Office Consumer is reader-supported. We may earn an affiliate commission from qualified links on our site.

Who Needs to Sign a Business Associate Agreement Under HIPAA? (w/Examples) + FAQs

Any vendor that creates, gets, stores, or sends protected health data for a covered entity must sign a business associate agreement before that data moves. That covers billing firms, cloud hosts, and IT support firms, but not the mail carrier or a treating doctor next door.

The rule reaches solo practices as often as hospitals. HHS fined one practice $240,000 in 2024 for using a vendor with no signed agreement in place, according to HIPAA Journal's enforcement tracker. A missing BAA anywhere in a vendor chain can undo years of clean compliance. This article reflects federal HIPAA rules as of 2026, and state privacy law can add stricter duties on top of that floor. Treat it as education, not a stand-in for advice from healthcare counsel about your own vendors.

🔍 What makes a vendor a business associate under the law

📋 Which real vendors need a signed BAA, and which don't

⚖️ How the narrow conduit exception works, and where it stops

🧩 What a compliant agreement has to say, in plain terms

✅ The exact steps to take before you hand PHI to a vendor

Federal Rules on Business Associate Agreements, and Why State Law Still Matters

HIPAA sets a national floor for how protected health information, shortened here to PHI, moves between a covered entity and its vendors. That floor comes from the Privacy Rule at 45 CFR 160.103, and it works the same in every state. States can add tougher privacy or breach-notice duties on top, and a later section flags where that overlay tends to matter.

Before 2009, a covered entity often shared PHI with a vendor on nothing more than a verbal promise to keep it safe. The HITECH Act changed that by making business associates directly liable under HIPAA, not only the covered entity that hired them, according to HIPAA Journal's BAA guide. That shift is why a signed BAA now protects both sides of the deal, not one alone.

Size does not exempt anyone from this rule. A single-provider practice and a five-hundred-bed hospital face the same legal standard the moment PHI reaches a vendor. What changes with size is not the requirement itself, but how many vendor deals a practice has to track and renew, and how much staff time that tracking takes each year.

This guide explains the federal rule. It is not legal advice for your own vendor list. HIPAA compliance carries real money and legal risk, so bring in healthcare counsel for any unusual, multi-state, or high-risk vendor deal. A short talk before signing costs far less than an OCR review after PHI moved with no BAA.

The dollar figures and enforcement examples in this guide come from cases HHS and industry trackers reported through 2026. A rule or figure that changes after this guide goes live will not show up here on its own, so treat every number as a snapshot, not a fixed fact. Checking HHS's own site before you act is the safest habit when money or legal exposure is on the line.

Who Counts as a Business Associate Under HIPAA

A business associate is any person or group outside a covered entity's own staff that handles PHI to do a job for that entity. The Privacy Rule names specific jobs at 45 CFR 160.103: claims work, billing, utilization review, quality assurance, and practice management. It also names legal work, accounting, consulting, and data aggregation, any time these touch PHI.

If a vendor's job needs PHI to get done, that vendor is a business associate. Size or how casual the job sounds does not change that. Skipping this step has a real cost: with no signed BAA, there is no legal promise the vendor will protect the data, and OCR treats that gap as its own violation. This is true even when the vendor never once mishandles a record.

A common myth: only firms with "medical" in their name qualify. HHS's own guidance names a CPA firm doing a provider's books, a lawyer reviewing patient files for a health plan, and a transcriptionist as textbook business associates. Each sounds like an ordinary vendor, yet each needs full PHI access to do its job.

Employees never sign BAAs with their own employer, since a covered entity's own staff is not a business associate of itself. A health plan or provider can still become a business associate of a different covered entity, when it does a service for that other entity. The test always comes back to one question: does this job need PHI to happen at all?

Picture a staffing agency that places a nurse on a covered entity's own payroll. That nurse joins the covered entity's staff, so no BAA applies. Now picture the same agency keeping a different nurse as its own worker, doing billing review from afar. That worker touches PHI through the agency's own systems, and that access alone makes the agency a business associate.

Which Situation Applies to You?

The right next step depends on which side of the vendor deal you sit on. A covered entity, a new vendor, a subcontractor, and a solo practitioner each face a different starting question. Find your situation below, since the wrong starting question can send you looking for the wrong fix.

