Pull your accounts payable list. If your practice is average sized, you have somewhere between 30 and 60 active vendors on it. Somewhere between eight and fifteen of those vendors touch protected health information, and every one of them is a signature you need on file. Working out who needs a business associate agreement is not a philosophical exercise — it is a reconciliation task, and it is the single easiest thing for an investigator to check first.

This article walks the decision the way you'd actually run it: a two-question test you can apply to any vendor, the specific categories that almost always require an agreement, the exceptions people misapply, and what "we have a BAA" needs to look like in your files to count as evidence.

Who Needs a Business Associate Agreement? The Short Answer

You need a business associate agreement with any person or organization outside your workforce that creates, receives, maintains, or transmits protected health information to perform a function or service on your behalf. That's the standard in 45 CFR 164.502(e) and 164.308(b). If PHI moves to them so they can do a job for you, sign an agreement before the data moves.

You do not need one with:

  • Members of your own workforce, including W-2 staff and contractors under your direct control
  • Another covered entity receiving PHI for that entity's own treatment purposes — a referral, a lab requisition, a specialist consult
  • True conduits that merely transport data without accessing it beyond what transport requires
  • Financial institutions processing payment transactions (authorizing, clearing, settling a card charge)
  • Vendors with only incidental, unintended exposure to PHI — the cleaning crew, the HVAC tech

HHS maintains a plain-language explanation of the definition and the exceptions on its business associates guidance page. Read it once a year; it settles most internal arguments.

The Two-Question Test You Run on Every Vendor

Stop trying to memorize categories. Ask two questions in order.

Question 1: Can they get to PHI in the course of doing their job?

"Can they" is broader than "do they." Your IT managed service provider may never open a chart, but they hold domain admin credentials. Your off-site storage company may never unseal a box, but they possess it. Access capability is enough.

The answer is yes for anyone with a login to your practice management system, anyone who receives a file export, anyone who takes custody of paper, and anyone whose software sits in the path of clinical or billing data.

Question 2: Are they doing it on your behalf?

This question separates business associates from other covered entities. When you send imaging to a radiology group so they can render their own professional service to the patient, that's a treatment disclosure — no agreement required. When you send the same images to a vendor who stores, indexes, and returns them to you, that vendor is working on your behalf. Agreement required.

Two yeses means you need a signed agreement in place before PHI flows. One yes and one no means document your reasoning in writing, date it, and keep it with your vendor file. Undocumented judgment calls are the ones that fall apart under questioning.

Vendor Categories That Almost Always Require an Agreement

Work down this list against your AP ledger. Most practices find at least two gaps.

  • Billing and revenue cycle companies. They live inside your claims data.
  • Collection agencies. Yes, even for balances only — account holder plus service date plus provider name is PHI.
  • EHR, practice management, and patient portal vendors, including anything with a patient-facing scheduling or intake form.
  • IT support, managed service providers, and remote monitoring tools. Credentialed access counts.
  • Cloud hosting, backup, and file-sharing platforms.
  • Email and secure messaging providers when they store message content.
  • Transcription and scribe services, including AI-assisted documentation tools.
  • Answering services and after-hours triage lines.
  • Interpreters and translation vendors engaged as outside contractors.
  • Shredding, document destruction, and off-site record storage.
  • Device and hard-drive disposal / e-waste recyclers.
  • Attorneys, accountants, and consultants who review records or claims data.
  • Data analytics, population health, quality reporting, and registry submission vendors.
  • Patient satisfaction survey and reputation management vendors.
  • Marketing agencies or web developers with access to form submissions, intake data, or portal analytics.
  • Clearinghouses, which are covered entities in their own right but act as business associates when handling your transactions.
  • Health information exchanges and interoperability intermediaries.

If you are staring at a list like this and realizing you have four vendors operating without paper, that is the moment to fix it rather than schedule a meeting about it. A signature-ready business associate agreement generator walks you through a six-step wizard and exports PDF and DOCX so you can send the same reviewed language to every vendor in an afternoon — one-time purchase, no subscription. Consistent language across your whole vendor list is also easier to defend than a folder of whatever each vendor's sales team sent you.

The Exceptions Operators Get Wrong Most Often

The conduit exception is narrower than your vendor claims

HHS reads the conduit exception to cover entities that transport data without accessing it other than randomly or incidentally — the postal service, private couriers, and telecommunications carriers moving packets. A vendor that stores your data, even briefly, even encrypted, is not a conduit. Storage implies persistence and access capability, and that puts them squarely in business associate territory.

Fax lines run over telecom infrastructure are generally conduits. Cloud fax services that hold received documents in a web inbox are not.

"We're encrypted and we don't hold the keys" does not exempt anyone

This is the most common vendor pushback, and it's wrong. OCR's cloud computing guidance states plainly that a cloud service provider that maintains encrypted PHI is a business associate even if it lacks the decryption key. No-view services are still business associates. Point vendors to that page when they push back; it ends the conversation quickly.

Contractors inside your workforce are not business associates

A locum physician, a temporary front-desk hire, or a per-diem coder who works under your direct control and follows your policies is workforce, not a business associate. Your evidence for that position is a personnel-style file: signed confidentiality attestation, your training record, and role-based access provisioning. If you can't produce those, you're describing a business associate with extra steps.

Payment processing versus revenue cycle

The card processor that authorizes and settles a copay charge is excluded. The company that posts payments, works denials, and calls patients about balances is a business associate. Same money, different function.

Subcontractors: The Chain Doesn't Stop at Your Vendor

Since the 2013 Omnibus Rule, business associates are directly liable under HIPAA and must obtain their own written agreements with subcontractors who handle PHI on their behalf. Your billing company's offshore coding partner, your EHR vendor's hosting provider, your transcription vendor's cloud storage — all require downstream agreements.

You do not sign those agreements yourself, and you should not try. What you owe is the flow-down obligation in your own agreement plus a reasonable question during diligence: which subcontractors handle our PHI, and do you have executed agreements with each of them? Get the answer in email. File it. Ask again at renewal.

If a vendor cannot name its subprocessors, that is a finding worth escalating to whoever signs the contract.

What Counts as Documented Evidence

"We have a BAA" is not evidence. An investigator or an auditor wants to see specific things.

  • A fully executed copy — both signatures, both dated. Unsigned templates and vendor click-through terms with no record of acceptance are recurring findings.
  • An effective date that precedes the first PHI disclosure. Backdating is worse than the original gap.
  • The required provisions from 45 CFR 164.504(e): permitted uses and disclosures, safeguards obligation, breach and security incident reporting, subcontractor flow-down, support for individual access and amendment requests, accounting of disclosures, HHS access to records, and return or destruction of PHI at termination.
  • A breach notification clock you can actually work with. The regulatory floor is notice without unreasonable delay and no later than 60 days after discovery. Sixty days consumes your entire 60-day patient notification window. Negotiate 5 to 10 calendar days and put it in writing.
  • Retention for six years past the later of creation or last effective date, per 164.316(b)(2).

HHS publishes sample business associate agreement provisions. Treat them as a floor, not a finished contract — they deliberately omit indemnification, insurance, breach cost allocation, and audit rights, all of which you want.

A Two-Week Workflow to Close Your Gaps

Assign owners. Unowned inventories don't get built.

Days 1–3: Build the list from money, not memory

Your practice manager exports 24 months of vendor payments from accounting. Your IT lead exports every third-party integration, API connection, and external user account from the EHR and network. Merge them. The overlap is small and the non-overlap is where the surprises live — the subscription someone expensed on a card, the analytics script a web contractor added to your intake page.

Days 4–7: Classify and triage

Your privacy officer runs the two-question test on each line and marks it BAA Required, Not Required with documented reason, or Needs Clarification. Sort the Required column by PHI volume and sensitivity. That's your outreach order.

Days 8–14: Paper and escalate

Send your agreement to every vendor in the Required column that lacks one. Track outreach date, response date, and execution date in the same spreadsheet. Vendors who refuse to sign, insist their terms of service suffice, or go silent for two weeks get escalated to the physician or administrator who controls the contract — with a written replacement recommendation attached.

Then set the recurrence: quarterly reconciliation against new AP entries, annual review of every executed agreement, and immediate review at any material change in what a vendor does with your data. Your risk analysis and policy set should reference this inventory directly; if you're rebuilding that documentation too, an automated HIPAA risk analysis and policy platform keeps the vendor inventory tied to the rest of the record.

What OCR Has Actually Penalized

Missing agreements have driven standalone settlements, not just add-on findings. A North Carolina orthopaedic practice settled for $750,000 in 2016 after releasing X-ray films to a vendor without an agreement in place. A pediatric specialty practice settled for $31,000 in 2017 over a missing agreement with a records storage company — a small figure that still bought a corrective action plan and years of oversight.

The pattern in the OCR breach portal is worth noting too: a substantial share of large breaches originate at business associates, not at the covered entity. The vendor's incident becomes your notification obligation, your patient letters, and your name in the public listing.

The Proposed Change Sitting on the Horizon

HHS published a proposed Security Rule update in January 2025 that would, among other things, require business associates to provide covered entities with written verification — certified by a subject matter expert — that required technical safeguards are deployed, on an annual basis. It also proposes tighter timelines for business associates to notify covered entities when contingency plans activate.

As of December 2025 that rule is not final, and nothing in it is enforceable yet. But the direction is clear: verification, not just promises. Practices that already collect annual attestations from vendors will absorb the change with a calendar reminder. Practices that can't produce a current vendor list will absorb it as a project.

Start With the Gaps You Already Know About

You probably already suspect three or four vendors on your list are operating without paper. Answering that question — who needs a business associate agreement in your specific practice — takes an afternoon with your AP export and the two-question test above.

When you know the names, generate a signature-ready business associate agreement for each one, send them out, and track executions in the same sheet you built the inventory in. One-time purchase, PDF and DOCX export, no subscription to manage. Then put the quarterly reconciliation on your calendar so this is the last time you have to start from scratch.