Skip to content
Health & consent

Which of your vendors needs a BAA, and what the agreement has to say

Almost every dispute about business associate agreements is really a dispute about one prior question: is this vendor a business associate at all. Practices sign agreements with companies that never needed one and skip them with companies that plainly did, because the intuitive test — does the vendor read the records — is not the test the rule uses. What follows is the definition as it is actually written, the two boundaries people cross in opposite directions, the terms the Privacy and Security Rules require the contract to contain, and the handful of terms that decide who carries the cost when something goes wrong. It is written for the practice signing a vendor up and for the vendor being handed a twelve-page agreement to sign.

9 min readPublished How we write these

The short version

  • The test is function, not sight. Under 45 CFR § 160.103 a business associate is a person who creates, receives, maintains or transmits protected health information on behalf of a covered entity for a regulated function — or who provides legal, accounting, consulting, management, administrative or financial services where providing them involves disclosure of PHI.
  • The conduit exception is not written in the regulation. It is HHS's reading of "access on a routine basis" in the definition, and the 2013 preamble calls it "a narrow one" covering couriers and internet service providers. The line drawn there is transient versus persistent access, not whether the vendor looks.
  • Encryption does not exempt anyone. An entity that maintains PHI on a covered entity's behalf "is a business associate and not a conduit, even if the entity does not actually view the protected health information".
  • Twelve terms are compulsory: § 164.504(e)(2) sets ten specific promises plus the permitted-use clause and the termination right, and § 164.314(a)(2)(i) adds Security Rule compliance, subcontractor flow-down and security-incident reporting. Everything else in a BAA — indemnity, insurance, audit rights, a shorter breach clock — is negotiable and nothing requires it.

The vendor's objection is nearly always the same sentence: we do not look at your data, so we are just a pipe. It is said in good faith and it is wrong about the rule, which asks what the vendor does with the information rather than what the vendor reads.

What actually makes a vendor a business associate

The definition at 45 CFR § 160.103 has two limbs. The first catches a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter" — the section then names claims processing, data analysis, utilisation review, quality assurance, billing, benefit management, practice management and repricing. The second catches anyone providing legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services "where the provision of the service involves the disclosure of protected health information".

Paragraph (3) adds three categories by name: a Health Information Organization, E-prescribing Gateway or other data transmission provider "that requires access on a routine basis" to PHI; anyone offering a personal health record on a covered entity's behalf; and any subcontractor further down the chain. Paragraph (4) then carves out four situations, and the useful one is the first — a health care provider is not a business associate "with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual". The referral letter to a specialist needs no agreement, and neither does the records release a patient signs.

Two facts decide it, and neither one alone

How long does it hold the information?

Does the vendor look at the information?

No, or only at random

Yes, to do the job

In transit only

Conduit

A courier, the postal service, an ISP carrying traffic. No agreement needed.

Business associate

Routine access to do the work is exactly what paragraph (3)(i) describes.

It maintains it

Business associate

Storage is the service. Encrypted and key-less makes no difference.

Business associate

The uncontested case, and the smallest share of real disputes.

Cell four is where the arguments happen. Both dimensions come from the Omnibus Rule preamble at 78 FR 5571–5572, which draws the line at "the transient versus persistent nature of that opportunity".

The conduit exception is narrower than the people invoking it think

There is no conduit exception in the regulation. It is HHS's interpretation of what "access on a routine basis" means, set out when the Omnibus Rule was finalised in January 2013: "The conduit exception is a narrow one and is intended to exclude only those entities providing mere courier services, such as the U.S. Postal Service or United Parcel Service and their electronic equivalents, such as internet service providers (ISPs) providing mere data transmission services." A conduit transports information but does not access it other than on a random or infrequent basis.

The load-bearing sentence comes next. The exception "is limited to transmission services (whether digital or hard copy), including any temporary storage of transmitted data incident to such transmission. In contrast, an entity that maintains protected health information on behalf of a covered entity is a business associate and not a conduit, even if the entity does not actually view the protected health information." HHS gives the example itself: a document storage company is a business associate whether or not it ever opens a box.

What the rule requires the contract to say

§ 164.502(e)(2) requires the assurances to be documented in a written contract meeting § 164.504(e). That section is short and specific. The permitted-use clause comes first, and it is a ceiling rather than a licence: the contract "may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity". Only two things sit outside that ceiling — use for the business associate's own proper management and administration under § 164.504(e)(4), and data aggregation for the covered entity's health care operations.

The promises § 164.504(e)(2)(ii) makes compulsory

A business associate agreement, stripped to what is mandatory

Ten in the Privacy Rule, plus the termination right at (e)(2)(iii). Section 164.314(a)(2)(i) adds three more for electronic PHI: comply with the Security Rule, bind subcontractors to it, and report every security incident — not only breaches. A data processing agreement covers similar ground for non-health data.

That is the whole compulsory list. Everything a real negotiation is about is absent from it: indemnity, a liability cap, insurance limits, audit rights, who pays for the credit monitoring and the notification mailing, and how fast the vendor must call you. A vendor holding the line on an unlimited indemnity is not refusing to be HIPAA compliant.

Start the underlying vendor agreement

A BAA rides on top of a services contract and does not replace one. Where the commercial terms live in a separate document, that is where the liability, insurance and termination bargain has to be struck.

Open

Agency, and who owns the sixty-day clock

Two provisions people read separately do most of the damage together. § 160.402(c)(1) makes a covered entity liable for a civil money penalty "for a violation based on the act or omission of any agent of the covered entity, including a workforce member or business associate, acting within the scope of the agency". § 164.404(a)(2) then deems a breach discovered by the covered entity as soon as it is known to any agent. If your vendor is your agent, its bad Tuesday is your bad Tuesday, and your notification clock started before anyone rang you.

Whether a vendor is an agent is not settled by the label on the contract. HHS applies the federal common law: "The essential factor ... is the right or authority of a covered entity to control the business associate's conduct." A BAA that simply sets terms, so the only remedy is to amend it or sue, generally does not create agency. One that lets the practice direct how the service is performed after the fact — HHS's example is a clause requiring the associate to release records "based on the instructions to be provided by or under the direction of a covered entity" — generally does. Calling the vendor an independent contractor changes nothing.

Two clocks, and the gap between them

  1. Day 0

    The vendor discovers it

    Deemed discovered when any employee or agent other than the wrongdoer knew, or by reasonable diligence would have known.

  2. By day 60

    The vendor must tell you

    § 164.410(b): without unreasonable delay and in no case later than 60 calendar days after its discovery.

  3. Day 60 from yours

    Patients and, at 500+, the Secretary

    § 164.404(b) and § 164.408(b). Below 500 individuals the Secretary is told on an annual log within 60 days of year end.

The 60 days at § 164.410(b) is an outer limit, not an allowance. Where the vendor is your agent the two clocks collapse into one and the gap disappears — which is why the notification window is the term most worth negotiating.

The chain does not stop at your vendor

Every subcontractor that touches the information is itself a business associate, and the duty to paper it travels with the delegation rather than with the relationship to you. § 164.502(e)(1)(i) is explicit that a covered entity "is not required to obtain such satisfactory assurances from a business associate that is a subcontractor"; § 164.502(e)(1)(ii) puts that obligation on your vendor instead. HHS put the reach plainly in 2013: covered entities must obtain assurances from their business associates, "and business associates must do the same with regard to subcontractors, and so on, no matter how far ‘down the chain’ the information flows".

