Your billing clearinghouse has touched every claim your practice has filed since 2019. Somebody signed something back then. Nobody can find it, the person who signed it left in 2022, and the vendor has since been acquired twice. That gap is exactly what a HIPAA vendor agreement is supposed to close — a written, signed contract that binds any outside company handling your protected health information to the same safeguards you follow. This article covers who needs one, what it must say, when it has to be executed, and what documented evidence looks like when the Office for Civil Rights asks.

The Regulation Doesn't Say "Vendor Agreement" — It Says Business Associate Contract

The term everyone uses in procurement meetings is "vendor agreement." The term in the regulation is business associate contract, governed by 45 CFR 164.502(e), 164.504(e), 164.308(b), and 164.314(a). They describe the same document. Your vendor's sales team may call it a BAA, a DPA addendum, or a HIPAA rider — what matters is whether it contains the required provisions and whether both parties actually signed it.

Since the 2013 Omnibus Rule, business associates are directly liable to OCR for Security Rule violations and for impermissible uses and disclosures. That did not remove your obligation. You still must obtain satisfactory assurances in writing before the vendor touches PHI, and you are still on the hook if you know about a pattern of violations and do nothing.

Who Needs a HIPAA Vendor Agreement? (The Short Answer)

You need a signed HIPAA vendor agreement with any person or company outside your workforce that creates, receives, maintains, or transmits protected health information on your behalf, or that provides services involving disclosure of PHI. In practice, that includes:

  • Billing companies, coding contractors, and clearinghouses
  • EHR and practice management software hosts
  • Cloud storage, backup, and file-transfer providers
  • Transcription and scribe services, including AI documentation tools
  • IT support and managed service providers with server or workstation access
  • Shredding, record storage, and secure disposal companies
  • Answering services, patient reminder and messaging platforms
  • Outside attorneys, accountants, and consultants who review charts
  • Collection agencies and revenue cycle firms
  • Release-of-information and copy services

You do not need one for your own employees, for other covered entities receiving PHI for treatment, for plumbers or janitors with only incidental exposure, or for pure conduits like the postal service and an internet service provider that only transports data without storing it.

The Nine Provisions Every HIPAA Vendor Agreement Must Contain

HHS publishes sample business associate agreement provisions. Use them as your floor, not your ceiling. A compliant agreement must, at minimum:

  1. Describe the permitted uses and disclosures of PHI by the vendor, tied to the actual service being performed.
  2. Prohibit any other use or disclosure unless required by law.
  3. Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
  4. Require reporting of breaches, impermissible disclosures, and security incidents to you.
  5. Bind subcontractors to the same restrictions through their own written agreements.
  6. Support patient rights — access under 164.524, amendment under 164.526, and accounting of disclosures under 164.528.
  7. Make internal practices, books, and records available to HHS for compliance review.
  8. Return or destroy PHI at termination, or extend protections if return is infeasible.
  9. Allow you to terminate for material breach.

Two additions worth negotiating that the regulation does not mandate: a firm notification deadline shorter than the regulatory outer limit, and a breach cost allocation clause. If a vendor's misconfigured storage bucket exposes 40,000 of your records, someone pays for notification letters, credit monitoring, and the call center. Decide in advance who.

The 60-Day Chain That Starts at Your Vendor's Help Desk

Under 45 CFR 164.410, a business associate must notify you of a breach without unreasonable delay and no later than 60 calendar days after discovery. Under 164.404, you must notify affected individuals no later than 60 calendar days after your discovery. If your vendor uses its full 60 days, your clock has already been running — a breach is treated as discovered by you when your business associate, acting as your agent, discovers it.

That is why a generic HIPAA vendor agreement is a liability. Write in a hard number: notice to your privacy officer within 5 business days of discovery for confirmed breaches, and within 24 hours for any incident affecting more than 500 records. Name the recipient by role and email address, not by individual, so the clause survives turnover.

Review the OCR breach reporting portal before you sign with a new vendor. It is public, searchable, and shows whether your prospective partner has already reported an incident. Ten minutes of searching has killed more bad vendor deals than any questionnaire.

Building the Vendor Inventory That Makes This Manageable

You cannot paper agreements you cannot name. Start with the money.

Step 1: Pull twenty-four months of accounts payable

Every recurring payment to an outside company is a candidate. Your practice administrator or office manager exports the vendor list from your accounting system and drops it in a spreadsheet. Expect 40 to 120 rows for a mid-size practice.

Step 2: Add the vendors nobody pays

Free tier tools. The scheduling app a physician signed up for personally. The fax-to-email service. The survey platform marketing uses. Ask each department head to list every piece of software they touch. This step always produces surprises.

Step 3: Classify each row

Three buckets: business associate, not a business associate, needs determination. For the third bucket, write down the reasoning and who decided. Documented reasoning is defensible; silence is not.

Step 4: Match each business associate to an executed agreement

Record the effective date, both signature dates, the signer names and titles, where the PDF lives, and the renewal or review date. If you cannot produce the signed document, treat it as missing and reissue.

Step 5: Assign owners and dates

Each business associate gets a named internal owner and an annual review date. The privacy officer owns the register; department owners confirm their vendors are still in use each year.

When you hit the vendors with no agreement on file — and you will, usually somewhere between three and fifteen of them — you need a clean document fast. You can generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export, which is generally faster than routing a redline through counsel for a $200-a-month transcription vendor. One-time purchase, no subscription, and the DOCX means your attorney can still edit it if the relationship warrants custom terms.

Where a HIPAA Vendor Agreement Gets Complicated

Software vendors that refuse to sign

Some consumer-grade tools state plainly that they will not enter a HIPAA vendor agreement. That is your answer: the tool cannot touch PHI. Not "we'll be careful." Not "we only put initials in it." If the vendor won't sign, the workflow changes or the vendor goes.

Vendors that aren't business associates but still hold health data

A wellness app your patients use directly, a direct-pay service line outside HIPAA's scope, or a marketing platform collecting health information from your website may fall under the FTC's Health Breach Notification Rule rather than HIPAA. Different rule, different notification obligations, same reputational damage. Map these separately.

Subcontractors your vendor never mentioned

Your billing company uses an offshore coding contractor. Your EHR host runs on a public cloud. Your agreement requires the vendor to bind those parties, but requiring it and verifying it are different activities. Once a year, ask your five highest-risk vendors in writing to list their subcontractors with PHI access and confirm agreements are in place. Keep the email thread.

Mergers and acquisitions

When your vendor is acquired, the agreement usually survives by assignment — but the security posture may not. Trigger a review on any change of control. Put that trigger in the contract.

What the Documented Evidence Actually Looks Like

If OCR opens a compliance review after a breach, the request for information typically asks for your business associate agreements and your policies governing them. Have these six artifacts ready:

  • The vendor register — every third party, classification, decision rationale, owner, review date.
  • Executed agreements — countersigned, dated, stored somewhere that is not one person's email.
  • A written policy stating that no vendor receives PHI before an agreement is executed, with the approval workflow spelled out.
  • Due diligence records — security questionnaires, SOC 2 reports, breach portal searches, dated.
  • Annual review documentation — who reviewed what, when, and what changed.
  • Termination records — for ended relationships, written confirmation that PHI was returned or destroyed.

Your risk analysis should reference vendor risk explicitly. NIST Special Publication 800-66 Revision 2 maps Security Rule requirements to practical implementation and treats third-party risk as a first-class concern rather than a footnote. If your risk analysis, policies, and document set are still living in scattered Word files, automating the risk analysis and policy set removes a lot of the manual assembly work.

The Failure Mode: Signed and Forgotten

The most common finding is not a missing agreement. It is an agreement signed in 2018 covering a service the vendor no longer provides, with a notification clause naming a privacy officer who retired, referencing an encryption standard nobody has verified since.

Set a recurring calendar item. Every January, pull the register. Confirm each vendor is still active, still performing the described service, still has current contact routing, and still has a valid agreement. Kill the rows for vendors you stopped using and document the PHI disposition. Budget a half day. It is the cheapest half day in your compliance calendar.

Also watch for the proposed Security Rule updates HHS published for comment in January 2025, which would tighten expectations around business associate verification of safeguards. Nothing is final as of today, but if your program already collects annual written confirmation from vendors, you are positioned for whatever lands.

Start With the Gap You Already Know About

You almost certainly have at least one vendor touching PHI without a current signed agreement. Name it, then close it this week. If the relationship is standard and low-complexity, build the agreement and send it for signature the same day rather than letting it sit in the legal queue for a quarter. Then start the register — because the second gap is the one you haven't found yet.