Back to resources

Business Associate Agreements (BAAs) are one of the most commonly missed HIPAA requirements in small practices. Not because practices don't know about them. Because the list of vendors who technically qualify as Business Associates is longer than most people expect.

This is a practical guide to who needs a BAA, what it needs to cover, and how to close the gaps if you're missing some.

Who is a Business Associate?

Under HIPAA, a Business Associate is any person or company that performs functions or services on behalf of your practice that involve accessing, creating, receiving, maintaining, or transmitting Protected Health Information (PHI).

The key word is "on your behalf." A vendor who processes or stores data as part of serving your practice is a Business Associate. A vendor who just sells you a product (like a chair or a printer) is not.

The vendors most small practices forget

Billing services and EHR vendors are obvious. These are the ones practices almost always have BAAs for. The ones that get missed:

Who does NOT need a BAA: Vendors who provide non-healthcare services without accessing PHI (your landlord, your office supply vendor, your malpractice insurer), and vendors who are themselves covered entities under HIPAA (like a laboratory you send specimens to).

What a BAA needs to include

HIPAA specifies the required elements of a BAA. A compliant BAA must address:

Most established vendors in the healthcare space will provide a standard BAA. Read it before you sign. Pay particular attention to the breach notification timeline (you want to be notified quickly, not on a 60-day lag) and to language about using your data for AI training.

What to do if a vendor won't sign a BAA

Two paths: stop using the tool for anything involving PHI, or escalate to a vendor tier that includes a BAA.

Some vendors offer a HIPAA-compliant version of their product at a higher price point. If the tool is genuinely useful to your practice and the price is reasonable, upgrading may be the right call. If the vendor has no BAA option at any tier, you have your answer.

BAA audit checklist

  • List every vendor your practice uses that touches patient data in any form
  • For each vendor, locate your signed BAA or document that none exists
  • Contact vendors with no BAA on file and request one
  • Review each BAA for breach notification timelines and data use terms
  • Store signed BAAs in a central location accessible to your compliance contact
  • Set a calendar reminder to review BAAs annually or when vendors change

A complete BAA inventory is one of the first things an OCR investigator requests. Getting yours in order now takes a few hours. Reconstructing it under a 30-day response deadline is a significantly worse situation.

Not sure which of your vendors need BAAs?

The free Cyber Health Score includes a vendor assessment section that flags common gaps in 5 minutes.

Get your free Cyber Health Score