If you run a covered healthcare practice

You are the party legally required to get satisfactory assurances, in writing, from every vendor that touches PHI on your behalf. That means a signed contract meeting the standard at 45 CFR 164.504(e), signed before any PHI is shared, not after the vendor deal is already running. If you lack a signed agreement for a vendor handling PHI today, treat that gap as urgent, not a task for next quarter. Practices that wait until renewal season often find the gap only after a breach forces the question.

Keep a running list of every vendor with PHI access. Update it whenever a new tool or contractor joins the mix. A yearly review catches web tools that quietly gained access to scheduling or billing data with no one flagging the step. That list also helps during an OCR review, since it shows the practice tracks its own vendor deals.

If you are a vendor being asked to sign

Refusing a BAA does not free a vendor from HIPAA once it does a qualifying job. A vendor doing business associate work is a business associate whether or not paperwork exists. The real choice is between signing now, on terms the vendor helped set, or facing the same duties later with no say in them. Vendors that never touch PHI, such as a pure equipment supplier, are the exception, and can say so plainly instead of signing something that does not fit.

A vendor with real questions about scope, such as how fast it must report a breach, should raise them before signing, not after an audit request arrives. Fixing unclear terms up front is normal, since both sides answer to OCR if the wording is vague. A vendor that signs without reading closely risks agreeing to rules it cannot meet.

If you are a subcontractor two steps removed

Subcontractors that help a business associate handle PHI are business associates too, under the Rule. They sign a Subcontractor BAA with that business associate, not the covered entity itself. That deal must carry the same limits the BAA above it sets. A subcontractor that thinks "the hospital's rules do not reach me" is wrong, since the same duties flow down every link.

A subcontractor should ask for a copy of the BAA above it, so its own agreement matches the same safeguards and report deadlines. Mismatched terms between the two create a gap regulators can flag during a review. Treating the Subcontractor BAA as a mere formality, rather than a true match to the agreement above it, is one of the more common gaps auditors find.

If you are a solo practitioner

A one-person practice is still a covered entity if it bills electronically for care. The BAA rule applies at any size, with no small-practice exception. A solo dentist or therapist most often needs BAAs with the EHR vendor, the billing service, and any cloud backup tool, the same short list a large group needs. Many EHR and billing vendors hand over a standard BAA during onboarding, which cuts the workload for a small practice a great deal.

A solo practitioner with no in-house lawyer can still meet this standard. Ask each vendor, before onboarding starts, whether it will sign a BAA. Most established EHR, billing, and cloud vendors already expect this request and keep a template ready. The ones that hesitate or push back on a fair ask deserve the closest look before you sign anything else.

The Conduit Exception and Other Narrow Carve-Outs

HHS carves out a small set of cases where PHI moves with no BAA needed, and the conduit exception is the one people misapply most. It covers groups like the U.S. Postal Service and private couriers, plus their electronic equivalents, since these entities move data without ever opening, reading, or storing its content. A courier that carries a sealed envelope is a conduit. A cloud vendor that keeps a searchable copy of the same data is not, even when that copy sits encrypted.

Other real carve-outs exist too. A hospital that sends a chart to a specialist for care needs no BAA with that specialist, since it is a treatment referral. A bank that runs a routine card payment falls outside the Rule too, since HHS treats card transactions as banking, not business associate work. Data that has been properly de-identified sits outside HIPAA entirely, since it stops being PHI.

None of these carve-outs apply simply because a vendor calls itself a "platform" or promises not to look at the data. The real test is the function the vendor performs, never the vendor's own label for that function. A common misconception is that encryption alone turns a business associate into a conduit.

Compliancy Group's BAA guidance is direct here: cloud vendors like AWS or Dropbox stay business associates even when they store only encrypted PHI and never hold the key. OCR treats stored access itself as the trigger, not whether the vendor can read the content. A practice that skips a BAA on the idea that "our vendor cannot see the data" leans on a line the Rule does not draw.

A dental practice that mails patient statements needs no BAA with the post office, since the carrier never opens or reads a single statement. The same practice would need one if it hired a mailing house that opens files to add patient details to each statement, since that step needs real access to PHI. The line between the two comes down to whether someone inside the vendor reads the content.

A Worked Example: Bringing a Billing Vendor Onboard

A realistic timeline shows how this rule plays out. Dr. Alvarez runs a four-provider dermatology group and decides to outsource claims work to a regional billing company instead of hiring in-house staff. Before that vendor touches a single claim, its job alone, processing claims that hold PHI, makes it a business associate under 45 CFR 160.103. That is true no matter how the sales contract describes the deal.

The compliant sequence runs in four steps:

  1. The practice drafts or adapts a BAA that covers permitted uses, required safeguards, and breach-reporting timelines.
  2. Both parties sign it before the first claim file with patient data goes out, never after.
  3. If the billing company later hires its own coding subcontractor, that subcontractor signs a matching agreement with the billing company, not with the practice.
  4. The practice keeps a signed copy on file and revisits it whenever the scope of services changes.

Skipping step two is the exact failure OCR punished in 2018, when it fined Advanced Care Hospitalists $500,000. OCR found the practice had shared PHI with a billing vendor with no BAA in place. The dollar figure is not automatic for every missing agreement, since fines scale with fault and whether a breach even occurred. Even so, the case shows the gap alone can draw a fine, well before the cost of cleanup or the damage to a practice's name.

Dr. Alvarez's practice could have skipped this risk by building the BAA into its vendor-selection checklist from the start. Many billing firms now hand over their own BAA template during the sales call, since so many practices raise the point too late. Asking for that template on the first call, before any files change hands, keeps the timeline clean.

The same four-step sequence applies whether the new vendor is a billing firm, a cloud host, or a scheduling app, since the trigger is always PHI access, not the vendor's industry label. A practice that builds this checklist once can reuse it for every future vendor, rather than relearning the steps each time a new contract comes up. That consistency is often what auditors look for first, since it shows the compliance habit is a system, not a one-off scramble after a close call.

A three-step decision flow for deciding whether a vendor needs a HIPAA business associate agreement.
A three-step decision flow for deciding whether a vendor needs a HIPAA business associate agreement.

Four Vendor Relationships That Trip Practices Up

Naming a vendor category is easy. Understanding why one category needs a BAA and another does not takes a closer look at four situations that come up constantly in real practices. Each one turns on a different piece of the rule, so the same yes-or-no answer will not cover all four.

The cloud storage vendor and the encryption myth

Rosa runs IT for a mid-size orthopedic group. She assumed its new cloud backup vendor was exempt, since every file sat encrypted at rest. She learned otherwise when the vendor's own team asked for a BAA at onboarding, citing the same access rule HIPAA Journal describes for AWS and Dropbox. Where the data sits, and whether it is encrypted, do not decide business associate status; ongoing access to the data does, and a vendor holding an encrypted copy still holds a copy.

Storage detailDoes it change BAA status?
Data encrypted at restNo, access itself is the trigger
Vendor lacks the decryption keyNo, persistent storage still counts
Data is fully de-identifiedYes, de-identified data is not PHI

Rosa's group now asks this question of every new SaaS tool before signup, not only obvious storage vendors. A scheduling app or patient-messaging tool can quietly gain the same kind of persistent access a cloud backup vendor has. Checking at signup, rather than after the tool is already in daily use, keeps the gap from opening in the first place.

The billing company and the claims-processing function

Tom's two-doctor family practice hired a national billing firm for revenue work, and the sales rep first called it "only software," hinting no BAA was needed. But the firm's real job was processing claims with PHI in them, not licensing software, so it counted as a business associate under the same test as above. Tom's practice held firm and got a signed BAA first. This lesson differs from Rosa's case: it turns on whether the service needs PHI at all, not on where the data sits.

Tom's story is common. Many billing vendors already keep a signed BAA template ready, since so many healthcare clients ask for one sooner or later. The delay usually comes from the practice asking late, not from the vendor saying no. Raising the point during the sales call, before any contract is signed, turns the BAA into a normal part of onboarding instead of an afterthought.

The IT support contractor with system access

Priya's practice long assumed IT support sat outside HIPAA, on the theory that "they only fix computers." That rule predates how deeply IT vendors now connect to clinical systems. Once her contractor got remote access to the EHR server to fix outages, that access made the vendor a business associate. Accountable's guidance lists IT support with system access next to billing firms and cloud hosts as a common, easily missed case.

