Vendors and BAAs
Know which vendors touch patient data, and whether the paperwork exists.
A register of every vendor that handles patient information on your behalf, with agreement status, dates and owners — fed by our published research on which tools are usable in the first place.
Last reviewed .
Most organizations discover the gap when a client asks, not before.
A signed agreement with your own client does not cover the clearinghouse, the storage provider, the phone system or the offshore contractor sitting underneath you. Each of those relationships needs its own agreement, and the register is what turns that from a memory exercise into a list.
Backed by researched verdicts
Add a vendor and our own published research attaches: whether an agreement is available, on which plan, the conditions that apply, and the primary sources behind it with the date we read them.
Expiry and renewal tracking
Agreements with end dates are tracked and surfaced before they lapse, rather than discovered lapsed during a security review.
Owners, so it is somebody's job
Each vendor has a named owner. Chasing an unsigned agreement is a task with a due date like any other gap.
Exports as a subprocessor list
Enterprise reviewers ask who else touches the data. The register exports as a section of the Trust Packet in the shape they expect.
What a business associate agreement must contain
The required provisions are set out at 45 CFR 164.504(e). An agreement missing them is not a business associate agreement, whatever it is titled — which matters, because vendors routinely offer a confidentiality addendum under the name.
- Permitted uses and disclosures
- What the business associate may do with the information, limited to what the contract and the rule allow. It may not use or disclose it in ways the covered entity itself could not.
- Safeguards
- A commitment to implement appropriate safeguards, and for electronic information, the Security Rule requirements specifically.
- Reporting
- An obligation to report breaches and any use or disclosure not permitted by the contract. The timeframe is negotiable and worth negotiating — the rule's outer limit is 60 days from discovery, and many covered entities require far faster.
- Subcontractor flow-down
- Every subcontractor that touches the information must agree to the same restrictions. This is the clause most often missing in practice, and the one that makes your own vendor list a compliance artifact rather than a purchasing record.
- Access, amendment and accounting
- Where the business associate holds a designated record set, provisions letting the covered entity meet individuals' rights of access and amendment, and to account for disclosures.
- Availability to HHS
- Practices, books and records relating to the use and disclosure must be made available to the Secretary for determining compliance.
- Return or destruction on termination
- At the end of the relationship, information is returned or destroyed if feasible; where it is not feasible, the protections continue for as long as it is retained.
- Termination for breach
- The covered entity may terminate if the business associate materially breaches the agreement.
Our free BAA template generator walks these provisions and produces a plain-language starting document. It is a starting point requiring your counsel's review, not a substitute for it.
The subcontractor chain, and where it breaks
The obligation flows all the way down. A covered entity signs with you; you sign with everyone underneath you; they sign with everyone underneath them. Reviews find the break most often in the same few places, because these are the vendors nobody thinks of as vendors.
| Category | Typical examples | Why it is missed |
|---|---|---|
| Infrastructure | Cloud hosting, object storage, managed databases, backup | Treated as plumbing rather than a party that holds the data. |
| Communications | Email, e-fax, VoIP with recording or voicemail transcription, SMS | A voicemail with a patient name in it is patient information. |
| Support tooling | Helpdesk and ticketing, screen sharing, remote access, error monitoring | A support ticket or a stack trace can carry patient data unintentionally. |
| Analytics and marketing | Product analytics, session replay, email marketing, ad pixels | Session replay on an authenticated page is a well-documented enforcement risk. |
| People | Offshore coding or transcription partners, contract developers, virtual assistants | Contractors are workforce members or subcontractors; either way they need covering. |
| AI services | Assistants and model APIs used on real data | The newest gap. Most consumer tiers will not sign, and the enterprise tier that will is a different product. |
Our published vendor research covers which of these will sign an agreement, on which plan, and under what conditions — with the primary sources and the date each was read. Adding a vendor to your register attaches that research automatically.
Renewal, review and what happens when a vendor changes
An executed agreement is not a permanent state. Vendors are acquired, change their terms, move a feature between plan tiers, or move data to a new sub-processor — and none of those events send you a notice you will act on.
Record the agreement with its dates
Signed date, expiry or renewal date where there is one, and which plan tier the agreement attaches to. The plan tier matters: agreements are frequently withdrawn when an account downgrades.
Set a review date even when there is no expiry
Many agreements are evergreen. Evergreen means nothing forces you to look at it again, which is precisely why a scheduled review is worth more here than on an agreement that expires.
Let the reminders do the chasing
Agreements approaching expiry or review surface to owners and administrators in a digest rather than requiring somebody to remember.
Re-check on a vendor event
Acquisition, a pricing or plan restructure, a breach in the news, or a change to the vendor's own trust page. Each is a reason to re-read the agreement rather than assume it still says what it said.
Keep the superseded versions
Six-year retention applies to agreements too, and the version in force at the time of an incident is the one that governs it.
Common questions
- Who is required to have a BAA?
- A covered entity with every vendor that creates, receives, maintains or transmits patient information on its behalf — and each of those vendors with its own subcontractors. A vendor that never touches it, like bookkeeping software you keep patient detail out of, generally does not require one.
- How do you get a business associate agreement?
- Most established vendors publish a standard agreement you accept in the admin console or request from their legal page — each entry in our vendor research links to exactly where. For subcontractors without one, HHS publishes sample provisions you can build on. The register tracks which agreements exist, which are missing, and when each needs revisiting.
- Is a BAA the same as an NDA?
- No. An NDA is a confidentiality promise between two parties. A business associate agreement is a HIPAA-required contract that obliges the vendor to implement Security Rule safeguards, report breaches, and accept direct regulatory liability. An NDA does not substitute, however strongly worded.
- What is an example of a business associate under HIPAA?
- A medical billing company, an IT provider or MSP with access to client systems, a cloud storage or email vendor holding patient information, an e-fax service, a transcription service. If a vendor performs a function involving patient information on your behalf, it belongs in the register.
Keep reading
- HIPAA risk assessment softwareGuided assessment with remediation tracking and carry-forward.
- Policies and acknowledgementsVersioned policies your staff read and sign.
- Staff training and certificatesAnnual courses with dated certificates and chasing.
- Incident and breach logFour-factor assessment with the deadline counting down.
- Free BAA template generatorA plain-language agreement with every required provision, built in your browser.
Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.