Business Associate Agreements Explained for Practice Managers
What makes a vendor a business associate, which vendors need BAAs, what the agreement actually obligates them to do, red flags in vendor paper, and the annual review.
By Scott McAuley · Aug 5, 2026 · 10 min read
Somewhere in your practice there is — or should be — a folder holding a stack of signed agreements that most practice managers have never actually read. Business associate agreements are the least glamorous documents in healthcare compliance, and among the most consequential: when a vendor loses your patient data, the first question a regulator asks is "was there a BAA, and what did it say?"
This guide is the plain-English version, written for the person who actually manages the vendor relationships — not the lawyer, not the IT department. It's the expanded treatment of the BAA chapter in our [complete HIPAA compliance and healthcare IT guide](/resources/hipaa-compliance-healthcare-it-guide): what makes a vendor a business associate, which of your vendors qualify (including the ones everyone forgets), what the agreement actually obligates the vendor to do, the red flags hiding in vendor paperwork, and the annual review that keeps the whole file honest.
What Makes a Vendor a Business Associate
The definition is functional, not categorical. A business associate is any outside company or person that creates, receives, stores, or transmits protected health information (PHI) on your practice's behalf. Four verbs. That's the whole test.
Notice what's *not* in the test: the vendor's industry, their size, whether they market themselves as "HIPAA compliant," or whether they ever intend to look at the data. A cloud backup service that holds encrypted copies of your server is a business associate even if no human there ever opens a file — they *store* PHI. A transcription service that turns dictation into chart notes *creates* it. Your IT provider, with admin credentials to every system in the building, *receives and transmits* it constantly as a side effect of doing their job.
Two useful boundaries. Your own employees are not business associates — they're your workforce, covered by your policies and training. And vendors that genuinely never touch PHI — the landscaper, the coffee service, the firm that shreds only your accounting records — don't need BAAs. The mistake practices make is drawing that line by gut feel instead of by walking the data.
The Rule That Decides Everything: No BAA, No PHI
Here's the rule that makes this a practice-manager topic rather than a legal-department one, because it governs day-to-day vendor decisions:
No PHI flows to any vendor until a BAA is signed. Not during a trial. Not "while the paperwork is in process." Not because the vendor is big and reputable.
The moment patient data moves to a vendor without a signed BAA, your practice is out of compliance — regardless of how secure that vendor is, and regardless of whether anything ever goes wrong. This is one of the few areas of HIPAA that is genuinely binary. And it cuts both ways: a vendor that hesitates, stalls, or says "our standard terms cover it" when you ask for a BAA is telling you something important about how they'll behave when something breaks.
The operational version of the rule: make "does this involve patient data, and do we have a BAA?" a standing question in every new-vendor conversation, asked before the free trial starts — because free trials run on real data, and real data is where the rule bites.
Walking Your Vendor List
Print your accounts-payable vendor list and walk it line by line with the four verbs in mind. Here's where BAAs are needed, in roughly the order practices get them wrong:
- Your IT provider or MSP. Admin access to every system means access to everything those systems hold. Any IT company serving healthcare should sign a BAA without hesitation — a provider that hedges here is disqualifying itself.
- Email and productivity platforms. Microsoft 365 and Google Workspace both offer BAAs, but only on qualifying business plans — consumer and some entry-level tiers are excluded — and only if you actually execute the agreement, which for both platforms is a deliberate step, not automatic. A practice on the wrong tier, or on the right tier with an unexecuted BAA, is emailing PHI with no agreement in place. Check the plan name on your invoice, not your assumption.
- EHR and billing vendors, and clearinghouses. Usually the vendors most fluent in BAAs, which creates its own trap: "it's covered in the terms somewhere" is not the same as a signed agreement you can produce. Verify it exists, get a copy, file it.
- Backup and cloud storage. Anywhere a copy of your data rests — backup services, file-sync tools, cloud archives — is storage of PHI. This includes the file-sharing account a staff member started using informally.
