Elevaire Systems
← Back to Insights
SecurityHIPAAcompliancevendor managementsecurityhealthcare compliance

Business Associate Agreements: The HIPAA Vendor Obligation Growing Practices Overlook

Elevaire Systems·

A healthcare practice with 80 employees rarely has a clean list of every vendor that touches patient data. The EHR vendor has a signed agreement. The billing company probably does. The cloud backup service, the answering service, the shredding company, and the IT provider are less certain. Each one that handles protected health information (PHI) on the practice's behalf needs a signed business associate agreement, and the practice is the party that answers if it does not exist.

Why This Obligation Gets Missed

HIPAA's definition of a business associate is broad. It covers any person or company that creates, receives, maintains, or transmits PHI on behalf of a covered entity, or that provides certain services to it, such as legal, accounting, consulting, data aggregation, or management work, where that work involves access to PHI. The test is not whether the vendor is a "healthcare company." It is whether PHI reaches them.

At 15 employees, a practice can hold the full vendor list in one person's head. At 75 or 100 employees, the list has grown by accident. Departments buy tools on their own. A second location brings its own vendors. An acquired practice arrives with contracts nobody has read. The person who signed the original BAAs may have left, and the renewal of the underlying service agreement quietly replaced the document that held the BAA.

The result is a gap between what the practice believes is covered and what is actually signed. That gap is invisible until a breach, an audit, or a patient complaint brings it to the surface.

What a BAA Must Actually Contain

The Privacy and Security Rules specify what a business associate contract has to say. Under 45 CFR 164.504(e), the contract must:

  1. Establish the permitted and required uses and disclosures of PHI by the business associate.
  2. Prohibit any use or disclosure beyond what the contract allows or the law requires.
  3. Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
  4. Require the business associate to report any unauthorized use or disclosure, including breaches of unsecured PHI.
  5. Require the business associate to make PHI available so the practice can meet patient requests for access, amendment, and an accounting of disclosures.
  6. Require compliance with Privacy Rule requirements where the business associate carries out the practice's obligations.
  7. Make the business associate's internal practices, books, and records available to HHS.
  8. Require return or destruction of PHI when the relationship ends.

HHS publishes sample business associate agreement provisions that cover these elements. Use of the sample language is not required, and HHS notes that it can be changed to fit the arrangement. A practice that relies on a vendor's own template should still check each of the eight items against it, because vendor templates tend to favor the vendor.

Business associates must also pass the same obligations down. If your billing company uses a subcontractor that touches PHI, the billing company needs its own BAA with that subcontractor.

What the Enforcement Record Shows

HHS's Office for Civil Rights (OCR) has treated a missing BAA as a violation in its own right, separate from any breach. The settlements below are older, but they show how the issue gets raised.

PracticeAmountWhat happened
Raleigh Orthopaedic Clinic$750,000Gave a vendor access to X-ray films with PHI without a BAA
North Memorial Health Care$1.55 millionShared PHI with a vendor without a BAA, among other findings
Center for Children's Digestive Health$31,000Disclosed records of at least 10,728 patients to a records storage vendor without a BAA

The first two settlements were announced in 2016 and the third in 2017, per reporting on the OCR actions and law firm summaries. The smallest settlement is the most instructive for a growing practice. It involved no hack and no ransomware, only a paper records vendor and an unsigned agreement. The practice also agreed to a two-year corrective action plan, which meant ongoing reporting to HHS and a signed BAA on file for every vendor.

HHS adjusts HIPAA civil penalty amounts for inflation each year, and the current figures are listed in 45 CFR 102.3. The settlement amounts above are a better guide to what a missing BAA tends to cost, because penalties depend on how long the gap lasted, how many patients were involved, and whether the practice knew about it.

Vendors Practices Forget

The obvious vendors get covered first. The ones below are where gaps usually sit.

Cloud and infrastructure providers. HHS's guidance on HIPAA and cloud computing states that a cloud service provider that stores PHI is a business associate even if the data is encrypted and the provider has no key. A backup service or file-sharing platform holding PHI needs a BAA.

IT and software vendors with access. Anyone with administrative access to systems that contain PHI, including remote support tools, qualifies when they can reach patient data in the course of their work.

Shared communication tools. Email platforms, secure messaging, e-fax services, telehealth platforms, and answering services handle PHI routinely.

Professional service providers. Outside counsel, accountants, consultants, and coding or billing contractors often see PHI during their work.

Physical vendors. Shredding companies, off-site records storage, and some transcription services handle PHI in paper or audio form.

Vendors acquired through a merger. An acquired practice's contracts do not automatically meet your standard. Treat them as unreviewed until proven otherwise.

Two related points matter here. Some vendors do not need a BAA, such as a janitorial service with no access to records or a workforce member covered by the practice's own policies. A BAA is also not a substitute for diligence. A signed agreement says the vendor will protect PHI. It does not show that the vendor can.

A Practical BAA Management Process

A growing practice can bring this under control in a few weeks and keep it under control with a quarterly check. The sequence below works for a practice of 50 to 200 employees.

  1. Build the vendor inventory. Pull the accounts payable vendor list, the software subscription list, and the list of vendors with system access. Combine them. Add anyone staff mention informally.
  2. Sort by PHI exposure. For each vendor, record whether it creates, receives, maintains, or transmits PHI, and in what form. Mark each as BAA required, not required, or unknown.
  3. Locate every signed BAA. Store them in one place, indexed by vendor, with effective date and the renewal date of the underlying service contract. If a BAA cannot be found, treat it as missing.
  4. Close the gaps. Send the practice's own BAA or the vendor's template for any vendor lacking one, and check it against the eight required elements. Pause new PHI sharing with any vendor that refuses to sign until the issue is resolved.
  5. Check subcontractors. For vendors that handle large volumes of PHI, ask whether they use subcontractors with access and whether those subcontractors have BAAs in place.
  6. Add a BAA gate to procurement. No new vendor goes live with PHI access until the BAA is signed. This single control prevents most future gaps.
  7. Review quarterly. Reconcile the vendor list against the BAA register, and review any vendor that was added, renewed, or offboarded.
  8. Handle offboarding. When a vendor relationship ends, confirm that the PHI was returned or destroyed as the BAA requires, and record it.

The inventory step is usually the slowest because it requires someone with authority to ask each department what it has bought. That is a leadership task more than a technical one, which is why it so often does not get done.

The Breach Notification Angle

A BAA is also the document that decides how fast the practice learns about a problem. Under the Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. The covered entity's own notification clock to patients and HHS generally runs from when the breach is discovered, which can include when a business associate's discovery is imputed to it.

A practice that wants faster notice than the regulatory outer limit can negotiate shorter reporting windows into the BAA. Practices commonly negotiate windows measured in days rather than weeks. That is a contract term, not a regulatory requirement, and it only exists if someone reads the BAA before signing.

HHS has also proposed changes to the Security Rule that would require covered entities to obtain written verification from business associates, at least once every 12 months, that technical safeguards are in place. As of this writing it is a proposal, not a final rule. Practices that already keep a current BAA register and a vendor review cadence will have far less to rebuild if it is finalized.

Who Should Own Vendor Agreements

At 25 employees, the office manager can own BAAs. At 100 employees, the volume of vendors, renewals, and acquired contracts exceeds what a side-of-desk owner can track. The practice's privacy officer is responsible for compliance, but the privacy officer is rarely positioned to see every technology purchase.

This is where fractional IT leadership fits. Elevaire Systems works alongside a practice's existing managed service provider, which keeps systems running and supports staff day to day. Fractional IT leadership owns the layer above that: the vendor inventory, the PHI exposure map, the procurement gate, and the quarterly review that connects technology purchases to compliance obligations. The managed service provider is typically itself a business associate that needs a BAA, and a fractional leader can confirm that its agreement covers the access it actually has.

Frequently Asked Questions

Do I need a BAA with my IT provider?

If your IT provider can access, store, or transmit PHI while providing its services, yes. That includes remote support with access to workstations or servers that contain patient data. HHS treats the question as whether PHI is reachable, not whether the provider intends to look at it.

What does it cost to fix missing BAAs?

The agreements themselves cost little if the practice uses a standard template, often just staff time and some legal review. The larger cost is the inventory work, which a practice with 100 employees can usually complete in a few weeks of part-time effort. The cost of leaving the gap open is the enforcement exposure described above.

Can a vendor refuse to sign a BAA?

Yes, and some consumer-grade tools will not sign one. If a vendor refuses and PHI is involved, the practice should not use that vendor for PHI. Many enterprise plans of common software include a BAA, while free or entry-level plans of the same product often do not, so check which plan you are on.

How does this work alongside our existing MSP or IT team?

Your MSP or internal IT team keeps managing systems, support, and monitoring. Fractional IT leadership adds ownership of the vendor register, procurement controls, and compliance reporting that those teams are usually not scoped to cover. It also reviews your MSP's own BAA and access.

How often should we review our BAAs?

Review the register at least quarterly and whenever a vendor is added, replaced, or renewed. Review the full set of agreements whenever the practice opens a location, acquires another practice, or changes its EHR, billing, or cloud platforms.

How do we get started?

Start with the vendor list. Combine accounts payable, software subscriptions, and system access records, then mark which vendors touch PHI and whether a signed BAA is on file. That single page shows the size of the gap and the order in which to close it.

About Elevaire Systems

Elevaire Systems provides fractional Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO) leadership, along with infrastructure modernization, intelligent automation, and compliance strategy for growing organizations.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation