EHR Marketplace Plugin BAA Checklist: What to Finalize Before Go Live

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

EHR Marketplace Plugin BAA Checklist: What to Finalize Before Go Live

Kevin Henry

HIPAA

July 08, 2026

7 minutes read
Share this article
EHR Marketplace Plugin BAA Checklist: What to Finalize Before Go Live

Verify BAA Execution

Before your EHR marketplace plugin touches any Protected Health Information, you need a fully executed Business Associate Agreement (BAA) covering every party that will access or process PHI. Confirm that the scope, permitted uses, and ePHI handling obligations match the real integration and data flows.

Parties you may need BAAs with

  • Covered Entity (healthcare organization) ↔ Plugin vendor (you or your supplier).
  • Covered Entity ↔ EHR platform, if not already in place.
  • Plugin vendor ↔ subcontractors (cloud hosting, analytics, support), with full flow-down terms.

What to confirm in the BAA

  • Effective date, signatures, and legal names match the production entities.
  • Permitted uses/disclosures, minimum necessary standards, and data de-identification or limited data set rules.
  • Administrative, physical, and technical safeguards (encryption, access controls, audit logging).
  • Breach and incident notification timelines, cooperation duties, and evidence preservation.
  • Subprocessor approval and flow-down; right to audit; cooperation with investigations.
  • Data return or destruction on termination; survival clauses; indemnification and insurance.

Artifacts to file before go live

  • Signed BAA (PDF) and any security addenda or marketplace terms.
  • Certificate of insurance and contact roster for incident, legal, and security leads.
  • System-of-record entry in your contract repository with renewal and notice dates.

If a BAA is not fully signed, do not enable PHI access, testing with live data, or production deployment.

Assess Vendor Compliance

Complete vendor due diligence to verify the plugin’s compliance posture aligns with HIPAA and your internal standards. Request evidence, validate controls in practice, and document remediation before production use.

Evidence to request

  • Security policies, workforce HIPAA training records, and role-based access procedures.
  • Independent assurance (e.g., SOC 2 Type II, HITRUST), recent pen test, and remediation results.
  • Architecture and data flow diagrams, encryption and key management approach, SSO/MFA details.
  • Incident response, breach notification playbooks, and business continuity/disaster recovery plans.

Operational controls to verify

  • Least-privilege access, periodic access reviews, and joiner/mover/leaver workflows.
  • Centralized logging with tamper resistance; alerting for anomalous PHI access.
  • Patch and vulnerability management cadence, secure SDLC, and secrets management.
  • Subprocessor list with active BAAs and data minimization for each service.

Due diligence outcomes

  • Risk rating with documented findings, owners, and target dates.
  • Go/no-go criteria tied to critical remediation (e.g., MFA, encryption, logging) before go live.

Inventory PHI Data Flows

Map how PHI and ePHI move between the EHR, the plugin, and any connected systems. Precise inventories reduce risk, prevent scope creep, and ensure the BAA and security controls match reality.

Define the data

  • List PHI elements (e.g., identifiers, clinical data, billing data) and categorize sensitivity.
  • Identify fields visible to users, stored in databases, or written to logs and caches.

Trace the movement

  • Document sources, APIs, queues, and storage locations (including backups and analytics).
  • Record transmission methods, encryption standards, and authentication mechanisms.

Retention and deletion

  • Set retention per data type; define deletion triggers and verification methods.
  • Ensure sandbox/test environments never contain production PHI unless governed by a BAA.

Access boundaries

  • Specify which roles can view, modify, or export PHI; enforce the minimum necessary.
  • Implement audit trails for user actions, API calls, and administrative overrides.

Review Integration BAA Requirements

Many EHR marketplaces impose integration-specific terms that intersect with BAAs. Align your implementation and customer contracts so permitted use, scopes, and disclosures remain consistent end-to-end.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Marketplace obligations to check

  • Approved use cases and data scopes; user consent and authorization requirements.
  • Audit rights, security attestations, penetration tests, and evidence submission cadence.
  • Notification duties to the EHR vendor for incidents, subprocessor changes, or material outages.

Contract alignment

  • Ensure your customer BAA does not permit broader uses than the marketplace allows.
  • Flow down all required terms to subcontractors; update privacy notices accordingly.

Regulatory nuances

  • Clarify handling of de-identified data and limited data sets; define re-identification bans.
  • Address cross-border processing and data residency if applicable.

Implement Compliance Tracking Tools

Establish a durable compliance workflow so obligations are tracked, evidenced, and renewed without manual scramble. Use lightweight tools if needed, but automate where possible.

Contract and BAA repository

  • Store executed BAAs with metadata: parties, effective dates, renewal terms, notice windows.
  • Automate reminders for renewals, audits, and security attestations.

Task and evidence management

  • Use a GRC or ticketing system to assign owners, due dates, and attach proof of control operation.
  • Standardize checklists for onboarding, change management, and annual reviews.

Security telemetry and access governance

  • Centralize logs in a SIEM; monitor for unusual exports, failed logins, and data spikes.
  • Enforce SSO, MFA, RBAC, and periodic access recertifications for all PHI-touching systems.

Go-live dashboard

  • Track critical gates: BAA execution, risk remediation, monitoring in place, runbook tested.
  • Publish status to stakeholders to prevent scope creep or premature launch.

Conduct Security Risk Analysis

Perform a documented Security Risk Analysis tailored to the plugin, systems, and workflows. Evaluate threats, vulnerabilities, likelihood, and impact, then plan and verify remediation before launch.

Scope and method

  • Inventory assets (APIs, databases, endpoints), data types, users, and integrations.
  • Assess controls against risks: authentication, authorization, encryption, logging, and resilience.
  • Record risks in a register with owners, treatment plans, and acceptance criteria.

Common findings and fixes

  • Overbroad API scopes or excessive data pulls → restrict to minimum necessary.
  • PHI in logs or analytics → scrub/redact and tighten access to observability tools.
  • Weak vendor oversight → formalize subprocessor reviews and BAA flow-downs.
  • Gaps in backup encryption or key rotation → implement and document lifecycle controls.

Finalize and sign off

  • Validate remediation; test incident and breach runbooks; confirm monitoring alert paths.
  • Executive sign-off that residual risk is understood and accepted.

Establish Renewal and Termination Procedures

Define BAA renewal management and termination steps now so you avoid lapses later. Clear procedures keep obligations current and ensure PHI is returned or destroyed properly at end of life.

Renewal playbook

  • Calendar renewal and notice dates; start reviews 90–120 days in advance.
  • Reassess vendor due diligence annually or upon major product changes.
  • Amend BAAs when data elements, subprocessors, or regions change.

Termination and offboarding

  • Disable integrations; revoke credentials and keys; lock data exports.
  • Return or destroy PHI, including backups per schedule; obtain certificates of destruction.
  • Retain required logs and evidence; document the closure in your risk register.

Go-Live Readiness Summary

  • All BAAs fully executed with accurate scope and flow-downs.
  • Vendor due diligence completed; critical findings remediated.
  • PHI data flows mapped; retention and deletion enforced.
  • Marketplace terms aligned with customer contracts.
  • Compliance workflow, monitoring, and dashboards operational.
  • Security Risk Analysis documented with sign-off.
  • Renewal and termination runbooks in place.

FAQs.

What is a BAA and why is it required before go live?

A Business Associate Agreement is a contract that sets how a vendor will safeguard Protected Health Information and support HIPAA obligations. You must have it in place before go live so the plugin’s use and disclosure of ePHI is lawful, limited to the minimum necessary, and subject to breach reporting and security safeguards.

How do you verify if an EHR plugin has a valid BAA?

Confirm a fully signed, current BAA that names the correct legal entities, matches the integration’s PHI scope, and includes safeguards, notification timelines, subcontractor flow-down, and data return or destruction terms. Store the executed document in your contract repository with renewal alerts.

What are the risks of missing a BAA for an EHR integration?

Operating without a BAA can create HIPAA violations, regulatory penalties, breach response liabilities, and contractual disputes. It also exposes you to uncontrolled ePHI handling, unclear incident duties, and difficulty terminating or proving proper PHI destruction.

How often should BAAs be reviewed and renewed?

Review BAAs at least annually and upon any material change to data flows, subprocessors, or functionality. Follow the contract’s renewal cycle, typically one to three years, and start your review 90–120 days before the renewal or notice window to avoid lapses.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles