Practice administrator signing a vendor agreement beside a laptop

The Short Answer

Any vendor that handles, stores, processes, or transmits protected health information (PHI) on behalf of your practice is a Business Associate under HIPAA. Before that vendor touches a single patient record, your practice must have a signed Business Associate Agreement (BAA) in place. A missing or incomplete BAA is one of the most common findings in HIPAA enforcement actions, and it is entirely preventable.

This article explains which vendors need a BAA, what the agreement must actually say, where IT operations fit into the picture, and what your practice should be verifying on a regular basis.

What Is a Business Associate Agreement?

A BAA is a written contract between a covered entity (your medical practice) and a Business Associate (a vendor or subcontractor) that creates legally binding obligations around how PHI is handled. The HIPAA Privacy Rule and Security Rule together define what those obligations must include. The agreement does not transfer your practice's compliance responsibility to the vendor. It documents what each party is required to do, and it gives your practice a contractual remedy if the vendor fails.

The agreement exists because HIPAA recognized that most healthcare organizations rely on outside parties to operate. The law extends its requirements to those parties rather than letting PHI flow freely outside the covered entity's walls.

Which Vendors Require a BAA: A Working Framework

The test is straightforward: does the vendor create, receive, maintain, or transmit PHI in the course of providing a service to your practice? If yes, a BAA is required before services begin. Below is a practical framework for working through your vendor list.

Category 1: Almost Always Require a BAA

  • EHR and practice management software vendors. PHI flows through these systems constantly. Every patient chart, scheduling record, and billing entry is covered.
  • Medical billing and revenue cycle companies. They receive claim data and patient demographic information to process on your behalf.
  • Medical transcription and digital dictation services. Provider notes contain detailed clinical information and are PHI by definition.
  • Secure fax and electronic fax providers. Referrals, lab results, and records sent by fax carry PHI.
  • Cloud storage and backup services that hold clinical or administrative data. If PHI resides in the backup, the backup vendor is a Business Associate.
  • Medical imaging platforms and PACS vendors. Images are PHI.
  • Patient portal and patient communication platforms. Appointment reminders, portal messages, and test results all carry PHI.
  • IT managed service providers and cybersecurity vendors with access to systems containing PHI. This includes remote monitoring, helpdesk support, email administration, endpoint management, and backup operations where PHI may be encountered.
  • Email and productivity platforms used to transmit or store PHI. Microsoft 365, for example, requires a BAA when used in a healthcare context. Microsoft offers one, but the practice must execute it.

Category 2: Evaluate Case by Case

  • Accounting and financial software vendors. If they access systems or data that include PHI, a BAA may apply. If they only see aggregate revenue figures with no patient identifiers, it may not.
  • Legal counsel. Attorneys acting as legal advisors to a covered entity are generally treated as having a professional relationship that satisfies HIPAA's conduit exception rather than a BAA. This is a nuanced area; consult your HIPAA compliance advisor.
  • Couriers and postal services. Standard mail and delivery services transmitting physical records are generally considered conduits, not Business Associates, if they do not open or access the contents. Specialized medical records transport may be different.

Category 3: Generally Do Not Require a BAA

  • Utilities and facilities vendors with no access to PHI.
  • Pure conduits (internet service providers, standard telephone carriers) where PHI merely passes through without storage or access.
  • Janitorial and maintenance companies that do not handle records or systems.

The gray area is where practices most often get into trouble. When uncertain, the correct default is to execute a BAA. The cost of an unnecessary agreement is minimal. The cost of a missing one, particularly when a breach occurs and a vendor is involved, can include civil money penalties, breach notification costs, and reputational damage.

What a BAA Must Actually Contain

HIPAA specifies required elements. A BAA that is missing any of these is not a valid BAA in the regulatory sense. Before signing, confirm the agreement includes the following.

Required Element What to Look For
Permitted uses and disclosures The agreement specifies exactly what the vendor may do with PHI and limits use to those purposes.
Prohibition on unauthorized use The vendor agrees not to use or disclose PHI in ways that your practice itself would be prohibited from doing.
Appropriate safeguards The vendor agrees to implement administrative, physical, and technical safeguards to protect PHI.
Breach reporting obligation The vendor must notify your practice of any breach or security incident without unreasonable delay. HIPAA sets a 60-day outer limit; many BAAs negotiate a shorter window.
Subcontractor requirements The vendor must require its own subcontractors who handle PHI to sign agreements with equivalent protections.
Access and amendment rights The vendor must support your practice's ability to provide individuals with access to their PHI and to make amendments when required.
Disclosure accounting The vendor must make information available for the practice to provide an accounting of disclosures when an individual requests one.
Compliance with Security Rule For vendors who handle electronic PHI (ePHI), the agreement must reference the Security Rule's requirements.
Termination provisions The agreement must address what happens to PHI when the relationship ends, including destruction or return of PHI.
Government access The vendor must agree to make internal practices and records available to the U.S. Department of Health and Human Services (HHS) for compliance review.

A vendor offering a one-paragraph "we comply with HIPAA" statement is not providing a BAA. If a vendor cannot or will not execute a proper BAA, that is material information for your practice's vendor selection decision.

Where IT Operations Fit In

IT operations sit at the center of most HIPAA technical safeguard requirements. The vendors and service providers your practice uses to manage endpoints, email, cloud storage, backup, remote access, and security monitoring are almost universally Business Associates who require BAAs.

Beyond the BAA, IT operations are where the Security Rule's technical safeguard requirements actually get implemented. These include access controls, audit logging, transmission security, and breach detection. A BAA is the contractual layer. The operational layer is what gets tested if a breach occurs or an auditor arrives.

The IT Operational Responsibilities That Support Your HIPAA Program

The following are examples of the technical safeguard work that a properly scoped managed IT engagement covers on behalf of a medical practice. Note that your practice retains responsibility for its overall HIPAA program. These are supporting operational functions, not a transfer of compliance accountability.

  • Access control and identity management. Every staff member accesses only the systems and data their role requires. Account access is provisioned promptly on hire and terminated promptly on departure. This is one of the most frequent failure points practices face when offboarding employees.
  • Audit logging and log retention. HIPAA requires covered entities to maintain documentation related to their security program for six years. Audit logs of who accessed what system, when, and from where are a core component of that documentation trail. The operational requirement is to generate those logs, protect them from tampering, and retain them for the required period.
  • Endpoint security and encryption. Full-disk encryption on every laptop and workstation means a lost or stolen device does not automatically become a reportable breach. This is a practical risk-reduction measure with direct HIPAA implications.
  • Email security and Microsoft 365 administration. Email is the primary attack route for phishing, business email compromise, and malware delivery. Properly configured advanced email protection, combined with an executed Microsoft BAA, supports both security operations and HIPAA requirements around ePHI transmission.
  • Backup and recovery operations. HIPAA requires a contingency plan that includes data backup and disaster recovery procedures. A properly scoped backup program creates independent, protected copies of both endpoint data and Microsoft 365 content, including email, SharePoint, and OneDrive. Microsoft does not fully back up its own cloud content.
  • Breach detection and incident response. Managed Detection and Response (MDR) pairs continuous monitoring technology with a live security operations team. Real analysts review alerts around the clock, separating false positives from genuine threats. A breach at 2 a.m. gets a response at 2 a.m., not the next business day.
  • Security awareness training. Staff are the most frequently targeted part of any organization. Recurring training and simulated phishing campaigns address the human layer of risk, which no technical control fully eliminates on its own.
  • Vulnerability and patch management. Most successful attacks exploit known vulnerabilities for which patches already exist. Keeping operating systems and applications current closes those gaps before attackers can walk through them.

Audit Log Retention: A Common Point of Confusion

Practices frequently conflate two different retention concepts. The HIPAA documentation retention requirement (six years for security program documentation, including policies and records of activity) is distinct from a baseline endpoint security information and event management (SIEM) retention window, which may be set shorter by a managed service provider as a default. These are not the same obligation, and your practice should confirm with your IT provider how audit log retention is configured and whether it aligns with your HIPAA program's requirements. This is a question worth raising explicitly, not assuming.

Maintaining Your BAA Inventory

A BAA executed at contract signing is not a one-time task. Practices need a living vendor inventory that tracks the following for each Business Associate relationship.

  • Vendor name and primary contact.
  • Service provided and whether PHI is involved.
  • BAA execution date and current version.
  • BAA renewal or review date (especially if tied to contract renewal).
  • Subcontractor disclosure: which downstream vendors does this Business Associate use who also touch your PHI?
  • Breach notification contact and expected notification timeline.

