When Does a Pharmacy Benefit Manager Need a BAA with a Specialty Clinic? HIPAA Rules Explained

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

When Does a Pharmacy Benefit Manager Need a BAA with a Specialty Clinic? HIPAA Rules Explained

Kevin Henry

HIPAA

September 01, 2026

9 minutes read
Share this article
When Does a Pharmacy Benefit Manager Need a BAA with a Specialty Clinic? HIPAA Rules Explained

HIPAA Business Associate Agreement Requirements

A Pharmacy Benefit Manager (PBM) needs a Business Associate Agreement (BAA) with a specialty clinic only when the PBM creates, receives, maintains, or transmits Protected Health Information (PHI) to perform services on the clinic’s behalf. In that scenario, the PBM acts as the clinic’s business associate, and a BAA is mandatory for HIPAA Compliance.

A BAA is not required when the PBM is acting for a health plan (its typical role) and exchanges PHI with the clinic for treatment, payment, or health care operations (TPO) permitted under HIPAA between Covered Entities. In those cases, each party remains responsible for its own HIPAA obligations without a direct BAA between them.

Key definitions that drive the BAA decision

  • Covered Entity: a health plan, health care clearinghouse, or health care provider (such as a specialty clinic) that transmits health information electronically for standard transactions.
  • Business Associate: a person or entity that performs functions or services for a Covered Entity involving PHI (e.g., claims processing, data analysis, utilization review).
  • PHI: individually identifiable health information in any form or medium that is created or received by a Covered Entity or Business Associate.

Common outcomes

  • No BAA needed: PBM manages formulary, claims adjudication, prior authorization, or utilization management for a health plan and shares PHI with the clinic for TPO as allowed between Covered Entities.
  • BAA required: PBM is retained by the clinic to perform services involving PHI (e.g., benefits investigations, patient support programs, revenue cycle work, or data analytics) on the clinic’s behalf.
  • Alternative structures: No BAA between PBM and clinic if both operate as part of a single Covered Entity, an Affiliated Covered Entity, or an Organized Health Care Arrangement—governance and internal HIPAA policies apply instead.

Pharmacy Benefit Manager Roles and Responsibilities

PBMs typically serve health plans by negotiating formularies, processing pharmacy claims, managing networks, handling prior authorizations, and operating specialty pharmacy services. In that primary role, the PBM is usually a Business Associate of the plan—not of the clinic—and PHI sharing with clinics often fits within Permitted Uses and Disclosures for TPO between Covered Entities.

When a PBM is directly engaged by a specialty clinic as its business associate, the PBM’s responsibilities under a BAA expand. The PBM must follow the clinic’s instructions, limit PHI use to the contracted scope, apply robust Safeguard Requirements, report incidents, and flow down the same requirements to its subcontractors.

Examples of PBM activities that can make it a clinic’s Business Associate

  • Running adherence or patient support programs under the clinic’s direction and using the clinic’s PHI.
  • Performing eligibility, benefits, or prior authorization coordination specifically on the clinic’s behalf rather than the plan’s.
  • Providing analytics, dashboards, or population health reports that use the clinic’s PHI for the clinic’s operations.
  • Assisting with the clinic’s revenue cycle tasks, such as coding support or claims resubmissions, using PHI supplied by the clinic.

Specialty Clinic Compliance Obligations

As a Covered Entity, a specialty clinic must determine whether a PBM is performing functions for the clinic involving PHI. If yes, the clinic must execute a BAA before any PHI is shared. If the PBM acts for a health plan and interacts with the clinic only for TPO, a BAA with the clinic is generally unnecessary.

Practical steps for clinics

  • Map data flows: identify who is directing the work, whose PHI is used, and the purpose (treatment, payment, operations, or a service on the clinic’s behalf).
  • Right instrument for the right data: use a BAA for Business Associate services; use a Data Use Agreement for a Limited Data Set; no agreement is needed for de-identified data.
  • Enforce minimum necessary: disclose only the PHI necessary to accomplish the task, even when disclosures are permitted.
  • Vet vendors: assess security posture, breach history, and compliance program; ensure subcontractor management and incident response are mature.

Timing of BAA Execution

A BAA must be fully executed before the PBM accesses, receives, or uses PHI to perform work for the clinic. Neither an NDA nor a services agreement alone satisfies HIPAA’s Business Associate requirements.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Timing best practices

  • Before pilot programs or demos using live PHI: execute the BAA first, or use de-identified data instead.
  • During scoping: when possible, rely on mock or de-identified data until the BAA is signed.
  • Upon service changes: amend the BAA if the PBM’s scope, systems, or subcontractors change in ways that affect PHI.
  • At termination: require return or destruction of PHI, or documented infeasibility with ongoing protections.

Essential BAA Provisions

Your BAA should be precise, operationally testable, and aligned with HIPAA’s required elements. The following provisions address Permitted Uses and Disclosures, Safeguard Requirements, and Breach Notification Procedures.

