Subcontractor BAA Rules: Who Signs What Down the Chain
Your billing company signs a BAA with you. Your billing company then hands claim scrubbing to a coding firm three states away, which routes overflow work to contractors overseas. Nobody told your privacy officer. Nine months later a laptop goes missing at the coding firm and 4,100 of your patients are in the file.
That coding firm needed a subcontractor BAA with your billing company — not with you. But when the notification letters go out, your practice name is on them, and your patients call your front desk. This article covers who owes a subcontractor BAA, what the document must contain, how far down the chain the obligation runs, and what evidence you keep so the answer to "show me" takes ten minutes instead of ten days.
The Obligation Doesn't Stop at Your Direct Vendor
Since the 2013 Omnibus Rule, HIPAA obligations flow down the vendor chain automatically. A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of a business associate is a business associate under 45 CFR 160.103 — whether or not anyone signed anything.
Two provisions do the work. Under 45 CFR 164.502(e)(2), a business associate may disclose PHI to a subcontractor only after obtaining satisfactory assurances, in the form of a written contract. Under 45 CFR 164.308(b)(2), those assurances must be documented before the PHI moves.
The practical consequence: liability attaches even when paperwork doesn't. An unsigned relationship is not an exempt relationship. It's an undocumented violation sitting in your vendor's file cabinet.
Who Signs a Subcontractor BAA — and Who Doesn't
The direct answer: a subcontractor BAA is signed between a business associate and its subcontractor. The covered entity is not a party. Your practice signs a BAA with your billing company; your billing company signs a subcontractor BAA with the coding firm; the coding firm signs one with its offshore contractor. Each link contracts with the next link only. There is no ceiling — the chain continues as long as PHI keeps moving.
HHS says this plainly in its business associate guidance: covered entities are not required to contract with subcontractors, and subcontractors are not required to contract with covered entities. The obligation runs one hop at a time.
Relationships that do NOT need a subcontractor BAA
- Conduits. The postal service, a courier, an ISP that only transmits PHI without accessing it beyond what's incidental to transport. The conduit exception is narrow — cloud storage does not qualify, because the provider maintains the data.
- Workforce members. A W-2 employee of your billing company is covered by that company's own policies and sanctions, not a separate contract.
- Vendors with no PHI access. The landlord, the office-supply distributor, the marketing firm working only on de-identified aggregate data.
- Downstream parties handling only de-identified data. If PHI is de-identified under the Safe Harbor or Expert Determination method before transfer, it isn't PHI anymore.
Relationships that almost always do
- Offshore or domestic coding and transcription contractors
- Cloud hosting and backup providers used by your EHR or billing vendor
- Data analytics firms your clearinghouse hires
- Shredding and media-destruction companies used by any vendor holding your records
- IT managed service providers that a business associate contracts for endpoint support
- AI transcription or documentation tools that a vendor embeds into its own product
What a Subcontractor BAA Must Contain
The required elements sit in 45 CFR 164.504(e). A subcontractor BAA must be at least as protective as the upstream agreement — a downstream contract cannot grant permissions the vendor never had. Read that sentence twice, because it's the single most common drafting failure.
- Permitted uses and disclosures. Specific, and no broader than what the upstream BAA allows.
- Safeguards. Administrative, physical, and technical, with compliance with the Security Rule stated as a direct obligation.
- Breach and incident reporting. Timing must be tight enough for the upstream party to meet its own deadlines.
- Flow-down. The subcontractor must bind its own subcontractors to the same terms.
- Individual rights support. Access, amendment, and accounting of disclosures — including cooperation timelines that fit inside the 30-day access clock.
- Termination and return or destruction of PHI. With a stated method and a certification requirement.
HHS publishes sample business associate agreement provisions that cover the required elements. They are a floor, not a finished contract — they don't address cyber insurance, indemnification, subcontractor approval rights, offshore data residency, or audit access, all of which belong in a real agreement.
If you're a business associate yourself — a billing service, an MSP, a transcription company — you own the drafting problem directly. Generating a signature-ready business associate agreement through a guided six-step wizard with PDF and DOCX export gets a compliant document in front of your subcontractor the same day, rather than waiting on a redline cycle while PHI is already flowing.
A Worked Example: The Chain Behind One Claim
A 14-provider orthopedic group. Follow one encounter:
- Practice → EHR vendor. BAA signed at implementation. Practice is the covered entity.
- EHR vendor → cloud infrastructure provider. Subcontractor BAA. The EHR vendor is now the upstream party.
- Practice → billing company. Separate BAA, separate obligations.
- Billing company → clearinghouse. Subcontractor BAA.
- Billing company → overflow coding firm. Subcontractor BAA — and this is the link most often missing, because overflow work starts as a temporary arrangement during a staffing gap and never gets papered.
- Coding firm → offshore contractors. Another subcontractor BAA, plus data residency terms your upstream contract should have required.
Six agreements. Your practice is a party to exactly two. But if step five is missing and the coding firm loses a laptop, your patients are notified, your name goes into the OCR breach portal for breaches affecting 500 or more individuals, and your phones ring.
The Breach Clock Runs Backward Up the Chain
Under the Breach Notification Rule, a covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days from discovery. A business associate must notify the covered entity on the same outer limit — 60 days from its own discovery.
Stack three layers of 60-day defaults and you have a 180-day worst case where your practice learns about a breach almost six months after it happened. That is legally survivable and operationally indefensible.
Fix it in the contract language. Your BAA with the direct vendor should require notice within 5 business days of discovery, and should require that vendor to impose a shorter window — 3 business days is typical — in every subcontractor BAA it executes. Write the flow-down timing explicitly. "Subcontractor shall comply with applicable law" gives you the 60-day default back.
What discovery means
A breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to any workforce member other than the person who committed it. Not the day the incident response team confirms scope. Not the day legal signs off. Your subcontractor BAA should say so, because vendors argue this point when the clock is unfavorable.
The Evidence File: What "Show Me" Actually Requires
When OCR opens an investigation, requests arrive with short response windows. Assemble this before you need it.
Your vendor inventory
One row per vendor with PHI access. Columns: vendor name, service, PHI categories touched, contract execution date, BAA execution date, BAA expiration or renewal date, whether subcontractors are used, and the name of the internal owner. That last column matters — unowned vendors are unmonitored vendors.
Subcontractor attestations
You cannot demand copies of your vendor's subcontractor BAAs as a matter of law, but you can require them by contract. At minimum, require an annual written attestation listing every subcontractor with PHI access, confirming an executed subcontractor BAA for each, and confirming no offshore access without prior written approval.
Send it as a form, not an open question. A one-page attestation with a signature line and a date gets returned. An email asking "can you confirm your subcontractor situation" gets forwarded and forgotten.
Change notification
Require 30 days' written notice before a vendor adds a new subcontractor with PHI access, with a right to object. This is the clause that surfaces the AI transcription tool your billing vendor quietly embedded in Q3.
Dates and versions
Keep executed BAAs for six years from the later of creation date or last effective date, per 45 CFR 164.316(b)(2). Keep superseded versions too. When an investigator asks which terms governed in March 2023, you need the March 2023 document, not the current one.
What Changed in 2025 — and What May Change Next
HHS published a proposed rule in January 2025 to modernize the HIPAA Security Rule. Among other things, it would tighten verification obligations between business associates and their subcontractors, moving from contractual promises toward documented technical verification on a defined cadence. As of December 2025 it remains a proposal, not enforceable law.
Don't wait for a final rule to act on the direction of travel. NIST's SP 800-66 Revision 2 already maps Security Rule requirements to concrete practices, including supply-chain risk considerations. Building annual subcontractor verification into your vendor management process now costs a few hours per vendor and puts you ahead of whatever version lands.
Five Questions to Send Every Vendor This Quarter
- List every subcontractor, by legal name, that creates, receives, maintains, or transmits our PHI.
- Confirm an executed subcontractor BAA is in place with each, and provide execution dates.
- Is any PHI accessed, stored, or processed outside the United States? If yes, by whom and where?
- What is your contractual breach notification deadline to us, and what deadline do you impose on your subcontractors?
- When did you last conduct a security risk analysis, and does its scope include subcontractor-hosted systems?
Set a 15-business-day response deadline. Log non-responses — a vendor that won't answer question one in three weeks is telling you something useful about question five.
Where Practices Actually Get Caught
Three patterns show up repeatedly in enforcement and in breach reporting.
The BAA that was never signed. A vendor relationship starts as a pilot, PHI flows, the pilot becomes production, and nobody circles back. OCR has repeatedly treated the absence of a business associate agreement as a standalone violation, independent of whether any data was actually exposed.
The BAA that only exists at the top. Your direct agreement is airtight; your vendor's downstream contracts are nonexistent. You discover this during a breach investigation, which is the worst possible time.
The BAA nobody reads. Executed in 2016, auto-renewing, referencing a subcontractor list that hasn't been accurate since the vendor's 2021 acquisition. Set a calendar reminder for annual review with the vendor inventory open beside you.
Start With the Gap You Already Know About
Pull your vendor list this week. Mark every vendor you know or suspect uses subcontractors with PHI access. That short list is your Q1 workplan.
For the agreements you need to put in place — whether you're a covered entity papering a direct vendor or a business associate executing a subcontractor BAA downstream — you can build a compliant, signature-ready agreement in about ten minutes and export it as PDF or DOCX. One-time purchase, no subscription. If your broader documentation set needs work too, automated risk analysis and policy generation covers the rest of the file OCR will ask for.
The subcontractor BAA is not the hardest document in your compliance program. It's just the one most often missing when someone finally goes looking.