The five vendors small practices get wrong

The vendorWhere it landsThe term that matters
AI scribe or ambient note toolBusiness associate. It receives the consultation audio and creates the note.Whether the agreement lets the vendor train its models on your patients' PHI. That is neither its own management and administration nor data aggregation, which § 164.501 confines to analyses relating to the covered entities' own operations.
Email and e-faxA hosted service that stores the messages maintains PHI. An ISP merely carrying the traffic is a conduit.Whether your account tier is one the vendor will sign for — many will sign only above a certain plan.
Reminder and marketing platformsBusiness associate. Reminders are treatment communications; campaigns are not.The marketing clause. Paid third-party promotion generally needs patient authorisation, whatever the BAA permits.
Outsourced IT and managed servicesBusiness associate wherever the engineer holds credentials to systems holding ePHI.Whether access is persistent. The conduit reasoning does not survive an administrator account.
Website analytics and tracking pixelsDepends entirely on whether the vendor will sign. Most large ad platforms will not.What runs on authenticated pages. Nothing that transmits identified PHI to a non-signing vendor belongs on a patient portal.
On the last row the ground moved. In American Hospital Association v. Becerra (N.D. Tex., 4:23-cv-01110, 20 June 2024) Judge Mark Pittman vacated the "Proscribed Combination" in OCR's March 2024 tracking bulletin — the position that an IP address collected on a public page became PHI — as "promulgated in clear excess of HHS's authority", and OCR said that August it would not appeal. The rest of the bulletin stands, and nothing changed for logged-in pages.

A signed BAA is not a compliance programme

The agreement is the paperwork of one obligation among many, and filing it does not discharge the others. § 164.306(a) applies the Security Rule to covered entities and business associates alike, and § 164.308(a)(1)(ii)(A) requires each of them to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities" to the ePHI it holds. A folder of countersigned agreements and no risk analysis is the least useful half of the file.

For vendors, the exposure is direct rather than contractual. § 160.402(a) lets the Secretary impose a civil money penalty on "a covered entity or business associate" that violates an administrative simplification provision, and since HITECH the Security Rule, the breach notification duty and the limits on use and disclosure apply to associates in their own right. OCR does not enforce your BAA's terms against your vendor — it enforces the Rules. That is also why the contract still matters: your indemnity is the only thing that moves money between you.

Where this leaves the two sides of the table

The classification question has one right answer and it does not depend on who has the leverage. A vendor that maintains protected health information is a business associate whether or not it signs, whether or not it can read the records, and whether or not anyone at either company has thought about it. What the signature changes is the covered entity's position, not the vendor's status — which is why the practice is the party with the urgent problem when a vendor refuses, and why the honest response to a refusal is usually to move the data rather than to accept the assurance.

For the vendor, the twelve mandatory terms are not the part worth fighting. They are identical in every agreement and they come from the regulation; resisting them signals only that nobody has read § 164.504(e). The cap, the indemnity, the notification window and the audit right are where a negotiation belongs, and where a software or platform contract usually settles it.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Does a vendor that only stores encrypted data need a BAA?

Yes. HHS drew the line at whether the vendor maintains the information rather than whether it can read it. The Omnibus Rule preamble states that an entity maintaining protected health information on a covered entity's behalf is a business associate and not a conduit even where it does not actually view the information, and OCR's cloud computing guidance applies that squarely to a provider holding encrypted records without the decryption key.

What happens if we never signed a BAA with a vendor that should have had one?

The disclosures already made were impermissible, and that exposure does not disappear when the agreement is signed later. Sign one now, because every day without it adds to the problem, but treat the gap as something to document and assess rather than something the new signature erases. The vendor is separately liable in its own right for any Security Rule failures during the period.

How quickly does a business associate have to report a breach?

Under 45 CFR 164.410 the associate must notify the covered entity without unreasonable delay and in no case later than 60 calendar days after it discovers the breach. That is an outer limit rather than a budget, and it consumes the covered entity's own 60-day window for notifying patients. Most agreements shorten it by contract, commonly to somewhere between five and fifteen days.

Do we need agreements with our vendor's subcontractors?

No, and the rule says so. 45 CFR 164.502(e)(1)(i) provides that a covered entity is not required to obtain satisfactory assurances from a business associate that is a subcontractor; the obligation sits with your vendor under 164.502(e)(1)(ii), and with each link below it. You can require disclosure of who the subcontractors are and a right to object, but that is a commercial term.

Is a BAA needed to send records to another doctor?

No. The definition of business associate at 45 CFR 160.103 excludes a health care provider with respect to disclosures by a covered entity to that provider concerning the treatment of the individual. Referrals, consultation letters and transfers of care sit outside the business associate framework entirely. The disclosure still has to be permitted, but no contract between the two providers is required.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week