Business Associate Agreements: The BAA Program, Done Right
Every vendor touching PHI needs a BAA — and most organizations have gaps. What a BAA must contain, the subcontractor trap, and how to inventory them.
Who needs a BAA
Any vendor that creates, receives, maintains, or transmits PHI on your behalf: EHR hosting, billing companies, cloud providers, shredding services, email hosting, answering services, data analytics firms. If PHI touches their systems, you need a signed BAA before — not after — they touch it. No BAA, no PHI sharing.
What a BAA must contain
- Permitted and required uses of PHI — what the BA may and must do with it.
- Safeguards: the BA must implement appropriate safeguards to prevent unauthorized use or disclosure.
- Subcontractor flow-down: the BA must get satisfactory assurances from any subcontractor handling the PHI.
- Breach notification: the BA must report breaches and security incidents — with timing that lets you meet your own notification deadlines.
- Termination provisions: what happens to PHI when the relationship ends — return or destroy.
Turn reading into quotes. Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes, no obligation.
Request quotesThe subcontractor trap
Your BAA is with your vendor. But if their subcontractor touches your PHI, that subcontractor is also a business associate — and needs its own BAA with your vendor. Chains of three or four are normal in cloud-hosted healthcare. Ask your vendors who their subprocessors are; most can't answer cleanly on the first try.
The inventory most orgs skip
Maintain a living BAA register: vendor, PHI involved, BAA signed date, renewal/termination terms, subprocessor list. Review it annually and whenever you onboard a vendor. Assessors ask for this inventory early — "we think legal has them somewhere" is not an answer.
BAA red flags
- Vendor refuses to sign. Walk away — or stop sending them PHI. There is no compliant alternative.
- Stale BAAs. Signed a decade ago with a company that's been acquired twice since.
- No incident-notification timeline. "We'll tell you if something happens" doesn't meet your 60-day notification clock.
BAAs are one of eight checks in our readiness quiz — and a standard line in every assessor quote scope.
Keep reading
There's No Such Thing as HIPAA Certification
HHS OCR does not certify anyone. What 'HIPAA certified' vendors are actually selling — and what real compliance looks like instead.
How to Choose a HIPAA Assessment Firm: 9 Questions to Ask
No government body accredits HIPAA assessors — so vetting is on you. The nine questions that separate real healthcare assessors from generalists.
HIPAA Risk Assessment Cost in 2026: What Organizations Actually Pay
The assessment fee is the smallest line item. A full first-year cost breakdown: analysis, readiness, program build, and staff time — with planning ranges.
Questions
Do we need BAAs with vendors that only store encrypted PHI?
Yes. Storage is maintenance of PHI — the encryption doesn't remove the BAA requirement. (It does affect breach-notification analysis, which is a separate question.)
What if a vendor won't sign a BAA?
Don't share PHI with them. If the service inherently involves PHI, find a vendor that will sign — this is non-negotiable.
Turn reading into quotes
Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match HIPAA assessors to your size, setting, and timeline → they send scoped quotes directly. Free, no obligation.