Office Consumer is reader-supported. We may earn an affiliate commission from qualified links on our site.

When Is a Business Associate Agreement Required? (w/Examples) + FAQs

A business associate agreement is required any time an outside vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity. That covers billing services, EHR hosts, and cloud storage providers. It does not cover treatment referrals, payment-only claims between covered entities, or a janitor's incidental glance at a chart.

OCR fined Raleigh Orthopaedic Clinic $750,000 in 2016 for handing over PHI on 17,300 patients to a vendor without signing a BAA first. Enforcement has continued as more practices outsource billing, IT support, and AI scribing as of 2026. Any covered entity, business associate, or employer health plan handing patient data to an outside party needs this test first.

🧩 What makes someone a "business associate" under HIPAA

📋 The exact trigger that requires a signed agreement, in plain terms

🚪 The specific exceptions where no agreement is needed at all

💰 What a missing agreement has cost practices, with dollar figures

✅ A step-by-step method to check every vendor you work with now

This article reflects HIPAA guidance and enforcement patterns as of 2026. HIPAA sets a federal floor, and some states add stricter privacy rules on top of it. Your own facts can change the answer. Treat this as a starting point, not a stand-in for advice from a healthcare attorney or compliance pro who reviews your actual contracts.

What Counts as a "Business Associate"

HIPAA binds "covered entities" directly. That means health plans, health care clearinghouses, and most health care providers. Almost none of them handle every task alone, though, so the Privacy Rule lets a covered entity share protected health information (PHI) with outside people and firms. Those outside parties become business associates once they do work involving PHI on the covered entity's behalf.

The law only allows that sharing once the covered entity gets a written, signed promise. The promise says the data will stay safe. Without it, the sharing itself breaks the rule.

The roles that create a business associate tie fall into two groups. Functions and activities include claims processing, data analysis, review of care, billing, and benefit management. Services include legal work, accounting, consulting, and data work done for a fee. A person only becomes a business associate when the role touches PHI to do that work.

The same accountant who designs a covered entity's ad flyer is not a business associate for that job. No patient data is involved, so the flyer work sits outside the rule. The moment that accountant's audit work exposes billing records tied to patients, the answer flips.

Named examples make the group easier to picture. A claims processor for a health plan is a business associate. So is a CPA firm whose audit work touches billing records, and a lawyer whose case file holds PHI. A medical transcription service and a pharmacy benefits manager both fit too.

A cloud EHR vendor fits the same pattern. So does an IT firm with remote access to a practice's servers. An AI tool that transcribes visit recordings counts as well, since each one handles PHI to do a job the covered entity would otherwise do itself.

The line gets tested most often with newer software tools. A scheduling app that only stores a name and appointment time carries little risk on its own. The same app becomes a business associate the moment it also stores a diagnosis code or a clinical note. Vendors rarely flag which side of that line they sit on, so check the actual data fields the tool touches.

Workforce Members Are Never Business Associates

A worker under a covered entity's direct control is a workforce member, not a business associate. That holds true even when the worker sees PHI daily. HIPAA defines a workforce member as anyone the covered entity directly controls, paid or not, which covers employees, volunteers, and trainees.

An associate dentist inside a dental practice is generally a workforce member, per ADA guidance on business associate status. She typically follows the practice's own HIPAA rules rather than signing a separate agreement with it. The practice, not the associate, usually carries the direct legal duty for how she handles PHI.

The line changes who answers for a mistake. A workforce member's error is the covered entity's error, handled through internal discipline. A business associate's error is now often its own liability too, thanks to a 2013 rule change.

The HITECH Act made business associates directly liable for HIPAA compliance in their own right. OCR can now bring an enforcement action against a business associate directly, not only through the covered entity that hired it. A staffing worker placed on site under daily oversight usually counts as a workforce member, while a remote contractor who logs in from another firm rarely does.

When a BAA Is Legally Required

The legal trigger is narrow and mechanical. A BAA is required any time an outside party will create, receive, maintain, or transmit PHI for a covered entity. All four verbs matter here.

A vendor that only maintains PHI still counts, even a backup host that never touches the data directly. The agreement must exist before the PHI starts to flow. Signing it after the fact does not undo the exposure that already happened.

A four-step decision path for whether a vendor needs a signed business associate agreement before it can access protected health information.
A four-step decision path for whether a vendor needs a signed business associate agreement before it can access protected health information.

Two details trip people up. First, a covered entity can also be a business associate of another covered entity. A hospital running billing for a smaller clinic needs a BAA with that clinic, even though both count as covered entities on their own.

Second, subcontractors inherit the same duty down the chain. If a business associate hands PHI to its own vendor, say a cloud host or a support desk abroad, that vendor becomes a "downstream" business associate. It needs its own signed agreement with the business associate above it, not with the original covered entity.

The required contract terms are specific, not a box to check. Under 45 CFR 164.504(e), a compliant BAA must spell out the permitted uses of PHI. It must bar the business associate from using the data beyond the contract's terms.

The contract must also require safeguards and prompt breach reporting. It has to pass the same terms down to any subcontractor. It must give the covered entity the right to end the deal if the business associate breaks the terms in a material sense.

A plain non-disclosure form, or one line of privacy language buried in a services contract, does not meet these terms on its own. Firms that lean on a vendor's boilerplate terms of service often find the gap only after a breach. By then the fix is far more costly than the paperwork would have been.

When a BAA Is NOT Required

Several ties look like they need a BAA but do not. Treating them as if they did still adds paperwork with no legal payoff. The exceptions below come straight from HHS guidance, and each one turns on the nature of the access.

Treatment and Payment Ties Between Providers

A hospital that refers a patient to a specialist, and sends the chart along, does not need a BAA with that specialist. The disclosure is for treatment, not a task done on the hospital's behalf. The same logic covers a doctor sending a sample to a lab, or a hospital lab forwarding a case to a second lab for review.

This exception holds no matter how many providers touch the chart in the process. A primary care doctor, a specialist, and a hospital lab can all pass the same record back and forth for one patient's care. None of those handoffs needs its own signed agreement, since every party acts as a treating provider, not a hired vendor.

Payment follows the same rule. When a provider bills a health plan and the plan pays, each side acts as its own covered entity. Neither is the other's business associate for that swap, so no agreement covers it. A billing office that only files claims and posts its own payments stays outside the rule for that reason.

A provider that also negotiates a discounted network rate with a plan stays outside the rule too. Accepting a lower rate to join a plan's network is still the provider acting on its own behalf, not performing a function for the plan. The line only moves once the provider starts doing work, such as utilization review, that the plan would otherwise do itself.

Conduits and Incidental Contact

A "conduit" moves PHI without regularly viewing its content, much like a courier carries a sealed envelope. HHS calls this exception narrow. It generally covers firms like internet providers and couriers whose access to the data stays rare, not a routine part of the job.

A phone carrier that scans network traffic now and then to confirm delivery stays a conduit for the same reason. Its glimpse of the data is not the point of the service. That test, routine access versus rare access, is what sorts a true conduit from a business associate.

A janitorial firm that empties trash and sometimes sees a stray page fits the same idea. The contact is incidental and unavoidable, so no BAA applies. A records-shredding vendor is different, since handling PHI is the whole point of that job, and a BAA is required unless the work happens under the covered entity's own direct control.

Group Arrangements and Health Plans

Covered entities that jointly run care, such as a hospital and its medical staff, can share PHI for that joint work without a BAA between each pair. A group health plan that shares PHI with a plan sponsor, usually the employer offering the plan, generally skips the BAA rule too. Per HHS guidance, that exception only kicks in once the plan papers are amended to spell out and cap what the employer can do with the data.

Skipping that paperwork step is a common and avoidable gap, since the exception rests on the papers existing, not on good faith alone. A close cousin of this rule covers public programs like Medicare sharing data with an agency such as the Social Security Administration to check eligibility. Both cases exist because the parties are seen as running one shared task, not as one hiring the other for a separate service.

Which Situation Applies to You?

The right BAA checklist depends on which side of the tie you sit on. Match your role to one of the three groups below. Then follow its steps rather than a generic list built for someone else's setup, since the mix of vendors and judgment calls shifts a lot by role.

The Solo or Small-Practice Owner

A solo provider or small practice usually has three to eight vendors worth a look. That list often includes an EHR platform, a billing service, an IT contractor, and maybe a scheduling tool that holds patient contact details. The fastest path is a vendor-by-vendor check.