Priya's practice fixed the gap fast. It asked its IT vendor for a BAA the same week remote access was granted, rather than waiting for the next contract renewal. The vendor already had a template on file, since most of its healthcare clients ask for the same thing. The bigger lesson: access itself, not the vendor's job title, decides when a BAA becomes necessary.

The shredding vendor versus the mail carrier

A shredding firm that destroys discharge summaries and billing statements is a business associate. Handling and destroying PHI is the core of its work, not a side effect. Compare that with a courier who drops off sealed lab boxes at the same practice and never opens a single record. That courier is a plain conduit, and the table below shows why one needs a BAA and the other does not.

VendorBAA required?
Document shredding or destruction serviceYes, PHI is the core of the service
Postal carrier or courier, sealed and unopenedNo, conduit exception applies
Cloud backup or data hosting providerYes, persistent access to PHI
Pure equipment supplier with no data accessNo, no PHI ever changes hands

What a Compliant Business Associate Agreement Must Include

A BAA is not a plain confidentiality form. It has to cover specific parts the Privacy Rule requires at 45 CFR 164.504(e). At minimum, it must state the allowed uses of PHI, and bar the vendor from using or sharing PHI beyond what the contract or law allows. It must also require real safeguards against any unfit use or leak.

The BAA must require the vendor to report security incidents and breaches within a set window. It must also require the vendor to return or destroy all PHI once the work ends, unless that is truly impossible. If a covered entity later learns of a real breach of the terms, the Rule tells it to fix the problem, and to end the contract if that fix fails.

A common myth is that a downloaded template covers all of this on its own. HIPAA Journal warns that many free templates were built for a different kind of service, so they need real edits before they fit a given vendor's actual job. A template written for a software vendor, for example, may say nothing about physical document destruction.

Getting this wrong has a real cost. A BAA missing the breach-report or safeguards text can leave a covered entity unable to show OCR it got the satisfactory assurances the Rule demands, even if a document was signed. Check any vendor template against these parts line by line, rather than trust a good-looking form on sight. A fifteen-minute checklist review now beats a six-month fix-it plan later.

Beyond these basics, a strong BAA also states how fast the vendor must report a suspected breach. A vague timeline can leave a covered entity unable to meet its own notice deadline under the Breach Notification Rule. That clock starts the moment the covered entity first knew, or should have known, about the breach. A covered entity checking a vendor's form should look for a set number of days, not a vague promise to report "soon."

How the BAA Chain Works With Subcontractors

Every downstream link in a vendor chain needs its own signed BAA, and the chain runs in one direction only. The covered entity signs a BAA with its direct business associate. That business associate then signs a Subcontractor BAA with any helper it brings in. Compliancy Group confirms this setup: covered entities need not sign with subcontractors, since that job sits with the business associate above them.

Picture a five-party chain: a hospital hires a billing firm, which hires a coding subcontractor, which hires an offshore data-entry firm. Each link needs its own signed BAA with matching rules. A gap at any single link breaks the cover for the whole chain, even if the other three agreements are flawless. This shows up in something as plain as a patient's records request, where HIPAA requires a covered entity to act within 30 days, with one possible 30-day extension on written notice, and a long vendor chain can eat up that whole window before the patient sees a single record.

A common myth is that the job ends once the top agreement is signed. What you should do instead is ask every direct business associate, in writing, to name its own subcontractors and confirm they carry matching agreements. Do not settle for a general promise that "we handle that." A covered entity that never asks this question has no real view of how many hands its patients' records pass through.

Renewal timing deserves its own note here. A BAA written for one scope of work does not cover a new service the same vendor adds later, so a billing firm that expands into coding review needs its old BAA checked, not assumed current. Set a reminder to revisit every active BAA when a vendor deal changes in any real sense.

A short vendor questionnaire can make this chain visible instead of guessing at it. Ask each direct business associate to list every subcontractor it uses, what each one touches, and whether a signed BAA covers that subcontractor today. Keep those answers with the main BAA file, so the next audit or renewal starts from a real map of the chain rather than a fresh search.

Does My State Differ From the Federal HIPAA Floor?

HIPAA sets the federal floor. A stricter state rule on top of it still stands. When a state's health-privacy or breach law is tougher than HIPAA, Compliancy Group notes that the tougher state rule wins. A compliant BAA has to match whichever rule applies in that state, not only the federal minimum in this guide.

This overlay matters most for breach-notice timing and the scope of what counts as protected data. Some states define covered health data more broadly than HIPAA does. Some set shorter reporting windows than the federal Breach Notification Rule requires. A practice that works across state lines, or uses a vendor that does, cannot assume one BAA template fits every state it touches.

State rules change often and vary widely, so this guide cannot list every state's exact rule with confidence. Confirm your own state's current health-privacy and breach rules with healthcare counsel. Do not treat the federal baseline here as the whole picture. A quick call to a compliance lawyer before renewal season costs far less than finding the gap during a review.

A practice in a state with a strict health-privacy law may need to notify patients faster than federal rules require. Its BAA language should match that shorter window. A vendor that works nationally often picks the toughest rule it faces anywhere, rather than writing a separate deal for each state. That habit can leave a practice with stronger cover than its own state demands, since the vendor picked the toughest rule for its whole client base.

A practice that assumes its BAA works everywhere, with no state check, risks a gap the federal floor alone will not catch. This risk grows for telehealth and multi-state groups, where patients and vendors sit in different states under different rules. Checking state rules with the federal floor, ideally with a lawyer, closes that gap before it turns into real risk.

Mistakes to Avoid With Business Associate Agreements

  • Sharing PHI before the agreement is signed. The BAA must be in place before any protected data moves, not drafted afterward once a vendor already has access.
  • Assuming encryption removes the requirement. A vendor holding an encrypted copy of PHI is still a business associate, and skipping the agreement on this theory leaves the practice unprotected.
  • Treating IT support as automatically exempt. Remote access to systems containing PHI makes a support contractor a business associate, whatever the invoice calls the service.
  • Letting a vendor's confidentiality clause substitute for a BAA. A generic NDA does not include the specific safeguards, breach-reporting, and data-return terms HIPAA requires.
  • Forgetting to require subcontractor BAAs from vendors. One unprotected link anywhere in the chain exposes every patient record that passes through it.
  • Using an unmodified template from the internet. A boilerplate BAA built for a different type of service can omit required elements or misdescribe the actual data flow.
  • Failing to track BAA renewal or expiration. An agreement tied to a service that changed scope, with no updated BAA, leaves the new activities uncovered.
  • Ignoring stricter state breach-notification deadlines. A BAA drafted only to the federal timeline can leave a practice noncompliant the moment a stricter state deadline applies.
  • Not confirming return or destruction of PHI at contract end. Data left behind after a vendor deal ends is an overlooked and lingering breach risk.

Do's and Don'ts for Managing Business Associate Agreements

Keep this list nearby the next time a new vendor deal starts, or an existing one changes scope. Most of these habits take minutes to check but close gaps that otherwise sit unnoticed for years. A quick pass through both lists before signing anything new is far cheaper than fixing a missing agreement after a breach.

Do

  • Do sign the BAA before any PHI is shared, because paperwork added later does not erase the exposure of the gap.
  • Do inventory every vendor that touches PHI at least once a year, since new tools and integrations get added quietly between reviews.
  • Do require proof of subcontractor BAAs from every business associate, not only a verbal assurance that "we've got it covered."
  • Do compare a vendor's template BAA against the required elements, so a professional-looking document is not mistaken for a complete one.
  • Do involve healthcare counsel for unusual or multi-state vendor arrangements, since state overlays can change what the agreement must say.

Don't

  • Don't assume a small vendor is too minor to need an agreement, because size has no bearing on whether its function involves PHI.
  • Don't rely on a vendor's promise not to look at the data, since access, not intent, is what the Rule measures in practice.
  • Don't skip the agreement because a deal is temporary, since even short-term access to PHI still triggers the requirement.
  • Don't let a vendor dictate terms with no review, because an unread BAA can leave out breach-reporting timelines the practice needs.
  • Don't wait for a breach to check whether a BAA exists, since that is the worst possible moment to discover a signature is missing.

