Your billing company just told you they subcontract claim scrubbing to an offshore team. Nobody at your practice knew. There is no agreement on file between the billing company and that subcontractor, and your own contract with the biller was signed in 2019 and never revisited. That gap — not a hacker, not a lost laptop — is the kind of finding that turns a routine complaint into a full compliance review. Every vendor that touches protected health information on your behalf is a HIPAA business associate, and each one requires a written agreement before the first record moves.

This article is for the person who owns the vendor list: who qualifies, what the agreement must say, when it has to be signed, and what evidence you produce when someone asks.

What Makes a Vendor a HIPAA Business Associate

Run every vendor through three questions. If the answer to all three is yes, you need an agreement.

  1. Does the vendor create, receive, maintain, or transmit protected health information?
  2. Are they doing it on behalf of your practice — performing a function or service for you?
  3. Are they outside your workforce (not an employee, volunteer, or trainee under your direct control)?

The second question is where administrators trip. A specialist you refer a patient to receives PHI, but they are treating the patient in their own right, not performing a service for you. That is a covered-entity-to-covered-entity disclosure for treatment. No agreement required.

Your answering service, on the other hand, is doing your job for you. So is your shredding company, your transcription vendor, your cloud backup provider, your patient-reminder texting platform, your medical malpractice defense firm reviewing charts, and the IT contractor with remote access to your server closet.

The Conduit Exception Is Narrower Than Vendors Claim

HHS carved out a genuine but very thin exception for entities that act as mere conduits — the postal service, private couriers, and internet service providers moving data without accessing it beyond what transmission requires. Random or incidental access is the test.

Cloud storage does not qualify. HHS has been explicit that a cloud service provider maintaining PHI is a business associate even if the data is encrypted and the provider holds no key. Read the agency's cloud computing guidance before accepting a vendor's claim that encryption exempts them. It does not.

Subcontractors Inherit the Obligation

Since the 2013 Omnibus Rule, a subcontractor who handles PHI for a business associate is itself a business associate, directly liable to HHS. Your billing company must have written agreements with its own downstream vendors. You are not required to sign those agreements, but you should require your vendor to attest that they exist and to notify you when the chain changes.

Put that attestation in your contract renewal checklist. "Do you subcontract any function involving our patient data, and do you have executed agreements with each subcontractor?" is a two-line email that has saved practices from unpleasant discoveries.

Quick Answer: Do You Need a BAA With This Vendor?

You need a business associate agreement when an outside company handles protected health information to perform a service for your practice. Common examples: billing and coding companies, EHR and practice management vendors, cloud hosting and backup providers, IT managed service providers, transcription services, answering services, secure messaging and patient engagement platforms, document shredding companies, collections agencies, data analytics firms, and attorneys or accountants who review PHI.

You do not need one for: other providers receiving PHI for their own treatment of the patient, health plans paying claims in their own right, couriers and ISPs acting as pure conduits, janitorial services with only incidental exposure, or your own employees. Government agencies receiving mandatory public health reports are also outside the requirement.

When you are genuinely unsure, the safer operational choice is to execute an agreement. There is no penalty for having one you did not strictly need.

The Nine Things Your Agreement Must Address

The regulation at 45 CFR 164.504(e) sets the required content. HHS publishes sample business associate agreement provisions that track the rule directly. Your agreement must:

  • Describe the permitted and required uses and disclosures of PHI by the business associate
  • Prohibit uses or disclosures beyond what the contract or law allows
  • Require appropriate safeguards, including Security Rule administrative, physical, and technical safeguards for electronic PHI
  • Require reporting of any use or disclosure not permitted by the contract, including security incidents and breaches
  • Bind subcontractors to the same restrictions
  • Require the vendor to make PHI available so you can satisfy patient access requests and amendment requests
  • Require the vendor to provide an accounting of disclosures
  • Require the vendor to make its books, records, and practices available to HHS
  • Require return or destruction of PHI at termination, and permit you to terminate for material breach

A one-page "we agree to comply with HIPAA" letter is not a business associate agreement. Neither is a security addendum buried in a master services agreement that never mentions patient access, accounting of disclosures, or termination handling. If your file contains either of those, treat it as a gap.

If you are rebuilding a stack of expired or inadequate contracts, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase with no subscription — useful when you need eleven agreements out the door before the end of the quarter and legal review time is not available for each one.

When the Agreement Has to Exist

Before the first disclosure. Not at go-live, not after the implementation call, not when the invoice arrives.

In practice, this means your vendor onboarding sequence has a hard gate. Build it into procurement:

  1. Intake. Whoever proposes the vendor answers the three-question test in writing.
  2. Determination. Your privacy officer classifies the vendor: business associate, not a business associate, or unclear. Record the reasoning in one or two sentences.
  3. Execution. If a business associate, the agreement is signed by an authorized officer on both sides before credentials are issued, before a data feed is turned on, before the first file transfer.
  4. Filing. Signed PDF goes to the vendor file with the effective date, renewal date, and the name of the person who owns the relationship.
  5. Review. Annual re-check of scope. Did the vendor's services expand? Did they add subcontractors? Did they change hosting regions?

Assign the gate to a specific role, not to "the practice." In a ten-provider group, that is usually the practice administrator with the privacy officer as backstop. Write the name down.

The 60-Day Chain: Breach Reporting Between You and Your Vendor

Under 45 CFR 164.410, a business associate must notify you of a breach without unreasonable delay and no later than 60 calendar days after discovery. You then have your own 60-day clock, running from the date the breach is treated as discovered by your practice, to notify affected individuals.

Stacked end to end, that is 120 days — long enough to blow through your obligation if the vendor uses every day of theirs. So negotiate it down. A 5 to 10 business day notification requirement in your agreement is standard and reasonable, and most competent vendors will accept it.

Specify what the notice must contain: identification of affected individuals, description of what happened, types of PHI involved, and what the vendor has done to mitigate. Vague "we experienced an incident" emails leave you unable to start your own risk assessment.

For breaches affecting 500 or more individuals, you notify HHS contemporaneously with individual notice. Smaller breaches are logged and reported within 60 days after the end of the calendar year. The OCR breach portal lists reported incidents, and a substantial share of the large ones are attributed to business associates rather than to providers directly. Scan it periodically for your own vendors' names.

What Documented Evidence Looks Like

If OCR opens a review, "we have agreements with everyone" is not a response. Here is what a defensible file contains:

A Current Vendor Inventory

One spreadsheet or register listing every third party with PHI access. Columns: vendor name, service, PHI types touched, systems accessed, business associate yes/no, determination rationale, agreement effective date, agreement expiration or renewal, internal owner, last review date.

Reconcile it against your accounts payable list once a year. That is how you find the transcription vendor a departing physician onboarded in 2022 and nobody documented.

Executed Agreements With Verifiable Signatures

Countersigned by both parties, with dates. An unsigned template in a folder is worse than nothing, because it demonstrates you knew the obligation and did not complete it.

Termination Records

When a relationship ends, document what happened to the PHI. Certificate of destruction, confirmation of return, or written attestation that retention is required and protections continue. Keep it with the closed vendor file.

Six-Year Retention

HIPAA documentation retention is six years from creation or from the date it was last in effect, whichever is later. An agreement that ran from 2019 to 2023 stays in your file until at least 2029.

Where Practices Actually Get Caught

OCR has resolved cases in which the substantive failure was simply the absence of an executed agreement before PHI moved to a vendor. No hacking. No malicious insider. A records storage company or an imaging transfer arranged on a handshake, followed by a breach that exposed the gap.

The other recurring pattern: a signed agreement and nothing else. An agreement is not a risk analysis, and it does not transfer your Security Rule obligations. You still owe a documented, enterprise-wide risk analysis covering every system where ePHI lives — including systems your vendors operate on your behalf. NIST's SP 800-66 Revision 2 maps Security Rule requirements to practical implementation steps and is the closest thing to a government-blessed methodology. If you need the risk analysis, policies, and supporting documents assembled as a set, automated HIPAA compliance documentation covers that layer.

Be direct with vendors who claim to be "HIPAA certified." HHS does not certify, endorse, or accredit any product, service, or company. A certificate from a training vendor tells you an employee sat through a course. It is not a substitute for your own diligence, and it does not replace the agreement.

What Is on the Horizon

HHS published a proposed rule in January 2025 to significantly update the Security Rule. Among the proposals affecting vendor relationships: business associates would be required to verify their safeguards annually through a written analysis and certification provided to the covered entity, and to notify covered entities within 24 hours of activating contingency plans after a security event.

That rule is not final as of December 2025, and the requirements may shift before it is. But the direction is clear — regulators expect continuous verification, not a signature from three years ago. Practices that already collect annual vendor attestations will have far less to change.

Start With the Reconciliation

Pull your vendor payment list this week. Mark every entry that touches patient data. Compare it to your agreement file. The delta is your work queue, and it is almost always longer than administrators expect.

For every gap you find, produce a compliant agreement and send it for signature — one-time purchase, PDF and DOCX export, no subscription to manage. Then log the effective date in your inventory and set the review reminder. That is the whole obligation, and it is finishable.