List every outside party with any system access. Mark whether PHI passes through that access, and confirm a signed BAA exists for every "yes." A vendor that only sees scrubbed scheduling data, like a plain text-reminder tool with no diagnosis attached, may not need one, but write that call down instead of only assuming it.

A single owner can usually finish this audit in an afternoon, since the vendor count stays small. The bigger risk is letting it slide once the practice grows past a handful of tools. A new billing add-on or a second scheduling app can slip in without anyone re-running the check.

The Group Practice or Health System Manager

A group practice manager juggles a longer vendor list and more workforce-versus-business-associate calls. Associate providers, locum staff, and doctors covering from other groups can land on either side of the line. It depends on their exact tie to the practice.

The fix is a standing review step. Any time a new provider, vendor, or subcontractor gets system access, one named person owns the call on whether a BAA applies. That call happens before access starts, never after the fact.

A larger group also has more moving parts to track between locations. A practice with three offices might use one billing vendor system-wide but a different local IT firm at each site, and every one of those local vendors still needs its own signed agreement. Treating "we have a BAA" as a single company-wide fact, instead of a per-vendor checklist, is the exact gap that lets a site-specific vendor slip through unnoticed.

The Business Associate Hiring Its Own Vendors

A billing firm, EHR vendor, or IT company that is itself a business associate has an extra layer to manage. Every subcontractor it uses that touches PHI needs its own downstream BAA. That covers a cloud host or a support team abroad.

A fast-growing vendor often adds subcontractors faster than its own compliance team can track them. A new analytics partner, a new customer-support desk, or a new cloud region can each show up mid-year without a downstream BAA in place. Building that check into every new-vendor onboarding step, rather than running it once a year, is what keeps the chain intact as the business associate itself keeps growing.

This is the most often missed spot. The covered entity's own BAA covers only its tie with that one business associate, not every vendor further down the chain. A firm that quietly moves its support desk overseas, without telling its covered-entity clients, opens a gap the first contract never planned for.

What a Missing BAA Costs: A Worked Example

Picture a nine-provider dental practice weighing three vendors: a cloud practice tool, an outside IT firm with server access, and a courier that moves paper charts between offices now and then. Legal review of a BAA for each vendor runs $150 to $400 in attorney time on a vendor template. Custom terms for the two vendors that truly need one run closer to $1,000 to $1,500 total, and the courier needs no agreement at all under the conduit rule.

Compare that small cost with real enforcement outcomes tied specifically to a missing BAA. OCR fined Raleigh Orthopaedic Clinic $750,000 in 2016 for handing over PHI without a signed agreement first. OCR fined Athens Orthopedic Clinic $1,500,000 in 2020, citing a failure to secure business associate agreements among its findings.

Even the smaller of the two settlements is roughly 500 times the cost of doing all three agreements right. Scale the math up to a 40-provider group with a dozen vendors, and full legal review on every deal still lands under $10,000 a year. That is a rounding error next to either fine above.

The gap grows once you count the costs beyond the fine itself. A breach case often forces a practice to pay for notification letters, credit monitoring, and forensic fees on top of any OCR penalty. None of those extra bills fall on the practice that had a signed, current BAA before the data ever moved.

Run the same math forward a few years and the gap only widens. A practice that spends $1,500 once on three solid agreements, then reviews them each year for maybe $200 in attorney time, spends under $2,500 total across five years. A single breach tied to a missing BAA, at even the smaller settlement on record, costs 300 times that five-year total in one enforcement action alone.

The time cost matters too, not only the dollar figure. Signing a BAA up front takes a practice manager a few hours to gather vendor contacts and route the paperwork for signature. Responding to an OCR breach investigation instead can consume weeks of staff time, pulling the practice manager and often the owner away from patient care for the length of the inquiry.

Where Practices Get This Wrong

Three failure patterns cover most of the missing-BAA cases seen in practice. Each teaches its own lesson. None of them repeats the others below.

Lesson one: the downstream chain breaks first. Maria runs a twelve-provider clinic and signed a solid BAA with her EHR vendor three years back. During a routine check, she learned the vendor had quietly moved its support desk to a firm abroad. That firm could view patient records for repairs, but it had never signed a downstream BAA of its own.

Maria's first agreement covered her clinic's tie with the EHR vendor. It did nothing to bind the vendor's own subcontractors, which is the exact gap the downstream rule exists to close. She fixed it by asking her EHR vendor for proof of a signed downstream deal with every subcontractor. That step is now part of her yearly vendor check.

What Maria assumedWhat was true instead
One signed BAA covers the whole vendor tie, foreverThe vendor's own subcontractors need separate, current BAAs of their own
A three-year-old agreement is still solidVendors swap subcontractors without notice, so a BAA needs a fresh look each year

Lesson two: encryption is no stand-in for an agreement. A telehealth founder thought that since patient data sat in an encrypted cloud store, the host was not a business associate at all. He assumed no BAA was needed. Encryption limits the damage if data leaks, but it does not change the vendor's legal status.

The cloud host still keeps PHI on the firm's behalf, so the fix was a signed BAA before launch, not after an OCR inquiry forced the issue. The founder now runs every new vendor through the same four-verb test before any tool goes live. That single habit caught two more vendors that needed agreements before launch day.

Lesson three: over-caution builds its own risk. A billing consultant kept getting asked to sign BAAs from clients whose work with her never touched PHI at all. They wanted to feel safe, nothing more. Signing a needless BAA is not free.

It can pull the signer into audit rights and risk that would not otherwise apply. It can later read as an admission that the signer did handle PHI after all. Once she pushed back, and the client's own lawyer reviewed the true scope of the work, a plain privacy clause replaced the BAA on jobs that fell outside the rule. That one change now saves her a dozen needless BAA fights a year.

SituationRight response
Vendor has no PHI access, client wants a BAA "to feel safe"Push back with a scope note; use a privacy clause instead
Vendor truly touches PHI to do its jobSign the full BAA before any data moves

Mistakes to Avoid

  • Assuming a template BAA is automatically compliant. A downloaded template can skip required terms like breach-reporting timelines, leaving the covered entity exposed even though a document is on file.
  • Treating one BAA as covering an entire vendor firm. A new department, a new data flow, or a new subcontractor inside the same firm can sit outside the first agreement's scope.
  • Letting the agreement lag behind the actual work. Data should never move before the BAA is signed, since a late agreement does not erase the exposure that already happened.
  • Confusing encryption or scrubbed data with an exemption. Both cut risk, but neither changes whether the vendor is legally a business associate handling real PHI.
  • Missing downstream subcontractors entirely. A vendor's own cloud host, support desk abroad, or backup firm each need a signed agreement, not a pass-through of the first one.
  • Skipping the plan-paper update for employer plans. The health-plan-sponsor exception only applies once the required plan language is in place, not by default.
  • Requiring BAAs from vendors who do not need one. Over-collecting agreements from janitorial firms or treatment-only partners adds needless contract risk with no payoff.
  • Never checking agreements after signing. Vendors change their subcontractors and storage setups over time, and a signed-once, forgotten agreement stops matching real life.

Do

  • Map every vendor with system access before you decide who needs a BAA. A written list catches the "maintains PHI" cases a quick mental check misses.
  • Require the BAA before any PHI moves, not after onboarding starts. Sequencing it first closes the gap where a stray disclosure could happen.
  • Ask new vendors straight out whether they use subcontractors. Their answer tells you if a downstream BAA chain needs to exist.
  • Put one named person in charge of the BAA list. Ownership stops the "someone else must have handled it" failure that shows up in real audits.
  • Check every active BAA at least once a year. Vendors change their subcontractors and storage setups more often than the paperwork does.

Don't

  • Don't accept a spoken promise that "we're covered." Ask to see the actual signed agreement, and check that it names the current firm.
  • Don't sign a BAA solely because a vendor asks for one. Confirm the tie truly involves PHI first, since a needless signature adds risk with no upside.
  • Don't assume covered-entity status alone protects you. Two covered entities doing work for each other still need a BAA between them.
  • Don't let one master services deal stand in for a BAA. A privacy clause buried in boilerplate rarely meets the specific required terms.
  • Don't forget a business associate can itself need BAAs with its own vendors. The chain does not stop at the first link.

Pros and Cons of Signing a Broad, Cautious BAA

Some firms choose to sign a BAA even in a gray-area case, rather than fight over the exact legal label. That choice brings real trade-offs. They are worth a look before you default to "sign it anyway."

Pros

  • Removes doubt in a gray-area tie. When it truly is not clear whether a vendor's access rises to business-associate status, a signed agreement settles the question.
  • Speeds up buying. Many large vendors will not move forward without a BAA on file, so signing early avoids a stalled deal later.
  • Creates a paper trail for audits. A signed agreement is solid proof of due care if OCR or a state regulator ever asks.
  • Sets one standard across vendors. The same safeguard and breach-notice terms apply to every vendor once BAAs become the default.
  • Cuts the cost of a future change. If a vendor's role grows to include PHI later, the agreement already sits in place.

Cons

  • Adds duties that would not otherwise exist. Audit rights and breach-notice duties all attach the moment the signature lands.
  • Can read as an admission of business-associate status. A regulator or opposing lawyer may treat the signature itself as proof the signer handles PHI.
  • Raises the paperwork load. Every signed BAA needs a fresh look now and then, which adds ongoing work for deals that were never legally needed.
  • Can clash with the true scope of work. A vendor with no real PHI access can get pulled into safeguard duties that do not fit its actual service.
  • Slows down low-risk vendor sign-up. Legal review on every deal, even needless ones, adds delay to ties that carry little real risk.

What to Do Next

  1. List every outside vendor, contractor, or tool with access to your systems, including cloud tools, IT support, and any AI-based transcription service.
  2. Mark whether PHI passes through each one, using the four-verb test: does the vendor create, receive, maintain, or transmit it on your behalf.
  3. Confirm a signed, current BAA exists for every "yes", and pull the actual document rather than trusting a vendor's website claim.
  4. Ask every business associate if it uses subcontractors that touch PHI, and require proof of a downstream BAA for each one named.
  5. Set a yearly review date for the whole BAA list, since vendor ties and subcontracting setups change without notice.
  6. Bring in a healthcare lawyer or compliance pro for any tie that stays unclear after working through the exceptions above, especially where state law may add rules HIPAA does not.

Frequently Asked Questions

Which vendor requires a business associate agreement?

Any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf. Common cases include billing services, cloud EHR hosts, IT support with system access, transcription services, and pharmacy benefits managers.

Which of the following situations is a business associate contract not required?

Treatment referrals, payment-only claims between covered entities, incidental janitorial contact, and true conduits like couriers. Each one involves either no PHI access, access that is not the point of the service, or a tie the rule exempts by name.

Can you have a BAA without a contract?

No, a BAA is itself a written contract or formal agreement. HIPAA requires the promise to be in writing, whether as its own document or a section inside a broader services deal. A spoken understanding does not meet the rule.

When should a BAA be signed?

Before any protected health information is shared with the vendor, not after work begins. Signing later leaves a gap where PHI moved without the required legal cover in place, and that gap does not close once the paperwork finally gets signed.

Do independent contractors working inside my office need a BAA?

Usually not, if their conduct sits under your direct control like an employee's. A contractor who works on site under your oversight, and follows your HIPAA rules, usually counts as a workforce member rather than a business associate.

What happens if a vendor refuses to sign a BAA?

The covered entity cannot legally keep sharing PHI with that vendor. Sending data to a vendor who turned down a required agreement is itself a HIPAA violation, no matter how solid the vendor otherwise seems.

Does a BAA need to be renewed every year?

Not by default, since most agreements stay valid until a set end date. A yearly review is still a strong habit, since a vendor's subcontractors, storage spots, and compliance posture can shift without any formal update.

Are subcontractors of a business associate also required to sign a BAA?

Yes, any subcontractor that touches PHI needs its own downstream agreement. The original covered entity's BAA with the business associate does not stretch on its own to that business associate's further vendors.

Can a covered entity be a business associate of another covered entity?

Yes, when one covered entity does a task involving PHI for another. A hospital running billing for an unaffiliated clinic is a common case, and the tie needs its own BAA despite both sides being covered entities.

Is a BAA required for a marketing vendor that only sees appointment reminders?

It depends on whether the data includes protected health information, not only contact details. A vendor sending plain reminder texts with no diagnosis attached may sit outside the rule, but write that call down rather than assume it.

What should a compliant BAA include?

Permitted PHI uses, safeguard rules, breach-report duties, and subcontractor flow-down terms, at minimum. A plain privacy clause or a vendor's boilerplate terms of service often skips several of these required parts.

Does encrypting the data remove the need for a BAA?

No, encryption lowers breach risk but does not change business-associate status. A cloud host that keeps encrypted PHI on a covered entity's behalf is still a business associate under the plain text of the rule.