When a vendor updates its platform, changes its subcontractors, or the nature of its service changes, the BAA should be reviewed to confirm it still accurately reflects the relationship. A BAA written for a simple scheduling tool may not cover a later-added patient engagement module that processes clinical data.

Practices that go through significant growth, add new service lines, or adopt new clinical software often discover BAA gaps during an internal HIPAA risk analysis. The risk analysis is your practice's tool for finding those gaps before a regulator or a breach does.

What to Ask Every New Vendor Before Signing

These are the questions your practice administrator or HIPAA compliance lead should ask before any new software or service vendor goes live.

  1. Will your service involve any access to, storage of, or transmission of patient information?
  2. Do you have a standard BAA you use, or will you sign ours?
  3. Who are your subcontractors that may handle our PHI, and are they under equivalent agreements?
  4. What is your breach notification process, and what is your committed notification timeline?
  5. What security certifications or assessments has your organization completed recently? (SOC 2 Type II reports are a common reference point.)
  6. What happens to our PHI when we terminate the relationship?

A vendor that cannot answer these questions clearly is a risk to evaluate carefully, regardless of how compelling the software demonstration was.

How Onsite Technical Services Supports This Work in Phoenix

Onsite Technical Services works with medical practices in the Phoenix area to implement and operate the technical safeguards that a well-run HIPAA program depends on. This includes executing a BAA with each practice we serve, because our managed IT and cybersecurity operations involve access to systems where ePHI resides.

Our role is to implement, operate, monitor, and document the technical controls that support your practice's HIPAA program. That means properly configured access controls, audit logging aligned with your retention requirements, encrypted endpoints, protected backups, advanced email security, around-the-clock threat monitoring, and the security awareness training your staff needs to be the last line of defense rather than the easiest target.

Your practice retains ownership of its HIPAA compliance program. We provide the operational infrastructure and documentation that program depends on. Business Technology Reviews (BTRs), included in our Standard Managed Services engagement, give your leadership a regular, structured look at how your IT environment is performing against your operational and compliance requirements, without waiting for a problem to surface.

For medical practices in Phoenix and the greater Phoenix area, properly managed IT runs approximately $200 to $250 per user per month, depending on the complexity of your environment. That is planning guidance, not a quoted price, and it covers managed IT and cybersecurity operations on a per-user basis, not per device.

Learn more about how Onsite Technical Services supports healthcare practices: onsite-tech.com/healthcare.

Frequently Asked Questions

Does my IT company need to sign a HIPAA BAA?

Yes. Any managed IT or cybersecurity provider that has access to systems, networks, or backups where patient information is stored or transmitted is a Business Associate under HIPAA. A BAA must be executed before services begin, not after. If your current IT provider has not signed one, that is a gap your practice should address immediately.

Does Microsoft need to sign a BAA for our Microsoft 365 account?

Yes. If your practice uses Microsoft 365 for email, file storage, or any other purpose that involves electronic protected health information, Microsoft is a Business Associate. Microsoft does offer a BAA for covered entities, but your practice must specifically execute it. It is not automatic when you subscribe to Microsoft 365.

What happens if a vendor refuses to sign a BAA?

A vendor that processes PHI on your behalf but refuses to execute a BAA creates a compliance risk your practice should take seriously. In most cases, the practice should not use that vendor for services involving PHI, or should restructure the engagement so the vendor has no access to PHI. Document the evaluation either way.

How long do we need to keep signed BAAs?

HIPAA's documentation retention requirement is six years from the date of creation or the date the document was last in effect, whichever is later. A BAA that has expired because you changed vendors should be retained for six years from the end of the agreement, not discarded when the relationship ends.

Is a vendor's general privacy policy the same as a BAA?

No. A privacy policy describes how a vendor handles data broadly for its entire customer base. A BAA is a specific, executed contract between your practice and that vendor, creating obligations tailored to the HIPAA requirements that apply to your relationship. They serve entirely different purposes, and one cannot substitute for the other.

Does having a BAA in place mean the vendor is HIPAA compliant?

A BAA creates contractual obligations, but it does not verify that the vendor is actually meeting them. The BAA is the agreement layer. Operational verification, such as reviewing a vendor's SOC 2 Type II report or asking about their security practices, is the due diligence layer. Both matter.

Book a Consult