Pros and Cons of Using a Standard BAA Template

A standard template speeds up onboarding, but it carries its own trade-offs. Weigh the time it saves against the edits it skips, especially for a vendor whose service does not match the template's first purpose. The right call often depends on how unusual the vendor deal is, not on the template's overall quality.

Pros

  • Templates save time on routine vendor deals, since drafting a full agreement from scratch for every vendor is impractical for a busy practice.
  • They set a consistent baseline across similar vendors, which makes tracking and renewal easier.
  • Many EHR and billing vendors supply their own compliant template, lowering the burden on a small practice with no in-house counsel.
  • A widely used template is easier for a vendor's legal team to review quickly, which can speed up signing.
  • Templates reduce the odds of leaving out a required element that an ad hoc, hand-written agreement might miss entirely.

Cons

  • A generic template may not match the actual data flow, since it was likely written for a different type of service.
  • It may miss state-specific breach-notification language that a stricter jurisdiction requires on top of the federal baseline.
  • Relying on it can create false confidence that compliance is complete once the document is signed, even if the underlying safeguards were never checked.
  • Templates rarely address subcontractor flow-down clearly, leaving the practice to chase that detail separately.
  • A vendor-provided template may favor the vendor's liability position, since the vendor is usually the one who drafts it.

What to Do Next Before You Sign Anything

  1. List every vendor, contractor, and subcontractor that currently touches PHI in any form, including cloud tools added informally.
  2. Pull the current signed BAA for each one, and flag any vendor on the list with none on file.
  3. Compare each existing BAA against the required elements: permitted uses, safeguards, breach reporting, and return-or-destroy terms.
  4. Ask every direct business associate, in writing, to name and confirm coverage for its own subcontractors.
  5. Check your state's breach-notification and health-privacy rules for anything stricter than the federal baseline.
  6. Bring in healthcare counsel for any vendor deal that is unusual, multi-state, or already tied to a complaint or breach.
  7. Set a recurring annual review date so new vendors never slip through without a signed agreement.

Frequently Asked Questions

Does every vendor with any PHI access need a signed BAA?

Yes. Any vendor that creates, receives, maintains, or transmits PHI to perform a service for a covered entity needs a signed BAA before that data moves, with only narrow carve-outs like the conduit exception.

Does a cloud storage provider count as a business associate if the data stays encrypted?

Yes. Persistent access to stored PHI makes a cloud vendor a business associate even when the data is encrypted and the vendor never holds the decryption key.

Is the U.S. Postal Service or a private courier a business associate?

No. Couriers that move sealed data without opening it fall under the conduit exception, so no BAA is needed.

Do subcontractors of a business associate need their own signed agreement?

Yes. Subcontractors that handle PHI for a business associate must sign their own Subcontractor BAA, carrying the same rules further downstream.

What happens if a practice never signs a required BAA?

Investigations and fines can follow. OCR has fined covered entities for missing BAAs alone, sometimes with no data breach involved at all.

Is a business associate agreement the same thing as an NDA?

No. A plain confidentiality form skips the safeguards, breach reports, and data-return rules a BAA needs.

Who signs first, the covered entity or the business associate?

Neither has to sign first by rule. What matters is that both parties execute the agreement before any PHI is shared, not the order of the two signatures.

Does a solo practitioner need a business associate agreement with anyone?

Yes. A one-person practice that bills online is still a covered entity, and it needs BAAs with its EHR, billing, and cloud-backup vendors, the same as a larger group.

Is an IT support company a business associate?

Yes, if it can access systems with PHI. Remote fix-it access to an EHR server is enough to make a support firm a business associate, no matter what the contract calls it.

Does a billing or coding company need a BAA?

Yes. Processing or submitting claims that contain PHI is a core business associate function, whether the vendor calls itself a service provider or a software company.

Can a vendor legally refuse to sign a BAA?

It can refuse the paperwork, not the underlying duty. A vendor doing a qualifying job is a business associate under HIPAA regardless, so refusing only leaves the deal uncovered.

Do state privacy laws ever change who needs a BAA?

They can add tougher terms, not remove the federal rule. A state may ask for broader breach notice or tighter safeguards, so confirm your state's current rules on top of the federal floor here.