Business Associate Agreements (BAAs) are one of the most commonly missed HIPAA requirements in small practices. Not because practices don't know about them. Because the list of vendors who technically qualify as Business Associates is longer than most people expect.
This is a practical guide to who needs a BAA, what it needs to cover, and how to close the gaps if you're missing some.
Who is a Business Associate?
Under HIPAA, a Business Associate is any person or company that performs functions or services on behalf of your practice that involve accessing, creating, receiving, maintaining, or transmitting Protected Health Information (PHI).
The key word is "on your behalf." A vendor who processes or stores data as part of serving your practice is a Business Associate. A vendor who just sells you a product (like a chair or a printer) is not.
The vendors most small practices forget
Billing services and EHR vendors are obvious. These are the ones practices almost always have BAAs for. The ones that get missed:
- Cloud storage providers: If you store any patient documents in Google Drive, Dropbox, OneDrive, or Box, you need a BAA. Google Workspace for Business and Microsoft 365 both offer BAAs. Standard consumer Dropbox does not.
- Email providers: If you send or receive patient information by email, your email provider needs a BAA. Gmail with Google Workspace for Healthcare: yes. Standard Gmail: no.
- AI transcription and note-taking tools: Any tool that processes session audio or generates clinical notes is almost certainly handling PHI.
- Scheduling software: If your scheduling platform stores patient names, contact information, or appointment details tied to health conditions, a BAA is required.
- Remote desktop and IT support tools: If your IT vendor can access systems that contain PHI, they need a BAA.
- Shredding and document destruction services: If they handle physical documents with patient information, a BAA is required.
- Answering services and patient communication platforms: If they handle messages or calls involving patient health information, a BAA is required.
- Accountants and billing consultants: If they access records that include patient-identifiable information, a BAA may be required.
Who does NOT need a BAA: Vendors who provide non-healthcare services without accessing PHI (your landlord, your office supply vendor, your malpractice insurer), and vendors who are themselves covered entities under HIPAA (like a laboratory you send specimens to).
What a BAA needs to include
HIPAA specifies the required elements of a BAA. A compliant BAA must address:
- What the Business Associate is permitted to do with PHI
- How they will protect PHI from unauthorized use or disclosure
- How they will report breaches or security incidents to you
- How they will return or destroy PHI when the agreement ends
- That subcontractors who access PHI will also be bound by BAA requirements
Most established vendors in the healthcare space will provide a standard BAA. Read it before you sign. Pay particular attention to the breach notification timeline (you want to be notified quickly, not on a 60-day lag) and to language about using your data for AI training.
What to do if a vendor won't sign a BAA
Two paths: stop using the tool for anything involving PHI, or escalate to a vendor tier that includes a BAA.
Some vendors offer a HIPAA-compliant version of their product at a higher price point. If the tool is genuinely useful to your practice and the price is reasonable, upgrading may be the right call. If the vendor has no BAA option at any tier, you have your answer.
BAA audit checklist
- List every vendor your practice uses that touches patient data in any form
- For each vendor, locate your signed BAA or document that none exists
- Contact vendors with no BAA on file and request one
- Review each BAA for breach notification timelines and data use terms
- Store signed BAAs in a central location accessible to your compliance contact
- Set a calendar reminder to review BAAs annually or when vendors change
A complete BAA inventory is one of the first things an OCR investigator requests. Getting yours in order now takes a few hours. Reconstructing it under a 30-day response deadline is a significantly worse situation.
Not sure which of your vendors need BAAs?
The free Cyber Health Score includes a vendor assessment section that flags common gaps in 5 minutes.
Get your free Cyber Health Score