Do Telehealth Companies Need a Business Associate Agreement (BAA) Under HIPAA?
HIPAA Compliance Requirements for Telehealth
Whether you need a Business Associate Agreement depends on your role with Protected Health Information (PHI). If you deliver care as a provider or health plan, you are a Covered Entity. If you create, receive, maintain, or transmit PHI for a Covered Entity—such as operating a video platform, messaging tool, or cloud storage—you are a Business Associate and must have a BAA in place before PHI flows.
The HIPAA Privacy Rule governs how PHI may be used and disclosed, while the HIPAA Security Rule requires safeguards for electronic PHI. Telehealth companies should scope how PHI moves through scheduling, intake, video, chat, transcripts, recordings, and analytics. If any component touches PHI on behalf of a Covered Entity, a BAA is required for that component and its subcontractors.
Some direct-to-consumer apps may not be subject to HIPAA if they do not act for a Covered Entity; however, once your service integrates with a provider or plan and handles PHI on their behalf, HIPAA applies. Map your data flows and determine exactly where BAAs are needed to avoid gaps.
Business Associate Agreement Legal Obligations
A compliant BAA sets out the legal framework for PHI handling. It restricts uses and disclosures to those permitted by the Covered Entity or required by law, and it embeds the Security Rule’s safeguard obligations. It also requires you to report breaches and certain security incidents without unreasonable delay, ensure your subcontractors agree to equivalent protections, and meet the “minimum necessary” standard.
The BAA must address individuals’ rights that flow through the Covered Entity—such as access, amendment, and accounting of disclosures—and require you to make relevant records available to the Department of Health and Human Services upon request. At termination, you must return or destroy PHI, or, if that is infeasible, extend protections and limit further use. Material violation of the BAA enables the Covered Entity to terminate the arrangement.
Vendor Responsibilities under a BAA
Security safeguards under the HIPAA Security Rule
- Administrative: risk analysis, risk management, workforce training, sanctions, vendor management, and incident response planning.
- Technical: unique user IDs, multi-factor authentication, role-based access, encryption in transit and at rest, audit logs, integrity controls, and secure software development practices.
- Physical: facility access controls, device and media protections, secure disposal, and workstation security for remote teams.
Operational and contractual duties
- Report any impermissible use or disclosure of PHI, including breach notifications, within agreed timelines.
- Flow down BAA-equivalent terms to subcontractors that handle PHI on your behalf, including Telehealth Platform Vendors and cloud providers.
- Document policies and procedures and keep evidence of compliance activities, testing, and remediation.
- Apply data minimization so logs, analytics, and support workflows avoid unnecessary PHI exposure.
Privacy-by-design for telehealth
- Harden video, voice, chat, and file-sharing features to prevent leakage, including preventing PHI in URLs and masking sensitive fields in logs.
- Segment environments (production, staging, support) and use least-privilege access for staff and service accounts.
- Plan for business continuity and disaster recovery so encrypted backups and restores remain controlled and auditable.
BAA Execution and Customization
BAA Execution Process
- Scope and classify PHI: identify where PHI is created, stored, transmitted, or viewed across your telehealth workflow.
- Due diligence: exchange security questionnaires, architecture diagrams, and control attestations before PHI flows.
- Draft and sign: ensure authorized signatories execute the BAA before go-live; store the executed copy in a controlled repository.
Customization levers
- Permitted uses: clarify support, de-identification, and quality improvement; restrict marketing or product development unless expressly permitted.
- Breach timelines: the legal outer limit is 60 days after discovery; many Covered Entities require initial notice within 24–72 hours.
- Subcontractors: pre-approve critical vendors and require equivalent BAAs and security assurances.
- Data handling: define retention, return, destruction, and any rights to de-identified or aggregated data.
BAA Retention and Termination Policies
BAA Retention Requirements
HIPAA requires you to retain documentation—BAAs, policies, procedures, risk analyses, and evidence of implementation—for at least six years from the date of creation or last effective date, whichever is later. Many organizations keep BAAs longer to align with state contract or recordkeeping laws, but six years is the federal baseline.
Termination and wind-down
If a party materially breaches the BAA, the Covered Entity must take reasonable steps to cure the breach; if unsuccessful, it must terminate the contract. When services end, promptly return or securely destroy PHI. If destruction is infeasible—such as immutable backups—document why, limit further use to legal requirements, and maintain protections until secure disposal is possible.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Enforcement of BAA Provisions
You enforce BAA terms through clear remedies and ongoing oversight. Include rights to audit, require periodic security attestations, review penetration tests, and track remediation. Use SLAs and metrics for incident response, uptime, access reviews, and backup testing, with escalation paths for repeated non-compliance.
Maintain a sanctions policy for workforce violations, document all incidents and corrective actions, and conduct regular risk analyses. Contract enforcement happens between the parties, while HIPAA enforcement sits with federal regulators; strong documentation and timely reporting reduce regulatory exposure and strengthen your defense posture.
Protecting PHI in Telehealth Services
Foundational controls
- Encrypt data in transit and at rest; manage keys securely; avoid embedding PHI in logs, URLs, or analytics tags.
- Enable multi-factor authentication, session timeouts, device compliance checks, and automatic logoff for clinician and patient apps.
- Isolate video/media services, restrict recordings, and protect transcripts with strict access controls and audit trails.
Operational excellence
- Run secure release pipelines with code review, dependency scanning, and vulnerability patching SLAs.
- Test incident response with tabletop exercises covering breach assessment, notification, and forensics.
- Train support teams to handle PHI safely during troubleshooting and redact sensitive screenshots or files.
Conclusion
If you handle PHI for a Covered Entity, you need a Business Associate Agreement. A well-crafted BAA, paired with disciplined Security Rule controls, subcontractor management, and clear retention and termination practices, lets you deliver telehealth services that protect patients and reduce legal and operational risk.
FAQs
What is a Business Associate Agreement in telehealth?
A BAA is a contract that sets the rules for how a telehealth company, acting as a Business Associate, may create, receive, maintain, or transmit PHI for a Covered Entity. It defines permitted uses, required safeguards, breach reporting, subcontractor flow-downs, and end-of-term PHI return or destruction.
When is a BAA required for telehealth companies?
You need a BAA when your service handles PHI on behalf of a Covered Entity—such as hosting video visits, messaging, storage, or support that accesses PHI. If you operate purely direct-to-consumer without acting for a Covered Entity, HIPAA may not apply, and a BAA may not be required.
How do telehealth companies enforce BAA compliance?
Build enforcement into the contract and operations: reserve audit rights, require security attestations, set breach-notice timelines, and define remedies. Internally, run risk analyses, access reviews, training, and incident response drills, and document everything to show continuous compliance.
What are the consequences of not having a BAA under HIPAA?
Without a required BAA, both parties risk HIPAA violations, regulatory investigations, civil penalties, contractual disputes, and reputational harm. Missing BAAs also signal weak governance, which can aggravate enforcement outcomes after a breach or complaint.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.