Core, HIPAA-required terms

  • Permitted Uses and Disclosures: specify what the PBM may do with PHI; prohibit uses not expressly allowed.
  • Minimum Necessary: require role-based access, data minimization, and purpose limitation.
  • Safeguards: mandate administrative, physical, and technical controls consistent with the HIPAA Security Rule.
  • Breach Notification Procedures: obligate the PBM to report breaches and security incidents without unreasonable delay and set a clear outside deadline.
  • Subcontractors: require flow-down obligations and written assurances from any PBM subcontractor that handles PHI.
  • Individual Rights Support: ensure the PBM assists with access, amendment, and accounting of disclosures.
  • HHS Access: require cooperation with investigations and audits.
  • PHI Return/Destruction: on termination, return or destroy PHI, or protect it if destruction is infeasible.
  • Termination for Cause: allow the clinic to end the agreement if the PBM violates material terms.
  • Defined breach reporting timeline to the clinic (e.g., 5–15 days from discovery) and required incident details.
  • Cybersecurity standards reference (e.g., encryption in transit/at rest, vulnerability management, multifactor authentication).
  • Right-to-audit and evidence delivery (risk analyses, penetration testing summaries, workforce training attestations).
  • Insurance requirements, indemnification, and subcontractor approval rights.
  • Data retention limits and secure disposal methods.

PHI Safeguarding and Breach Notifications

Safeguard Requirements should translate into daily practice. Expect the PBM to perform periodic risk analyses, implement least-privilege access, train its workforce, and maintain auditable controls. Technical safeguards should cover encryption, endpoint protection, logging and monitoring, secure software development, and tested backups.

Operational safeguards to require

  • Access governance: unique IDs, multifactor authentication, timely provisioning and deprovisioning, and quarterly access reviews.
  • Network and system security: encryption at rest and in transit, segmentation, patching SLAs, and vulnerability scanning with remediation.
  • Data handling: minimization, role-based views, de-identification when possible, and secure data transfer protocols.
  • Vendor oversight: due diligence on subcontractors and written flow-down terms; continuous monitoring for high-risk vendors.

Breach Notification Procedures—what “good” looks like

  • Immediate triage and containment, then a documented risk assessment for any impermissible use or disclosure.
  • Notification to the clinic without unreasonable delay and within a contractually defined outer limit; include what happened, PHI types involved, affected individuals, mitigation steps, and corrective actions.
  • Coordination so the clinic can meet its own HIPAA notification timelines to individuals, regulators, and (if applicable) the media.
  • Post-incident review and preventive enhancements with target dates and accountable owners.

Regulatory Guidance and Sample BAA Provisions

HIPAA’s Privacy, Security, and Breach Notification Rules set the baseline. Your BAA should closely track those requirements and clarify real-world responsibilities, escalation paths, and documentation expectations.

Sample BAA clause snippets (customize as needed)

  • Permitted Uses and Disclosures: “PBM may use and disclose PHI solely to perform the Services described herein for Clinic and as required by law; all other uses or disclosures are prohibited.”
  • Minimum Necessary: “PBM will limit PHI to the minimum necessary and implement role-based access aligned to job duties.”
  • Safeguards: “PBM will implement administrative, physical, and technical safeguards appropriate to the risk to ensure the confidentiality, integrity, and availability of PHI.”
  • Breach Reporting: “PBM will notify Clinic of any breach of unsecured PHI or security incident without unreasonable delay and no later than [X] days after discovery, with details sufficient for Clinic’s notifications.”
  • Subcontractors: “PBM will ensure that any subcontractor agrees in writing to restrictions and conditions at least as stringent as those in this Agreement.”
  • Return/Destruction: “Upon termination, PBM will return or destroy all PHI received from Clinic, or if infeasible, extend protections and limit further uses to those that make return or destruction infeasible.”

Conclusion

A PBM needs a BAA with a specialty clinic only when it performs services involving the clinic’s PHI on the clinic’s behalf. If the PBM is acting for a health plan and exchanges PHI with the clinic for TPO between Covered Entities, a direct BAA is usually unnecessary. Use targeted Permitted Uses and Disclosures, rigorous Safeguard Requirements, and clear Breach Notification Procedures to keep HIPAA Compliance practical and defensible.

FAQs

When is a BAA legally required between a PBM and specialty clinic?

A BAA is required when the PBM creates, receives, maintains, or transmits PHI to perform services for the clinic (e.g., patient support, eligibility checks, or analytics directed by the clinic). If the PBM is acting for a health plan and shares PHI with the clinic for TPO between Covered Entities, a PBM–clinic BAA is generally not required.

What specific HIPAA rules govern PBM and specialty clinic relationships?

The HIPAA Privacy Rule governs Permitted Uses and Disclosures; the Security Rule sets Safeguard Requirements for electronic PHI; and the Breach Notification Rule defines reporting duties. BAAs operationalize these rules by specifying limits on PHI use, safeguards, subcontractor flow-downs, and notification timelines.

How should PHI be protected under a BAA?

Require risk-based administrative, physical, and technical safeguards, including encryption in transit and at rest, least-privilege access, workforce training, logging and monitoring, vendor oversight, and tested incident response. The BAA should mandate prompt breach reporting with sufficient detail for the clinic’s regulatory notifications.

When must a BAA be signed before exchanging PHI?

Before the PBM accesses any PHI to perform services on the clinic’s behalf. Use de-identified data or a Limited Data Set with a Data Use Agreement during scoping if you must proceed prior to execution, and amend the BAA promptly if the service scope or data flows change.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles