business associates and confirming written agreements are in place is enough for most vendors and takes them ten minutes.
Treating the marketing agency, the answering service, and the shredding company as too small to matter
Size is irrelevant. A two-person answering service that takes symptom descriptions over the phone handles PHI. If it uses a cloud telephony platform that retains recordings, that platform is a downstream business associate and needs an agreement with the answering service.
Letting the inventory go stale
Vendor stacks change quietly. Your EHR adds an AI scribe module hosted by a third party; your patient-communication tool switches SMS carriers. Neither triggers a phone call to you. An annual vendor-list refresh, with a specific question about new subcontractors, catches most of it.
What's Coming: The Proposed Security Rule Update
In January 2025, HHS published a proposed rule that would substantially rewrite the HIPAA Security Rule. Among the proposals: business associates would have to verify their technical safeguards annually through a written analysis and certification, and provide that verification to the entity above them — including from each downstream business associate. The comment period closed in March 2025, and as of December 2025 the rule is not final.
Don't wait for it. Practices that already collect annual attestations will absorb a final rule as a formatting change. Practices that have never asked will be starting from zero on a deadline. Watch the HHS Security Rule page for the final text.
A 30-Day Plan
Week 1. Pull every vendor with PHI access into one list — check accounts payable, not memory. Mark which have executed BAAs and which don't.
Week 2. Read the flow-down clause in each existing BAA. Flag every agreement with no subcontractor language or no breach-notice deadline shorter than 60 days.
Week 3. Send a standard request to your top 10 vendors by PHI volume: current subcontractor list, most recent security assessment, confirmation of downstream agreements. Log the send date.
Week 4. Replace flagged agreements. Set a recurring annual review and assign the owner by name.
If you're rebuilding more than the BAAs — policies, risk analysis, workforce training documentation — the automated HIPAA document set covers the full package. But start with the agreements. A signed BAA with real flow-down language is the single cheapest control you can put between your practice and someone else's subcontractor's mistake.
Generate a current, signature-ready agreement from the BAA builder, send it to the three vendors whose paperwork you can't currently locate, and put the executed copies in the file this month.