CompyMax

Vendors and BAAs

Know which vendors touch patient data, and whether the paperwork exists.

A register of every vendor that handles patient information on your behalf, with agreement status, dates and owners — fed by our published research on which tools are usable in the first place.

Last reviewed .

Most organizations discover the gap when a client asks, not before.

A signed agreement with your own client does not cover the clearinghouse, the storage provider, the phone system or the offshore contractor sitting underneath you. Each of those relationships needs its own agreement, and the register is what turns that from a memory exercise into a list.

Backed by researched verdicts

Add a vendor and our own published research attaches: whether an agreement is available, on which plan, the conditions that apply, and the primary sources behind it with the date we read them.

Expiry and renewal tracking

Agreements with end dates are tracked and surfaced before they lapse, rather than discovered lapsed during a security review.

Owners, so it is somebody's job

Each vendor has a named owner. Chasing an unsigned agreement is a task with a due date like any other gap.

Exports as a subprocessor list

Enterprise reviewers ask who else touches the data. The register exports as a section of the Trust Packet in the shape they expect.

What a business associate agreement must contain

The required provisions are set out at 45 CFR 164.504(e). An agreement missing them is not a business associate agreement, whatever it is titled — which matters, because vendors routinely offer a confidentiality addendum under the name.

Permitted uses and disclosures
What the business associate may do with the information, limited to what the contract and the rule allow. It may not use or disclose it in ways the covered entity itself could not.
Safeguards
A commitment to implement appropriate safeguards, and for electronic information, the Security Rule requirements specifically.
Reporting
An obligation to report breaches and any use or disclosure not permitted by the contract. The timeframe is negotiable and worth negotiating — the rule's outer limit is 60 days from discovery, and many covered entities require far faster.
Subcontractor flow-down
Every subcontractor that touches the information must agree to the same restrictions. This is the clause most often missing in practice, and the one that makes your own vendor list a compliance artifact rather than a purchasing record.
Access, amendment and accounting
Where the business associate holds a designated record set, provisions letting the covered entity meet individuals' rights of access and amendment, and to account for disclosures.
Availability to HHS
Practices, books and records relating to the use and disclosure must be made available to the Secretary for determining compliance.
Return or destruction on termination
At the end of the relationship, information is returned or destroyed if feasible; where it is not feasible, the protections continue for as long as it is retained.
Termination for breach
The covered entity may terminate if the business associate materially breaches the agreement.

Our free BAA template generator walks these provisions and produces a plain-language starting document. It is a starting point requiring your counsel's review, not a substitute for it.

The subcontractor chain, and where it breaks

The obligation flows all the way down. A covered entity signs with you; you sign with everyone underneath you; they sign with everyone underneath them. Reviews find the break most often in the same few places, because these are the vendors nobody thinks of as vendors.

CategoryTypical examplesWhy it is missed
InfrastructureCloud hosting, object storage, managed databases, backupTreated as plumbing rather than a party that holds the data.
CommunicationsEmail, e-fax, VoIP with recording or voicemail transcription, SMSA voicemail with a patient name in it is patient information.
Support toolingHelpdesk and ticketing, screen sharing, remote access, error monitoringA support ticket or a stack trace can carry patient data unintentionally.
Analytics and marketingProduct analytics, session replay, email marketing, ad pixelsSession replay on an authenticated page is a well-documented enforcement risk.
PeopleOffshore coding or transcription partners, contract developers, virtual assistantsContractors are workforce members or subcontractors; either way they need covering.
AI servicesAssistants and model APIs used on real dataThe newest gap. Most consumer tiers will not sign, and the enterprise tier that will is a different product.

Our published vendor research covers which of these will sign an agreement, on which plan, and under what conditions — with the primary sources and the date each was read. Adding a vendor to your register attaches that research automatically.

Renewal, review and what happens when a vendor changes

An executed agreement is not a permanent state. Vendors are acquired, change their terms, move a feature between plan tiers, or move data to a new sub-processor — and none of those events send you a notice you will act on.

  1. Record the agreement with its dates

    Signed date, expiry or renewal date where there is one, and which plan tier the agreement attaches to. The plan tier matters: agreements are frequently withdrawn when an account downgrades.

  2. Set a review date even when there is no expiry

    Many agreements are evergreen. Evergreen means nothing forces you to look at it again, which is precisely why a scheduled review is worth more here than on an agreement that expires.

  3. Let the reminders do the chasing

    Agreements approaching expiry or review surface to owners and administrators in a digest rather than requiring somebody to remember.

  4. Re-check on a vendor event

    Acquisition, a pricing or plan restructure, a breach in the news, or a change to the vendor's own trust page. Each is a reason to re-read the agreement rather than assume it still says what it said.

  5. Keep the superseded versions

    Six-year retention applies to agreements too, and the version in force at the time of an incident is the one that governs it.

Common questions

Who is required to have a BAA?
A covered entity with every vendor that creates, receives, maintains or transmits patient information on its behalf — and each of those vendors with its own subcontractors. A vendor that never touches it, like bookkeeping software you keep patient detail out of, generally does not require one.
How do you get a business associate agreement?
Most established vendors publish a standard agreement you accept in the admin console or request from their legal page — each entry in our vendor research links to exactly where. For subcontractors without one, HHS publishes sample provisions you can build on. The register tracks which agreements exist, which are missing, and when each needs revisiting.
Is a BAA the same as an NDA?
No. An NDA is a confidentiality promise between two parties. A business associate agreement is a HIPAA-required contract that obliges the vendor to implement Security Rule safeguards, report breaches, and accept direct regulatory liability. An NDA does not substitute, however strongly worded.
What is an example of a business associate under HIPAA?
A medical billing company, an IT provider or MSP with access to client systems, a cloud storage or email vendor holding patient information, an e-fax service, a transcription service. If a vendor performs a function involving patient information on your behalf, it belongs in the register.

Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.