Business Associate Agreements Explained for Practice Managers

What makes a vendor a business associate, which vendors need BAAs, what the agreement actually obligates them to do, red flags in vendor paper, and the annual review.

By Scott McAuley · Aug 5, 2026 · 10 min read

Somewhere in your practice there is — or should be — a folder holding a stack of signed agreements that most practice managers have never actually read. Business associate agreements are the least glamorous documents in healthcare compliance, and among the most consequential: when a vendor loses your patient data, the first question a regulator asks is "was there a BAA, and what did it say?"

This guide is the plain-English version, written for the person who actually manages the vendor relationships — not the lawyer, not the IT department. It's the expanded treatment of the BAA chapter in our [complete HIPAA compliance and healthcare IT guide](/resources/hipaa-compliance-healthcare-it-guide): what makes a vendor a business associate, which of your vendors qualify (including the ones everyone forgets), what the agreement actually obligates the vendor to do, the red flags hiding in vendor paperwork, and the annual review that keeps the whole file honest.

What Makes a Vendor a Business Associate

The definition is functional, not categorical. A business associate is any outside company or person that creates, receives, stores, or transmits protected health information (PHI) on your practice's behalf. Four verbs. That's the whole test.

Notice what's *not* in the test: the vendor's industry, their size, whether they market themselves as "HIPAA compliant," or whether they ever intend to look at the data. A cloud backup service that holds encrypted copies of your server is a business associate even if no human there ever opens a file — they *store* PHI. A transcription service that turns dictation into chart notes *creates* it. Your IT provider, with admin credentials to every system in the building, *receives and transmits* it constantly as a side effect of doing their job.

Two useful boundaries. Your own employees are not business associates — they're your workforce, covered by your policies and training. And vendors that genuinely never touch PHI — the landscaper, the coffee service, the firm that shreds only your accounting records — don't need BAAs. The mistake practices make is drawing that line by gut feel instead of by walking the data.

The Rule That Decides Everything: No BAA, No PHI

Here's the rule that makes this a practice-manager topic rather than a legal-department one, because it governs day-to-day vendor decisions:

No PHI flows to any vendor until a BAA is signed. Not during a trial. Not "while the paperwork is in process." Not because the vendor is big and reputable.

The moment patient data moves to a vendor without a signed BAA, your practice is out of compliance — regardless of how secure that vendor is, and regardless of whether anything ever goes wrong. This is one of the few areas of HIPAA that is genuinely binary. And it cuts both ways: a vendor that hesitates, stalls, or says "our standard terms cover it" when you ask for a BAA is telling you something important about how they'll behave when something breaks.

The operational version of the rule: make "does this involve patient data, and do we have a BAA?" a standing question in every new-vendor conversation, asked before the free trial starts — because free trials run on real data, and real data is where the rule bites.

Walking Your Vendor List

Print your accounts-payable vendor list and walk it line by line with the four verbs in mind. Here's where BAAs are needed, in roughly the order practices get them wrong:

The output of this walk is a one-page BAA inventory: vendor, what PHI they touch, BAA signed (date), and where the copy lives. If that looks like a row from a risk-assessment inventory, it should — it's the same table.

What a BAA Actually Obligates the Vendor to Do

A BAA is not a formality; it's a contract that puts specific duties on the vendor. A real one obligates the business associate to:

Read that list once and the negotiating dynamic becomes clearer: a well-run vendor treats the BAA as routine because they've built their service to meet these duties. A vendor who resists is usually resisting the duties, not the paperwork.

What a BAA Does Not Do

This is the misunderstanding that hurts practices: a BAA is not an outsourcing of your compliance. Signing one does not transfer your obligations to the vendor, and a drawer full of signed BAAs is not a compliance program.

Your risk assessment is still yours. Your staff training, access controls, policies, and breach duties to patients are still yours. If a vendor with a signed BAA has a breach, your practice still generally owns the patient and HHS notifications. What the BAA changes is *accountability and defensibility*: the vendor now carries direct regulatory exposure for their own failures, and your signed agreement plus documented diligence is the evidence that you did what the law asks of you. Under the current penalty structure — roughly $145 to over $73,000 per violation depending on culpability, with annual caps around $2.19 million — that evidence is precisely what separates the lowest tiers from the willful-neglect tiers.

Think of the BAA as one load-bearing wall in the structure described in [the full HIPAA guide](/resources/hipaa-compliance-healthcare-it-guide) — necessary, and nowhere near sufficient on its own.

Red Flags in Vendor BAAs

Most practices sign whatever BAA the vendor slides across. Before you do, scan for three clauses that show up in vendor-drafted agreements and quietly shift risk onto you:

1. Unilateral amendment. Language letting the vendor "update these terms from time to time" without your signature means the agreement you filed may not be the agreement in force when the breach happens. Insist on amendments requiring mutual written consent.

2. No breach-notification timeline — or a hollow one. "Without unreasonable delay" with no outer bound, or a window so long it consumes most of your own 60-day patient-notification clock, leaves you holding a deadline you can't meet. Look for a specific commitment measured in days, with enough detail (what was involved, which individuals) for you to act.

3. Subcontractor silence. If the BAA says nothing about downstream vendors, your data can end up with companies you've never heard of, under no equivalent obligations. The agreement should state that subcontractors handling your PHI are bound to the same terms.

None of this requires a law degree — it requires reading the document with those three questions in hand, and being willing to ask for changes. Reputable vendors accommodate; the ones who won't are, again, telling you something.

The Annual BAA File Review

A BAA file rots quietly. Vendors get acquired, plans get downgraded, staff adopt new tools, and the agreement signed four years ago no longer matches the services actually in use. The fix is a scheduled habit, not a heroic project: once a year, walk the vendor list against the BAA file.

The natural home for this review is your annual security risk assessment — the vendor inventory you build in [the SRA walkthrough](/resources/hipaa-security-risk-assessment-walkthrough) is the same list, and Phase 1 of that process explicitly includes matching every ePHI-touching vendor to a signed BAA. In one pass you catch the four standard failures: new vendors with no BAA, departed vendors who never confirmed data destruction, changed services that outgrew the old agreement, and the informal tools that crept in through a browser tab.

Keeping this cadence honest — the review actually happening, the file actually current, the findings actually closed — is exactly the kind of standing discipline our [compliance support](/services/compliance-support) practice runs for healthcare clients year-round.

When a Vendor Has a Breach

Sooner or later a vendor will send the letter every practice dreads. What happens next runs on the paperwork you filed years earlier:

1. The vendor's BAA duty kicks in — they must notify you, which is why the notification-timeline clause mattered.

2. Your notification duties activate. For breaches of your patients' data, your practice generally owns notification to patients and HHS, on the regulatory clock, even though the failure was the vendor's.

3. The file decides your exposure. A signed BAA, a documented annual review, evidence you vetted the vendor — that's a practice that did its job and lands accordingly. A missing BAA converts the vendor's incident into your independent violation.

4. The relationship decision follows. The BAA's termination and return-or-destroy provisions are what let you exit cleanly if the vendor's answers aren't good enough.

The pattern worth internalizing: every step of a vendor breach goes better or worse based on decisions made long before it, in documents most practices never read. Reading them is the job.

Getting the File in Order

If this guide surfaced gaps — vendors you can't match to a signed agreement, a phone or shredding vendor nobody thought about, a file that predates your current EHR — the fix is a focused afternoon, not a quarter-long project: build the inventory, request the missing agreements, read the three red-flag clauses before signing, and put the annual review on the calendar.

Texas Management Group runs this exact exercise as part of our [healthcare IT practice](/industries/healthcare) — usually inside a broader risk assessment, because the vendor walk and the ePHI inventory are the same work. If you'd rather not do it alone, [contact us](/contact) and we'll walk the list with you, flag what's missing, and hand you the findings in writing.

*Scott McAuley is the founder and CEO of Texas Management Group, and founder of Talos Automation and Talk Is Cheap — 25+ years running IT, communications, and automation for Texas businesses.*

Frequently Asked Questions

What is a business associate under HIPAA?

Any outside company or person that creates, receives, stores, or transmits protected health information on your practice's behalf. The test is what data flows through them — not their industry, size, or whether a human there ever looks at a record. IT providers, email platforms, EHR and billing vendors, backup services, phone and texting platforms, transcription, and shredding companies all routinely qualify.

Which vendors need to sign a BAA with my practice?

Every vendor that touches PHI in any form, before any data flows. The commonly missed ones: the IT provider (admin access to everything), email platforms (BAAs exist only on qualifying business plans and must be deliberately executed), phone/VoIP and texting services (voicemails, recordings, and messages are PHI), and the physical-world category — transcription and shredding — that practices forget entirely.

Does signing a BAA make my practice HIPAA compliant?

No. The BAA covers one vendor relationship: it obligates that vendor to safeguard PHI, report breaches to you, and bind their subcontractors. Your risk assessment, policies, training, technical safeguards, and patient notification duties remain yours. A BAA is a required component of compliance, never a substitute for it.

What are the red flags in a vendor's BAA?

Three clauses deserve a hard look before signing: unilateral amendment (the vendor can change terms without your signature), a missing or hollow breach-notification timeline (no specific day-count, or one that consumes your own 60-day clock), and subcontractor silence (no commitment that downstream vendors handling your PHI are bound to equivalent terms).

What happens if a business associate has a breach?

The vendor must notify your practice under the BAA, and your practice generally owns the patient and HHS notifications on the regulatory clock. Your exposure then turns on your paperwork: a signed BAA plus a documented annual vendor review demonstrates due diligence, while a missing BAA makes the vendor's breach your independent violation as well.