Your billing manager signed up for an AI note-summarizing tool last March with a practice credit card. It ingests audio from exam rooms. Nobody told you. There is no Business Associate Agreement in your file, no entry in your vendor inventory, and no line item in your risk analysis. That single subscription is the most common failure point in HIPAA for cloud vendors — not a sophisticated breach, just a service that entered the building through the side door.

This article is for the person who has to fix that: the practice owner, privacy officer, or compliance lead who signs vendor contracts and answers when OCR calls. It covers which cloud services are business associates, what the agreement must say, how responsibility splits between you and the vendor, and what documentation proves you did the work.

What HIPAA for Cloud Vendors Actually Requires

A cloud service provider that creates, receives, maintains, or transmits protected health information on behalf of your practice is a business associate under 45 CFR 160.103. That triggers four obligations:

  • A signed Business Associate Agreement executed before the vendor touches PHI, meeting the contract requirements in 45 CFR 164.504(e) and 164.314(a).
  • Direct Security Rule liability for the vendor — administrative, physical, and technical safeguards, plus its own risk analysis, under the HITECH amendments.
  • Breach notification to your practice without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.410).
  • Downstream BAAs with the vendor's subcontractors that handle your PHI.

Your side of the ledger: identify every cloud vendor touching PHI, obtain the BAA, include the service in your risk analysis, and retain the documentation for six years.

The Conduit Exception Is Narrower Than Your Vendor Thinks

Vendors sometimes argue they are a "mere conduit" and therefore exempt. HHS has been explicit that the conduit exception is limited to entities that transmit PHI and provide only transient storage incidental to that transmission — the postal service, an internet service provider, a telecommunications carrier moving packets.

A cloud platform that stores your data is not a conduit. Persistence is the dividing line. If PHI sits on the vendor's infrastructure for any period beyond transient transmission, the vendor is a business associate and needs a BAA.

HHS addressed this directly in its guidance on HIPAA and cloud computing, which remains the single most useful document to send a vendor's legal team when they push back. Print it. You will use it more than once.

Encryption Does Not Remove a Cloud Vendor From HIPAA

The most persistent myth in this space: "We can't read the data, so we're not a business associate." Wrong. HHS calls these "no-view services," and the guidance is unambiguous — a cloud provider that stores encrypted PHI without holding the decryption key is still a business associate and still needs a BAA.

The lack of key access changes what safeguards are practical, not whether HIPAA applies. A no-view vendor may reasonably rely on your practice for access controls and audit logging of the data content, but it still owes availability protections, physical security of the data centers, workforce training, and breach notification. Document that division in the agreement rather than assuming it.

Same answer for de-identification claims. If the vendor receives identifiable data and de-identifies it, the receipt itself is a business associate function. The BAA has to exist first.

The Shared Responsibility Split Nobody Documents

Large infrastructure providers publish shared responsibility models. Most practices never read them, then discover after an incident that encryption at rest was a configuration checkbox nobody checked.

What the cloud vendor typically owns

Physical security of data centers. Hypervisor and host operating system patching. Network infrastructure. Availability and redundancy of the underlying platform. Its own workforce screening and sanctions. Notification to you when it discovers a breach.

What your practice almost always owns

User account provisioning and termination. Role-based permissions inside the application. Multi-factor authentication enforcement. Whether encryption options are turned on. Retention and deletion settings. Audit log review. Deciding which staff members get access to which records.

Write this split into a one-page document per major vendor and store it with the BAA. When an investigator asks who was responsible for disabling the terminated employee's account, you want a paper answer, not a conversation.

The configuration gap

A HIPAA-eligible cloud service is not the same as a HIPAA-configured deployment. Many platforms offer both compliant and non-compliant configurations under the same subscription. Public sharing links, default retention periods, and third-party integrations enabled by a staff member can each move PHI outside the protected boundary while the vendor remains technically compliant. Your annual review needs to check settings, not just contracts.

Five Contract Terms to Nail Down Before You Sign

The BAA is a floor, not a ceiling. HHS publishes sample business associate agreement provisions that satisfy the regulatory minimum. Add these five, in the BAA or the master services agreement:

  1. Breach notification timing shorter than 60 days. The regulation gives the business associate up to 60 days. Your practice then has its own 60-day clock from discovery. Negotiate vendor notice within 5 to 10 business days of discovery, with preliminary notice within 72 hours.
  2. Data location and offshore access. Name the countries where PHI may be stored and where support personnel may access it. Offshore access is not prohibited by HIPAA, but you cannot assess a risk you do not know about.
  3. Subcontractor disclosure. Require a current list of subcontractors that handle PHI and advance notice before material changes.
  4. Return or destruction on termination. Specify the format, the deadline in days, and a written certificate of destruction. "Commercially reasonable efforts" is not a deadline.
  5. Audit and evidence rights. The right to receive the vendor's most recent independent security assessment annually, plus penetration test summaries. Full audit rights are unrealistic with hyperscale providers; documentation rights are not.

