The vendors you forgot to sign a BAA with
A business associate agreement is required with anyone who creates, receives, maintains or transmits protected health information on your behalf. In a modern practice that is a longer list than most people have written down — and the gaps are almost never the obvious vendors.
Under HIPAA, a covered entity — which a practice billing electronically almost certainly is — must obtain satisfactory assurances that a business associate will appropriately safeguard protected health information. Those assurances take the form of a written contract with specified terms.
Who is a business associate
The test is functional rather than categorical: does this entity create, receive, maintain or transmit PHI on your behalf, or provide services involving disclosure of PHI to them?
That sweeps in more than people expect:
- EHR and practice management vendors. Universally recognised.
- Billing services and clearinghouses. Also obvious.
- Cloud storage and backup providers holding any file containing PHI.
- Email providers, where PHI passes through business email.
- Transcription services, human or automated.
- AI documentation vendors — see AI scribe consent.
- Telehealth platforms.
- Answering services and virtual receptionists, who take names and reasons for calling.
- Scheduling and appointment-reminder tools.
- IT support and managed service providers with access to systems holding PHI.
- Document shredding and disposal companies.
- Outside accountants, attorneys and consultants where engagement involves PHI.
The vendors practices actually miss. Not the EHR — everyone signs that one. It is the appointment-reminder tool someone adopted because it was free, the transcription app on a personal phone, the survey platform used for intake questionnaires, and the marketing automation tool connected to the client list. Each entered the practice without a procurement conversation, and each is a business associate.
The conduit exception, which is narrow
Entities that merely transport information without accessing it other than incidentally — a postal service, a telecommunications carrier — are conduits rather than business associates.
The exception is genuinely narrow and is frequently over-read. It covers transient transmission, not storage. A cloud provider holding your files is not a conduit even if it never looks at them, because it maintains the data rather than transmitting it. If a vendor stores PHI, assume a BAA is required.
What the agreement must contain
HIPAA specifies required elements. A compliant BAA:
- Describes permitted and required uses and disclosures of PHI.
- Prohibits use or disclosure beyond what the contract or law permits.
- Requires appropriate safeguards, including Security Rule requirements for electronic PHI.
- Requires reporting of unauthorised uses or disclosures, including breaches.
- Requires that subcontractors handling PHI agree to the same restrictions.
- Provides for individual access, amendment and accounting of disclosures where applicable.
- Makes records available to HHS for compliance determination.
- Requires return or destruction of PHI at termination where feasible.
- Permits termination for material breach.
Subcontractor flow-down
The obligation follows the data. A business associate that engages a subcontractor to handle PHI must have a BAA with that subcontractor, and so on down the chain.
You do not sign agreements with your vendor's subcontractors — your vendor does — but you should know they exist. A practical due-diligence question worth asking any vendor: which subcontractors touch our data, and do you hold BAAs with all of them? A vendor that cannot answer clearly is telling you something.
A BAA is not a compliance programme
Worth stating plainly, because signing one produces a feeling of resolution it does not earn.
The agreement allocates responsibility contractually. It does not verify that the vendor is actually secure, and a breach at a business associate still involves your clients' information and still requires your notification analysis. Reasonable diligence — what security certifications a vendor holds, where data is stored, how access is controlled, what their breach history looks like — is a separate exercise from getting the contract signed, and it is the one that reduces actual risk.
Practical hygiene
- Keep an inventory. Every vendor touching PHI, the BAA date, and where the signed copy lives. Practices that cannot produce a BAA on request are, for practical purposes, in the same position as practices that never signed one.
- Review at renewal. Vendors change subprocessors and terms.
- Gate new tools. The single most effective control is a rule that no tool touching client information is adopted without a BAA in place first. This is unpopular and it prevents most of the gaps described above.
- Handle termination. When a vendor relationship ends, PHI should be returned or destroyed, and you should have evidence that it was.
What is not a business associate
Two categories worth knowing, because over-application wastes effort.
Other covered entities receiving PHI for their own treatment purposes are not business associates — a referral to a psychiatrist does not require a BAA, because they are treating the patient rather than performing a service on your behalf. Likewise, disclosures to a health plan for payment purposes do not create a business associate relationship.
Members of your workforce are not business associates either. Employees, volunteers and trainees under your direct control are covered by your own policies and training rather than by contract.
When a vendor has a breach
The scenario that tests whether the paperwork was ever more than paperwork.
A business associate breach involves your clients' information, and your obligations do not transfer with the data. The BAA should require the vendor to notify you without unreasonable delay and to provide the information you need — who was affected, what data, when, what they have done — because your own notification analysis and timelines depend on facts only they hold.
What practices discover at this point is whether their BAA specified a notification window or merely said "promptly," and whether they have any contractual right to the detail they now urgently need. Both are worth checking while nothing is happening.
The Security Rule sits alongside
BAAs address contractual assurance. The HIPAA Security Rule separately requires administrative, physical and technical safeguards for electronic PHI, and it applies to you regardless of what your vendors do.
The foundational requirement is a risk analysis — an actual assessment of where electronic PHI lives, what threatens it and what controls exist — reviewed periodically. It is the most commonly missing item in small-practice compliance and the first thing regulators ask for, because everything else in a security programme is supposed to follow from it.
Personal devices and shadow tools
The most common route by which PHI reaches a vendor with no BAA is not procurement — it is a clinician using something convenient on their own phone. A voice memo app, a notes app that syncs to a personal cloud account, a translation tool, a general-purpose AI assistant pasted a chunk of a session summary.
Each of those is a disclosure to a vendor with no agreement, and none of them will appear in any inventory. The control is a clear, specific policy about what may and may not touch client information, stated in terms of examples rather than principles, plus a practical alternative for each thing people were using the shadow tool to do.
Verified 29 July 2026. Federal rules cited here (HIPAA, 42 CFR Part 2, Medicare billing requirements) are supplemented and sometimes exceeded by state law, which varies substantially; professional licensing boards impose further obligations. Regulatory requirements in this area have changed repeatedly and continue to develop. Primary references: HHS HIPAA; 42 CFR Part 2; CMS billing guidance. This page is general reference, not legal advice. Decisions with compliance consequences warrant healthcare counsel licensed in your jurisdiction.