What Is a BAA? The Vendor Contract Your Practice Needs
Count the outside companies that touch your patient data. The billing service. The transcription vendor. The shredding company. The IT contractor with domain admin. The answering service. The cloud storage account nobody remembers opening. A three-provider primary care office typically lands somewhere between 15 and 40. Every one of them raises the same question: what is a BAA, and do you have a signed one on file for this vendor?
This article is for the person who owns that list — the practice administrator, privacy officer, or compliance lead who will be asked to produce signed agreements when a records request goes sideways or a vendor gets ransomwared. It covers who needs an agreement, what the document must say, and what the evidence file looks like when someone asks for it.
What Is a BAA in Plain Operator Terms
A BAA — business associate agreement, sometimes written as a business associate contract — is a written agreement between your practice (the covered entity) and any outside person or company that creates, receives, maintains, or transmits protected health information on your behalf. It obligates that vendor to safeguard the PHI, limit how they use it, report incidents to you, and pass the same duties down to their own subcontractors.
The requirement sits in the Privacy Rule at 45 CFR 164.502(e) and 164.504(e), with a parallel Security Rule requirement at 164.308(b) and 164.314(a). HHS publishes guidance on business associates and a set of sample agreement provisions you can read directly.
Two things a BAA is not. It is not a certification — nobody at HHS reviews or blesses your agreement. And it is not a shield. If your vendor loses 4,000 records, the signed agreement does not make the incident someone else's problem in the eyes of your patients or your state attorney general. It defines duties and creates a paper trail. That is its job.
Which Vendors Need One and Which Don't
The test is function, not industry. Ask: does this vendor handle PHI in order to perform a service for us? If yes, you need an agreement before they touch data.
Needs a BAA: billing and RCM companies, clearinghouses, EHR and practice management hosts, transcription and scribe services, answering and after-hours services, release-of-information vendors, cloud storage and backup providers, email and secure messaging providers that store your messages, IT managed service providers with access to systems containing PHI, shredding and document destruction companies, medical records copy services, patient engagement and reminder platforms, collections agencies, outside coders and auditors, attorneys reviewing charts, actuarial and accounting firms that see PHI.
Does not need a BAA: your own W-2 employees and contracted workforce members you directly supervise (they are covered by your policies and training, not a BAA). Other providers you share PHI with for treatment — the specialist you refer to is not your business associate. Health plans paying claims. Janitorial staff with incidental exposure and no data access. Couriers, the postal service, and internet service providers acting as pure conduits.
The conduit exception is narrower than vendors claim
The conduit exception covers transmission only — a delivery truck, a telecom line. The moment a vendor stores PHI, even encrypted, even briefly, even without ever looking at it, they are a business associate. HHS has been explicit that cloud service providers holding encrypted PHI without the key are still business associates. When an IT vendor tells you they "just move data" or "can't read it anyway," that is not the standard. Storage is maintenance. Maintenance requires an agreement.
What Is a BAA Required to Contain? Nine Terms
A compliant business associate agreement must, at minimum:
- Describe the permitted and required uses and disclosures of PHI by the business associate.
- State that the business associate will not use or further disclose PHI except as permitted by the contract or required by law.
- Require appropriate safeguards, including Security Rule administrative, physical, and technical safeguards for electronic PHI.
- Require the business associate to report any use or disclosure not permitted by the contract, including breaches of unsecured PHI and security incidents.
- Require the business associate to bind its subcontractors to the same restrictions in writing.
- Require the business associate to make PHI available for individual access, amendment, and accounting of disclosures under 164.524, 164.526, and 164.528.
- Require the business associate to make internal practices and records available to HHS for compliance review.
- Require return or destruction of all PHI at termination, if feasible, and continued protection if it is not.
- Authorize your practice to terminate the contract if the business associate materially violates it.
If a vendor hands you a one-page document that omits subcontractor flow-down or termination rights, it is not sufficient. That is the most common gap in the agreements crossing practice administrators' desks.
Subcontractors: The Chain Doesn't Stop at Your Vendor
Since the 2013 Omnibus Rule, subcontractors of business associates are business associates themselves, directly liable under HIPAA. Your billing company that offshores data entry must have an agreement with that offshore firm. Your EHR host that uses a third-party backup provider must have one with the backup provider.
You do not sign those downstream agreements. You do, however, have a legitimate interest in confirming they exist. Add one line to your vendor questionnaire: List every subcontractor with access to our PHI and confirm a written agreement is in place with each. Keep the answer with the file. When a breach originates four layers down — and several of the largest healthcare breach reports on the OCR breach portal trace to vendors and their vendors — that questionnaire is the difference between diligence and negligence.
A Worked Example: Onboarding a Transcription Vendor in 10 Business Days
Here is the workflow that actually holds up. Assign each step to a named role, not "the office."
Day 1 — Practice manager. Intake form: what PHI will this vendor touch, how does it get there, where is it stored, who at the vendor can see it. No PHI moves until the file is open.
Days 2–3 — Privacy officer. Send your standard agreement. Do not start from the vendor's template unless you have read every clause. Vendor templates frequently add broad de-identification and data-analytics rights, indemnity caps that make breach recovery meaningless, or 30-day breach notice windows.
Days 3–5 — Security officer. Request evidence of safeguards: encryption at rest and in transit, MFA on administrative accounts, access review cadence, last penetration test or security assessment, incident response contact. Note the January 2025 HHS proposed Security Rule update would push covered entities toward obtaining periodic written verification of a business associate's technical safeguards. It is a proposal, not law, but asking now costs you nothing and puts you ahead of it.
Days 5–8 — Negotiation. Push the breach notice window down. The regulatory floor lets a business associate take up to 60 days, which is useless to you because your 60-day clock to notify patients runs from the business associate's discovery. Ask for 5 business days for suspected incidents and immediate notice for confirmed breaches of unsecured PHI.
Day 9 — Signature. Correct legal entity names on both sides. "Riverbend Family Medicine, PLLC," not "Riverbend." A signature from someone with authority to bind the vendor.
Day 10 — Register entry. Log vendor, service, PHI categories, effective date, renewal date, breach notice window, subcontractor list, and file location. Then provision access.
If drafting the document is the bottleneck — and for most practices it is, because the alternative is paying counsel by the hour for a form contract — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, which matters when you are papering 20 vendors at once.
What the Documented Evidence Looks Like
An investigator or a health system's third-party risk team will not ask "do you take BAAs seriously." They will ask for four things.
The register. A single spreadsheet or system of record listing every business associate, current status, and where the executed agreement lives. If you cannot produce this in five minutes, you do not have a program.
The executed agreements. Fully signed, both parties, dated. Countersigned PDFs, not "we emailed it to them in 2021."
Retention proof. Under 45 CFR 164.530(j)(2), keep each agreement six years from the date of creation or the date it was last in effect, whichever is later. A vendor you fired in 2023 under a 2018 agreement stays in your file until 2029. Do not purge on termination.
Diligence artifacts. The security questionnaire, the subcontractor disclosure, any remediation correspondence, and your annual review notes. This is also where your risk analysis and supporting policy set should reference vendor risk explicitly, since business associate relationships are a risk category the Security Rule expects you to have evaluated.
Where These Agreements Fail
Five patterns, all of them cheap to fix and expensive to ignore:
- No agreement at all. Older OCR resolutions make the point plainly — Raleigh Orthopaedic Clinic settled for $750,000 in 2016 after releasing X-ray films to a vendor without an agreement, and Center for Children's Digestive Health settled for $31,000 in 2017 over a records storage vendor. The absence itself is the violation, regardless of whether data leaked.
- Expired or superseded. A 2014 agreement with a vendor whose entire architecture changed in 2020 is a document, not a control.
- Wrong entity. Practices reorganize. The PLLC that signed may no longer exist.
- Signed after access was granted. Check whether the effective date precedes the first data transfer. Auditors do.
- Never reviewed again. Put a recurring annual task on the privacy officer's calendar: reconcile the register against accounts payable and against your list of active system accounts. Vendors you forgot about show up in both places.
"We're SOC 2 Certified — Do We Still Need a BAA?"
Yes. A SOC 2 report, an ISO 27001 certificate, and a HITRUST assessment are all evidence of controls. None of them is a contract between your practice and that vendor, and none of them creates the specific obligations HIPAA requires — subcontractor flow-down, individual access support, HHS access, return or destruction at termination. When a vendor offers an attestation in place of an agreement, accept the attestation as diligence evidence and still require the signed document.
The related question: what if a vendor refuses? Then you have a decision, not a negotiation. A vendor that will not sign cannot lawfully receive PHI from you. Some large platforms genuinely do not offer agreements because their product was never built for PHI — consumer file sync, general-purpose form builders, marketing automation, most free video tools. The answer there is to change vendors, not to hope.
Your Next Two Hours
Pull last quarter's accounts payable. Highlight every vendor that could plausibly touch patient data. Match each against your signed agreements. The gaps you find in that hour are the gaps an investigator would find, and closing them is straightforward — draft, send, countersign, log.
If the missing paperwork is what is stalling you, build your agreement in six steps and export it ready for signature, then work down the list one vendor at a time. A complete register beats a perfect one you never finished.