Which Vendors in a Medical Practice Actually Need a HIPAA Business Associate Agreement (BAA)?
Definition of Business Associate
A Business Associate is any person or organization that creates, receives, maintains, or transmits Protected Health Information (PHI) on your behalf to perform a function or service regulated by HIPAA. If a vendor touches PHI for your practice’s operations, they are likely a Business Associate.
Subcontractors of your vendors also become Business Associates when they handle PHI, and they must agree to the same protections. By contrast, a “mere conduit” that only transmits information in a transient way without persistent storage is generally not a Business Associate.
Covered entities—healthcare providers, health plans, and healthcare clearinghouses—have their own HIPAA duties. When a covered entity performs services for your practice that involve your PHI (rather than its own), it can act as your Business Associate. The contract terms that govern this relationship are set out in 45 CFR 164.504(e).
Examples of Business Associates in Medical Practices
These common vendors usually require a HIPAA Business Associate Agreement because they handle PHI for your practice’s treatment, payment, or healthcare operations:
- Electronic Health Record (EHR) and practice management platforms.
- Cloud hosting, data backup, and disaster recovery providers that store or maintain ePHI.
- Medical billing, coding, revenue cycle firms, and claims clearinghouses (often also covered entities when acting for themselves).
- Transcription, medical scribing, and dictation services.
- Telehealth and secure video platforms used to deliver care.
- e-Prescribing, e-fax, and patient messaging/appointment reminder services that include PHI.
- Answering services, contact centers, and referral management vendors.
- IT managed service providers with system-level access, remote support, or device management touching PHI.
- Document scanning, record storage, and secure shredding/destruction companies.
- Data analytics, population health, quality reporting, and risk adjustment vendors using identifiable data.
Note: A cloud service provider that stores encrypted ePHI is still a Business Associate. Storage and maintenance of PHI—viewable or not—triggers BAA requirements.
Vendors Not Requiring a BAA
Not every third party needs a Business Associate Agreement. The following categories typically do not require one, provided they do not create, receive, maintain, or transmit PHI for you:
- Mere conduits: postal and courier services, and telecom/ISPs that only transmit data without routine access or storage.
- Banks and payment processors that process payments but do not need PHI beyond what is necessary for the transaction.
- Vendors with incidental, infrequent exposure and no system access to PHI (for example, janitorial or building maintenance), assuming your practice safeguards PHI appropriately.
- Vendors receiving only properly de-identified data; de-identified information is not PHI.
- Apps chosen directly by patients to receive their own records under right-of-access; those developers are not your Business Associates.
- Other covered entities (for example, health plans or laboratories) when exchanging PHI for treatment, payment, or healthcare operations as permitted by HIPAA rather than performing services on your behalf.
When in doubt, ask a simple question: does the vendor routinely create, receive, maintain, or transmit your patients’ PHI on your behalf? If yes, you need a BAA.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Importance of Business Associate Agreements
A HIPAA Business Associate Agreement is the mechanism that limits a vendor’s permitted uses of PHI and contractually obligates safeguards. It clarifies roles, security expectations, and breach notification obligations so you can respond quickly if something goes wrong.
BAAs also help demonstrate compliance during audits and investigations. OCR has pursued HIPAA enforcement actions where covered entities lacked required BAAs, leading to costly settlements and corrective action plans.
Key BAA Requirements
HIPAA requires specific Business Associate Agreement clauses under 45 CFR 164.504(e). Strong agreements generally include the following:
- Permitted uses of PHI: narrow, purpose-specific rights to use/disclose PHI, applying the minimum necessary standard.
- Safeguards: administrative, physical, and technical measures to protect PHI and comply with the Security Rule.
- Reporting: prompt reporting of security incidents and breach notification obligations without unreasonable delay (no later than 60 days from discovery), including required breach details.
- Subcontractors: flow-down terms so any subcontractor that handles PHI agrees to the same restrictions and safeguards.
- Individual rights support: cooperation to provide access, amendments, and an accounting of disclosures when you receive such requests.
- HHS/OCR access: agreement to make internal practices, books, and records relating to PHI available to the Secretary when required.
- Return or destruction: return or secure destruction of PHI at contract end, or continued protections if return/destruction is infeasible.
- Termination for cause: your right to terminate if the vendor materially breaches HIPAA obligations.
Recommended additions include cyber liability insurance requirements, incident response timelines beyond statutory minimums, audit and assessment rights, encryption and logging expectations, and explicit prohibitions on secondary uses of PHI not listed in the permitted uses of PHI.
Managing and Monitoring BAAs
Start with a complete vendor inventory and data flow map that identifies which third parties touch PHI, what type of PHI they handle, and for what purpose. Risk-rank vendors and require BAAs before onboarding or expanding services.
Perform due diligence: review security questionnaires and independent reports (for example, SOC 2 or ISO attestations), confirm access controls, and ensure Business Associate Agreement clauses align with your risk appetite. Build breach reporting and escalation paths into both the BAA and your incident response plan.
Centralize contract management so BAAs, amendments, and renewals are easy to track. Review BAAs at least annually or at each renewal, and whenever services, subcontractors, systems, or laws change. Verify that downstream subcontractors are covered and that data return/destruction is completed at offboarding.
Monitor performance through periodic attestations, targeted audits, and tabletop exercises involving your vendors. Keep training current for staff who select, manage, and oversee Business Associates so responsibilities are clear and consistently enforced.
Summary: Identify which vendors handle PHI, execute BAAs that meet 45 CFR 164.504(e), and continuously oversee compliance. This disciplined approach limits risk, speeds response to incidents, and protects your patients and practice.
FAQs
What is a Business Associate under HIPAA?
It is a person or organization that creates, receives, maintains, or transmits PHI for your practice to perform regulated functions or provide specific services. Because they handle your patients’ data, they must sign a BAA that defines permitted uses of PHI and required safeguards.
Which vendors require a Business Associate Agreement in healthcare?
Common examples include EHR and practice management vendors; cloud hosting, backup, and disaster recovery providers; billing and coding firms; transcription and scribing services; telehealth and secure messaging platforms; e-prescribing and e-fax services; answering services; IT managed service providers with access to ePHI; document scanning/storage/shredding; and analytics or quality reporting vendors using identifiable data.
What are the consequences of not having a BAA with a vendor?
Operating without a required BAA is a HIPAA violation. Your practice may face OCR investigations, HIPAA enforcement actions, monetary penalties, corrective action plans, breach notification costs, contractual disputes, and reputational harm if an incident occurs.
How often should BAAs be reviewed or updated?
Review BAAs at least annually or at contract renewal, and update them when services change, new subcontractors are added, systems or data flows shift, or regulations evolve. Revisit timelines for breach notification obligations and security controls as your risk posture changes.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.