If you are papering a new vendor relationship and need a compliant document quickly, a signature-ready Business Associate Agreement generator will produce the required provisions in PDF and DOCX without a subscription. Use it as a baseline, then layer the five terms above on top.

Building Your Cloud Vendor Inventory in One Afternoon

You cannot manage what you have not listed. Here is the workflow that actually finds shadow vendors.

Step one — pull the money trail. Ask your bookkeeper for 24 months of credit card and ACH statements filtered for recurring charges under $500. Nearly every unauthorized SaaS subscription in a medical practice shows up as a small recurring charge nobody questioned.

Step two — pull the network trail. Ask your IT provider for a list of outbound domains from practice workstations over 30 days. Scheduling widgets, form builders, fax-to-email services, and transcription tools appear here.

Step three — ask the humans. Send a three-question survey to every department lead: what software do you use daily, what do you use monthly, and what do you use when the main system is down. That last question surfaces the personal Dropbox account someone uses during outages.

Step four — classify. For each entry, record whether PHI is created, received, maintained, or transmitted. If yes, it needs a BAA. If uncertain, treat it as yes until the vendor proves otherwise in writing.

Step five — assign an owner. Every vendor gets a named staff owner and a renewal date. A vendor without an owner becomes a vendor without oversight within one staffing change.

A five-provider practice typically lands between 18 and 40 cloud services touching PHI. If your list has six entries, you have not finished step one.

The Evidence an Investigator Asks For

OCR investigations following a breach report almost always request the same artifacts. Assemble them now rather than during a 30-day response window.

  • The current risk analysis, with scope covering all systems that hold ePHI — including cloud-hosted systems, named individually.
  • The risk management plan showing what you did about the risks you identified, with dates and responsible parties.
  • Executed BAAs for every vendor on the inventory, with signature dates preceding the date PHI first flowed.
  • Policies and procedures covering access management, audit controls, contingency planning, and sanctions.
  • Workforce training records with dates and attendance.
  • Evidence of periodic evaluation — dated notes from your annual review of each vendor.

The risk analysis is where most practices fail, and cloud services are the usual reason. A risk analysis that inventories your server closet but omits the eleven SaaS platforms holding patient data is not compliant with 45 CFR 164.308(a)(1)(ii)(A). NIST's SP 800-66 Revision 2 gives a workable method for scoping and documenting one.

If pulling this together from scratch is the reason it keeps slipping to next quarter, a platform that automates HIPAA risk analysis reports and the supporting policy set will get you a defensible baseline in days instead of months. The output still needs your judgment about your own systems — but you start from a structured document rather than a blank one.

Where Cloud Vendors Break: Subcontractors and Offshore Support

Your BAA obligates the vendor to bind its subcontractors. Most vendors do this. The gap appears at the third and fourth tier, where a hosting provider uses a monitoring service that uses an offshore support desk.

You cannot audit tier four. You can require tier-one disclosure and ask two questions during renewal: which subcontractors handle PHI, and has that list changed since last year. Document the answer. A dated email from the vendor's compliance contact is evidence; an assumption is not.

Enforcement history shows OCR has pursued business associates directly, including IT and services vendors, for failures in risk analysis and access controls. The OCR breach portal lists reported incidents affecting 500 or more individuals, with the business associate identified where one was involved. Search your vendors there before you sign. It takes four minutes and occasionally changes a decision.

A 90-Day Plan You Can Actually Finish

Days 1–15. Build the vendor inventory using the five-step workflow. Assign owners. Flag every vendor without a BAA on file.

Days 16–45. Send BAA requests to flagged vendors. Set a hard internal deadline. For vendors that refuse or stall, start identifying replacements — a cloud vendor that will not sign a BAA is telling you something useful.

Days 46–75. Update the risk analysis to include every cloud system by name, with a threat and vulnerability assessment for each. Document the shared responsibility split for your top five vendors by data volume.

Days 76–90. Review configurations. Confirm MFA, verify terminated-user account removal against your HR termination list for the past year, and check retention settings. Write a dated memo summarizing what you found and fixed.

One note on the regulatory horizon: HHS proposed significant Security Rule revisions in January 2025 that would tighten requirements around asset inventories, encryption, and vendor verification. As of this writing the rule is not final. Practices that build a real cloud vendor inventory now will be closer to compliance if and when it lands.

Start With the Gap You Already Know About

Pick the vendor you thought about while reading this — the one whose BAA you cannot locate. Email the vendor today, log the request, and put a calendar reminder for seven days out. That is the whole first step.

When you are ready to close the larger gap, generate your risk analysis and compliance document set and use the cloud vendor inventory you just built as its scope. The documents are only useful if they describe the systems you actually run.