- Phone, VoIP, and texting platforms. Modern phone systems store voicemails and call recordings as data, and patients leave names, conditions, and callback numbers in both. Texting platforms carrying patient communication are squarely in scope. This category deserves its own diligence pass — what makes a communications vendor genuinely BAA-worthy, and how compliant patient texting actually works, is covered in depth in Talk Is Cheap's guide to [HIPAA compliant communications](https://talkischeap.io/hipaa-compliant-communications).
- Transcription services. They create chart content from dictation. Human or AI-powered, domestic or offshore — business associate, full stop. AI transcription tools adopted informally by individual clinicians are a fast-growing gap here.
- Shredding and record-storage companies — the forgotten category. The truck that hauls away your paper charts, and the warehouse storing the old ones, handle PHI in its most literal form. Practices meticulous about software vendors routinely have no BAA with the company physically driving patient records down the highway.
The output of this walk is a one-page BAA inventory: vendor, what PHI they touch, BAA signed (date), and where the copy lives. If that looks like a row from a risk-assessment inventory, it should — it's the same table.
What a BAA Actually Obligates the Vendor to Do
A BAA is not a formality; it's a contract that puts specific duties on the vendor. A real one obligates the business associate to:
- Use PHI only for the services they're providing you — not analytics side projects, not marketing, not "improving their models" unless you've agreed to it
- Implement the Security Rule's safeguards on their side — the vendor takes on direct regulatory obligations of their own
- Report security incidents and breaches to you, so your notification clock can start
- Bind their subcontractors to equivalent terms — the chain of custody follows the data downstream
- Return or destroy your PHI when the relationship ends, and say so in writing
- Make their practices available to regulators if it comes to that
Read that list once and the negotiating dynamic becomes clearer: a well-run vendor treats the BAA as routine because they've built their service to meet these duties. A vendor who resists is usually resisting the duties, not the paperwork.
What a BAA Does Not Do
This is the misunderstanding that hurts practices: a BAA is not an outsourcing of your compliance. Signing one does not transfer your obligations to the vendor, and a drawer full of signed BAAs is not a compliance program.
Your risk assessment is still yours. Your staff training, access controls, policies, and breach duties to patients are still yours. If a vendor with a signed BAA has a breach, your practice still generally owns the patient and HHS notifications. What the BAA changes is *accountability and defensibility*: the vendor now carries direct regulatory exposure for their own failures, and your signed agreement plus documented diligence is the evidence that you did what the law asks of you. Under the current penalty structure — roughly $145 to over $73,000 per violation depending on culpability, with annual caps around $2.19 million — that evidence is precisely what separates the lowest tiers from the willful-neglect tiers.
Think of the BAA as one load-bearing wall in the structure described in [the full HIPAA guide](/resources/hipaa-compliance-healthcare-it-guide) — necessary, and nowhere near sufficient on its own.
Red Flags in Vendor BAAs
Most practices sign whatever BAA the vendor slides across. Before you do, scan for three clauses that show up in vendor-drafted agreements and quietly shift risk onto you:
1. Unilateral amendment. Language letting the vendor "update these terms from time to time" without your signature means the agreement you filed may not be the agreement in force when the breach happens. Insist on amendments requiring mutual written consent.
2. No breach-notification timeline — or a hollow one. "Without unreasonable delay" with no outer bound, or a window so long it consumes most of your own 60-day patient-notification clock, leaves you holding a deadline you can't meet. Look for a specific commitment measured in days, with enough detail (what was involved, which individuals) for you to act.
3. Subcontractor silence. If the BAA says nothing about downstream vendors, your data can end up with companies you've never heard of, under no equivalent obligations. The agreement should state that subcontractors handling your PHI are bound to the same terms.
None of this requires a law degree — it requires reading the document with those three questions in hand, and being willing to ask for changes. Reputable vendors accommodate; the ones who won't are, again, telling you something.
The Annual BAA File Review
A BAA file rots quietly. Vendors get acquired, plans get downgraded, staff adopt new tools, and the agreement signed four years ago no longer matches the services actually in use. The fix is a scheduled habit, not a heroic project: once a year, walk the vendor list against the BAA file.
The natural home for this review is your annual security risk assessment — the vendor inventory you build in [the SRA walkthrough](/resources/hipaa-security-risk-assessment-walkthrough) is the same list, and Phase 1 of that process explicitly includes matching every ePHI-touching vendor to a signed BAA. In one pass you catch the four standard failures: new vendors with no BAA, departed vendors who never confirmed data destruction, changed services that outgrew the old agreement, and the informal tools that crept in through a browser tab.
Keeping this cadence honest — the review actually happening, the file actually current, the findings actually closed — is exactly the kind of standing discipline our [compliance support](/services/compliance-support) practice runs for healthcare clients year-round.
When a Vendor Has a Breach
Sooner or later a vendor will send the letter every practice dreads. What happens next runs on the paperwork you filed years earlier:
1. The vendor's BAA duty kicks in — they must notify you, which is why the notification-timeline clause mattered.
2. Your notification duties activate. For breaches of your patients' data, your practice generally owns notification to patients and HHS, on the regulatory clock, even though the failure was the vendor's.
3. The file decides your exposure. A signed BAA, a documented annual review, evidence you vetted the vendor — that's a practice that did its job and lands accordingly. A missing BAA converts the vendor's incident into your independent violation.
4. The relationship decision follows. The BAA's termination and return-or-destroy provisions are what let you exit cleanly if the vendor's answers aren't good enough.
The pattern worth internalizing: every step of a vendor breach goes better or worse based on decisions made long before it, in documents most practices never read. Reading them is the job.
Getting the File in Order
If this guide surfaced gaps — vendors you can't match to a signed agreement, a phone or shredding vendor nobody thought about, a file that predates your current EHR — the fix is a focused afternoon, not a quarter-long project: build the inventory, request the missing agreements, read the three red-flag clauses before signing, and put the annual review on the calendar.
Texas Management Group runs this exact exercise as part of our [healthcare IT practice](/industries/healthcare) — usually inside a broader risk assessment, because the vendor walk and the ePHI inventory are the same work. If you'd rather not do it alone, [contact us](/contact) and we'll walk the list with you, flag what's missing, and hand you the findings in writing.
*Scott McAuley is the founder and CEO of Texas Management Group, and founder of Talos Automation and Talk Is Cheap — 25+ years running IT, communications, and automation for Texas businesses.*
Frequently Asked Questions
What is a business associate under HIPAA?
Any outside company or person that creates, receives, stores, or transmits protected health information on your practice's behalf. The test is what data flows through them — not their industry, size, or whether a human there ever looks at a record. IT providers, email platforms, EHR and billing vendors, backup services, phone and texting platforms, transcription, and shredding companies all routinely qualify.
Which vendors need to sign a BAA with my practice?
Every vendor that touches PHI in any form, before any data flows. The commonly missed ones: the IT provider (admin access to everything), email platforms (BAAs exist only on qualifying business plans and must be deliberately executed), phone/VoIP and texting services (voicemails, recordings, and messages are PHI), and the physical-world category — transcription and shredding — that practices forget entirely.
Does signing a BAA make my practice HIPAA compliant?
No. The BAA covers one vendor relationship: it obligates that vendor to safeguard PHI, report breaches to you, and bind their subcontractors. Your risk assessment, policies, training, technical safeguards, and patient notification duties remain yours. A BAA is a required component of compliance, never a substitute for it.
What are the red flags in a vendor's BAA?
Three clauses deserve a hard look before signing: unilateral amendment (the vendor can change terms without your signature), a missing or hollow breach-notification timeline (no specific day-count, or one that consumes your own 60-day clock), and subcontractor silence (no commitment that downstream vendors handling your PHI are bound to equivalent terms).
What happens if a business associate has a breach?
The vendor must notify your practice under the BAA, and your practice generally owns the patient and HHS notifications on the regulatory clock. Your exposure then turns on your paperwork: a signed BAA plus a documented annual vendor review demonstrates due diligence, while a missing BAA makes the vendor's breach your independent violation as well.