Back to Blog
Compliance6 min read

Business Associate Agreements: What to Look For Before You Sign

A BAA is more than a checkbox. The terms you accept define your liability, your notification timeline, and what happens when something goes wrong.

Business Associate Agreements are required by HIPAA before you share protected health information with a vendor. Most covered entities know they need them. Far fewer know what to look for when reviewing one — or what happens when a vendor's standard BAA contains terms that shift liability in ways the covered entity didn't expect.

Who Is a Business Associate?

A Business Associate is any person or organization (other than a member of your workforce) that creates, receives, maintains, or transmits PHI on your behalf. The "on your behalf" part matters: they have to be doing it to perform a service for you, not incidentally.

Examples that often get missed:

  • EHR and practice management software vendors: Obviously BAs. Usually have BAAs ready.
  • Cloud storage providers (AWS, Azure, Google Cloud): If you're storing PHI there, they're BAs. All three major cloud providers offer BAAs for covered services.
  • IT managed service providers: If they have access to systems containing PHI — even just for maintenance — they're BAs.
  • Billing companies and medical coding services: Classic BAs.
  • Transcription services: Transcribing clinical notes means they receive PHI.
  • Attorneys reviewing patient records: Yes, even lawyers need BAAs if the work involves reviewing PHI.
  • Accountants analyzing revenue data linked to patient services: Depends on what data they're seeing.

Who is NOT a Business Associate:

  • Your workforce (employees and volunteers)
  • Other covered entities you refer patients to (the Privacy Rule covers treatment, payment, and operations disclosures between CEs)
  • Conduit providers who transmit but don't have routine access to PHI (the US Postal Service is the canonical example — your internet service provider generally falls into this category for encrypted data)

If you're unsure, ask: does this vendor have routine access to the PHI itself? If yes, you need a BAA.

What a BAA Must Contain

45 CFR §164.504(e)(2) specifies required provisions. A BAA that doesn't include all of these isn't compliant:

Permitted uses and disclosures: The BAA must specify what the BA is allowed to do with your PHI. Uses outside this list are prohibited. If your billing company's BAA says they can use PHI for their own operations without limitation, that's a problem.

Prohibition on unauthorized use or disclosure: The BA must agree not to use or disclose PHI other than as permitted by the BAA or required by law.

Appropriate safeguards: The BA must implement safeguards to protect ePHI. The Security Rule applies directly to BAs — this isn't just a contractual obligation, it's a regulatory requirement on them.

Subcontractor obligations: The BA must ensure that any subcontractors who will handle your PHI have BAAs in place. This is the "sub-BA" chain. If your EHR vendor stores data on AWS and AWS doesn't have a BAA with either of you, there's a problem. Ask vendors who their subcontractors are and what BAA arrangements they have.

Breach reporting: The BA must report any breach of unsecured PHI to you without unreasonable delay and no later than 60 days after discovery. This is where most BAAs are negotiated heavily — some vendors want longer windows, or want to define "discovery" in ways that extend the clock.

Return or destruction of PHI: Upon termination of the agreement, the BA must return or destroy all PHI and retain no copies. If return or destruction isn't feasible, the BA must extend the same protections going forward and limit further uses and disclosures.

Termination right: You must have the right to terminate the agreement if the BA violates a material term and doesn't cure the violation.

What to Review Before Signing

Most vendors have standard BAAs that are written to favor the vendor. That doesn't make them non-compliant, but it does mean you should read them carefully.

Breach notification timing: The regulation says 60 days, but your internal process may require faster notification. If an OCR investigation follows a breach, the 60-day clock starts when the BA discovers the incident — not when they tell you. A BA that takes 55 days to notify you leaves you with 5 days to complete your own investigation and notify individuals. Negotiate for shorter windows (10-30 days is reasonable) if you can.

Subcontractor chain: Does the BAA require the vendor to identify their subcontractors? Can you get a list? Some vendors resist this transparency. If a vendor processes PHI using subcontractors who don't have BAAs in their chain, your liability exposure doesn't disappear because the vendor signed your BAA.

Security standards: Does the BAA specify what security measures the BA must maintain? Generic "appropriate safeguards" language is the minimum. If you can get specific commitments — encryption at rest, MFA for admin access, annual security reviews — that's better. If you're a larger organization, you may have leverage to require this; smaller CEs often don't.

PHI return timeline on termination: When the agreement ends, how long does the vendor have to destroy your PHI? Some BAAs give vendors 90 days or more. That's 90 days of your patient data sitting with a former vendor. Shorter timelines protect you.

Limitation of liability: Vendors sometimes include liability caps in their BAAs. Be aware that OCR civil money penalties don't respect contractual liability caps — if a vendor's breach causes violations and OCR investigates, your regulatory exposure isn't capped by the vendor's contract. Indemnification clauses and liability caps affect civil litigation, not regulatory enforcement.

When a Vendor Won't Sign a BAA

If a vendor won't sign a BAA, you cannot legally share PHI with them. Full stop. This comes up frequently with consumer-grade SaaS tools — project management software, messaging apps, note-taking apps, email services.

The practical implication: if your clinical staff is using a tool that receives PHI, and that vendor won't sign a BAA, you have two options. Either stop using the tool for PHI-related activities, or find a vendor that will sign a BAA and offers equivalent functionality.

Many tools have HIPAA-compliant tiers specifically because they'll sign a BAA under those plans. Switching from the free version to a HIPAA Business Associate plan often solves the problem. Examples: Google Workspace (with HIPAA BAA), Zoom for Healthcare, certain Slack configurations.

The Enforcement Record

OCR has taken enforcement actions against covered entities for failing to have BAAs with their vendors:

  • Advocate Health Care Network (2016): $5.55M — among other violations, failed to have BAAs with business associates
  • Parkview Health System (2014): $800,000 — PHI sent to a physician's home without a BAA in place
  • MD Anderson Cancer Center (2018): $4.3M — encryption failures and unauthorized disclosures, BAA issues among findings

BAA failures aren't hypothetical. OCR finds them in investigations following breach reports.


SOURCES

  • 45 CFR §164.504(e) — Business Associate Contracts: ecfr.gov
  • HHS, "Business Associate Contracts": hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html
  • HHS, "Business Associates": hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
  • OCR HIPAA Enforcement — Settlement Agreements: hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
  • AWS HIPAA compliance and BAA information: aws.amazon.com/compliance/hipaa-compliance/

Reviewing your vendor BAAs or building a HIPAA compliance program? Schedule a consultation to talk through your vendor landscape.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch