Which Vendors Need a HIPAA BAA? A Practical Checklist with Examples

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Which Vendors Need a HIPAA BAA? A Practical Checklist with Examples

Kevin Henry

HIPAA

August 08, 2026

9 minutes read
Share this article
Which Vendors Need a HIPAA BAA? A Practical Checklist with Examples

If you handle Protected Health Information (PHI), you must know exactly which vendors need a HIPAA Business Associate Agreement (BAA). This practical guide shows you how to decide quickly, verify requirements, and document a defensible rationale—complete with real‑world examples and checklists.

Your goal is simple: ensure every partner that creates, receives, maintains, or transmits PHI on your behalf signs a BAA and can meet the HIPAA Privacy Rule and HIPAA Security Rule. When a BAA is not possible, redesign the workflow to remove PHI—or choose a different vendor.

Definition of Business Associate Agreement

A Business Associate Agreement is a contract that governs how a vendor (a “business associate”) may handle your PHI. It defines permitted uses and disclosures, mandates safeguards aligned to the HIPAA Security Rule, and sets breach‑notification duties under the HIPAA Privacy Rule. Without a signed BAA, a vendor cannot lawfully receive PHI for covered functions.

Core elements a BAA should include

  • Permitted and prohibited uses of PHI, with “minimum necessary” limits.
  • Administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.
  • Breach notification timelines, content, and cooperation duties.
  • Flow‑down obligations to subcontractors that handle PHI.
  • Access, amendment, and accounting support to help you meet patient rights.
  • Return or secure destruction of PHI at termination; data retention boundaries.
  • Audit and reporting rights; incident and vulnerability disclosure expectations.

What counts as PHI?

PHI is individually identifiable health information in any form (paper, oral, electronic) that relates to health status, care, or payment and can identify a person. It includes obvious identifiers (name, SSN) and operational data (medical record numbers, device IDs, full‑face photos, appointment details, IPs tied to patients) when linked to health context.

When a BAA is typically not required

  • Data is properly de‑identified under HIPAA standards before the vendor receives it.
  • The vendor is your workforce member (employee) rather than an external entity.
  • The vendor is a true “conduit” that merely transports data in transient form without storage or access (a narrow exception).
  • Services that never touch PHI because you designed the workflow to exclude it (e.g., marketing emails that avoid health context and identifiers).

Identifying Vendors Handling PHI

Do not rely on job titles or product categories. Map data flows and ask, “Does this vendor create, receive, maintain, or transmit PHI for us?” If yes—or even if they could reasonably access PHI—treat them as a business associate.

Fast triage checklist

  • Describe the exact data exchanged, including logs, backups, screenshots, and support tickets.
  • Decide whether any field or context makes a record identifiable as patient‑related.
  • Assess potential access: admin consoles, support screens, or debugging traces that reveal PHI.
  • Confirm subcontractors (hosting, analytics, transcription) that the vendor uses.
  • Choose a path: (1) sign a BAA, (2) remove/transform PHI before sharing, or (3) replace the vendor.

Examples

  • BAA required: EHR platforms, claims clearinghouses, revenue‑cycle/billing services, e‑fax/scan vendors for records, medical transcription, care‑management tools, contact centers scheduling named patients, legal or consulting firms reviewing charts.
  • BAA required if PHI is present: SMS/email reminders that include patient identity and care details; data integrations that sync patient lists; IT managed services with admin access.
  • Often not BAAs: postal carriers or true transient carriers; vendors engaged only with de‑identified datasets you prepared.

BAA Requirements for Cloud Infrastructure Providers

Cloud Infrastructure HIPAA Compliance hinges on two things: a signed BAA and correct architecture. Most large IaaS providers offer BAAs, but you must use HIPAA‑eligible services and configure security controls under a shared‑responsibility model.

Shared‑responsibility essentials

  • Provider: physical security, certain platform controls, and contractual assurances in the BAA.
  • You: risk analysis, network segmentation, identity and access management, encryption choices, logging/monitoring, backup and disaster recovery, and vendor oversight.

Cloud BAA implementation checklist

  • Execute the BAA and restrict workloads to the provider’s HIPAA‑eligible services.
  • Isolate PHI into dedicated accounts/projects; enforce least‑privilege IAM and MFA.
  • Encrypt in transit and at rest; manage keys (KMS or BYOK) with rotation and access logging.
  • Harden storage: block public access by default; lifecycle policies to control retention and deletion.
  • Enable audit logs, access logs, and security alerts; document monitoring thresholds and response playbooks.
  • Protect backups and snapshots; test restores; define RTO/RPO; include cross‑region replication controls.
  • Document data flows, subcontractors, and breach‑notification paths in your vendor inventory.

Common pitfalls

  • Using non‑eligible cloud services for PHI (e.g., ad or public analytics features).
  • Leaky object storage, unmanaged temporary files, or debug logs exposing PHI.
  • Mixing test and production PHI without strict access boundaries and masking.

BAA in AI Tools and Platforms

AI systems often ingest prompts, transcripts, images, or metadata that can contain PHI. To achieve AI Healthcare Vendor Compliance, require a BAA that tightly controls data use and visibility—especially around model training and human review.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

What your AI BAA should state explicitly

  • No training, fine‑tuning, or evaluation on your PHI unless you provide written, revocable authorization.
  • Clear data‑retention limits, secure deletion, and options for dedicated or single‑tenant environments.
  • Access controls that prevent vendor personnel from viewing PHI except under audited, least‑privilege support workflows.
  • Segregation of your data; no commingling across customers; documented subcontractors and regions.
  • Robust breach reporting and assurance of Security Rule–aligned safeguards.

Operational safeguards for AI use

  • Assume prompts and context windows may persist in logs; enable log redaction or anonymization.
  • Disable chat histories for PHI or route through a HIPAA‑configured gateway.
  • Prefer private endpoints, dedicated instances, and PHI‑aware DLP/redaction before inference.
  • Validate outputs for hallucinations; prohibit reproduction of other patients’ data in generated text.

Examples

  • Not acceptable: consumer chatbots without BAAs or that use inputs for training.
  • Acceptable with controls: a vendor that signs a BAA, provides a HIPAA‑configured private model endpoint, disables human review, and enforces short retention with auditable deletion.

BAA Availability in SaaS Vendors

SaaS HIPAA Compliance varies widely. Many SaaS vendors will sign a BAA only on specific “HIPAA” or enterprise plans, and some do not support PHI at all. Always confirm BAA availability early to avoid rework.

Where BAAs are commonly available

  • Telehealth platforms, secure messaging/portal tools, e‑signature built for healthcare, practice management, e‑prescribing, revenue‑cycle, and patient‑engagement systems.

Where BAAs are rare

  • Advertising networks, social media tools, generic analytics/behavioral tracking, and free‑tier productivity apps. If no BAA is offered, do not share PHI.

SaaS due‑diligence checklist

  • Confirm a signed BAA and review the list of covered features; disable non‑covered add‑ons.
  • Verify role‑based access, MFA, SSO, and audit logs; restrict support access.
  • Define data export, termination assistance, and deletion SLAs.
  • Review retention in backups, search indexes, and observability tools.
  • Test configurations in a staging tenant with synthetic data before go‑live.

Compliance in AI Therapy Scribe Vendors

Therapy scribes record or transcribe sessions to draft clinical notes. Because these workflows capture highly sensitive mental‑health information, you should treat them as business associates and demand strong safeguards.

Special considerations for mental‑health documentation

  • Psychotherapy notes have extra protections and are usually kept separate from the designated record set; ensure the vendor can segment and control access.
  • If you handle substance use disorder treatment information, additional federal protections may apply; confirm the vendor can support required consent and segmentation workflows.
  • Establish clear patient consent for recording; consider state two‑party consent laws.
  • Offer recording alternatives when patients decline; document your process in the record.

Therapy scribe vendor checklist

  • Executed BAA; explicit “no training on PHI” and no human review unless authorized.
  • Device and transport encryption; secure storage; short retention; reliable deletion.
  • Private processing endpoints; comprehensive access logs; clinician‑controlled redaction.
  • Configurable templates (e.g., SOAP) without auto‑inserting unverified details.
  • Incident response commitments; rapid breach notification; ongoing security testing.

Evaluating AI Health Vendor HIPAA Posture

Build a repeatable vendor‑risk process so you can demonstrate AI Healthcare Vendor Compliance and sound HIPAA governance.

Due‑diligence framework

  • Prescreen: ask if they will sign a BAA and whether PHI‑handling features are in scope.
  • Security questionnaire: architecture, eligible services, retention, encryption, identity, logging.
  • Contracting: BAA plus addenda for “no training,” data‑location limits, subcontractor disclosures, and audit rights.
  • Validation: run a limited pilot with synthetic data; verify logs, access controls, and redaction.
  • Go‑live controls: least‑privilege access, DLP, alerts, playbooks, and user training.
  • Ongoing monitoring: review reports, breach notices, pen‑test summaries, and change logs annually.

Practical checklist with examples

  • Cloud compute or storage hosting PHI → BAA required; use HIPAA‑eligible services only.
  • Appointment reminder SMS including patient name and visit type → BAA required; template for minimum necessary.
  • Analytics on de‑identified data only → BAA often not required; validate de‑identification method.
  • Law firm or consultant reviewing charts → BAA required; limit access to case scope.
  • True conduit (transient transport only) → BAA typically not required; verify no storage/access.
  • Consumer AI chatbot without BAA → Do not input PHI; use a HIPAA‑configured alternative.

Common pitfalls to avoid

  • Assuming “enterprise‑grade” equals HIPAA compliance without a signed BAA.
  • Letting PHI leak into tickets, screenshots, logs, or demo environments.
  • Mixing HIPAA and non‑HIPAA features in the same tenant without guardrails.

Conclusion

The fastest path to compliance is consistent triage: inventory vendors, map PHI flows, require BAAs where PHI is handled, and configure controls that match the HIPAA Privacy Rule and HIPAA Security Rule. When a vendor cannot sign a BAA, remove PHI or find one that can.

FAQs.

What is a HIPAA Business Associate Agreement?

A HIPAA BAA is a contract that allows a vendor to handle your PHI under strict rules. It defines permitted uses, mandates Security Rule safeguards, requires breach notification, and flows obligations to subcontractors. Without it, a vendor cannot lawfully receive PHI for covered functions.

Which vendors must sign a BAA?

Any vendor that creates, receives, maintains, or transmits PHI on your behalf—for treatment, payment, or healthcare operations—must sign a BAA. Examples include EHRs, billing services, telehealth platforms, transcription, cloud hosting for PHI, contact centers, and consultants who review records.

Do all cloud providers offer BAAs?

No. Many large providers do, but typically only for specific HIPAA‑eligible services and often on higher‑tier agreements. Even with a BAA, you must architect controls—encryption, access, logging, backups—to meet Cloud Infrastructure HIPAA Compliance.

How do AI tools comply with HIPAA requirements?

AI tools must sign a BAA, restrict data use (no training on your PHI without explicit authorization), limit retention, control human access, log all activity, and provide secure processing options. You should also redact PHI when possible and disable features that store prompts or share data across customers.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles