Business Associate Agreements: Your Vendors Handle Patient Data Too
Your clinic is responsible for patient data even when a vendor is the one holding it. The BAA is the contract that proves you did your homework — here is who needs one and what it must say.

What a BAA is, in one paragraph
A Business Associate Agreement is a written contract required by HIPAA between your clinic and any vendor that creates, receives, maintains, or transmits patient information on your behalf. It spells out what the vendor may do with that information, what safeguards they must have, and what happens — including breach notification — if something goes wrong.
Here is the part clinic owners miss: the BAA does not transfer your liability away. If your billing company loses patient data and you never signed a BAA with them, regulators come to you. The agreement is your proof that you did your part.
Which vendors need one
If a vendor can touch patient information in any form, they almost certainly need a BAA. The usual suspects in a small Coastal Bend clinic:
- Your EHR / practice management software vendor. The most obvious one.
- Billing and collections companies. They live in your claims data.
- Your IT provider. Yes — anyone with remote access to your systems or who handles your backups is a business associate. If your IT company will not sign a BAA, that is a red flag the size of the building.
- Cloud backup and email hosting. Patient data in email threads and backup images counts.
- Shredding and document destruction services. They handle PHI on the way out the door.
- Answering services and transcription services. They hear and store patient details.
- The landlord’s copier lease company? Only if the copier stores images of scanned documents and the vendor services it with access to the drive. Ask — this is the one people forget.
What the agreement must contain
A handshake and a checkbox are not a BAA. The agreement must include specific required provisions: the vendor may only use PHI as the contract permits, must apply appropriate safeguards, must report breaches and security incidents to you, must ensure any subcontractors agree to the same terms, and must return or destroy PHI when the contract ends.
Read that subcontractor line again. Your EHR vendor’s cloud hosting subcontractor needs to be bound by the same protections. Ask your vendors who their subcontractors are — the chain of BAAs should have no missing links.
What happens without one
You own the fallout. No BAA means no documented safeguards, no breach notification duty on the vendor’s side, and no paper trail showing you vetted them. In an investigation, that reads as negligence.
Vendor breaches become your breaches. When — not if — a vendor has an incident, the notification obligations land on you, with none of the cooperation terms a BAA would have guaranteed.
What to do Monday morning
Make the vendor list. Every company that could touch patient information goes on it — software, billing, IT, shredding, answering service, cloud backup. Next to each name, write “signed BAA” or “missing.” Then start with the missing ones that touch the most data: EHR, billing, IT provider. Most reputable vendors will send you their standard BAA within days of being asked.
While you are at it, ask each vendor who their subcontractors are and confirm the chain is documented. You will rarely need this information. The one time you do, you will need it urgently — and “we never asked” is not an answer you want to give.
A signed BAA is not a lifetime pass. Vendors get acquired, switch subcontractors, and quietly change their terms of service. Once a year, pull your vendor list and confirm three things for each name: the BAA is still signed and on file, the vendor contact for security incidents is still correct, and nothing about the service changed — new cloud hosting, new owners, new data practices. Pay special attention after any vendor acquisition; the acquiring company’s paper does not automatically replace yours. When you add a new vendor, the BAA gets signed before they touch patient data, not after — make it a line item in your vendor onboarding, next to the login credentials.
If a vendor cannot produce a BAA at all — not “we’re working on it,” but nothing to send — start shopping for their replacement the same week. A vendor without a BAA is a vendor that has decided compliance is your problem.
File every BAA where you can find it in under a minute — a shared folder beats a filing cabinet nobody opens.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Does our IT company really need to sign a BAA?
Yes. Any IT provider with access to systems containing patient information — remote support, backups, email hosting — is a business associate under HIPAA. A provider that resists signing is telling you something important about how they operate.
What if a vendor says their standard terms ‘cover HIPAA’?
Standard terms of service are not a BAA unless they contain all the provisions HIPAA requires. Ask for the actual Business Associate Agreement document, and confirm it addresses safeguards, breach notification, subcontractors, and return-or-destruction of PHI.
Do subcontractors of our vendors need BAAs too?
Your vendor’s BAA must require them to get the same protections from their own subcontractors. You do not sign directly with the subcontractor, but you should confirm the chain exists — ask your vendor who handles data on their behalf.
We have used the same billing company for years without a BAA. Is it too late?
No — get one signed now. The requirement applies to every business associate relationship regardless of how long it has existed. Document the date you executed it; going forward is what matters.
What happens to patient data when we end a vendor contract?
The BAA must require the vendor to return or destroy all PHI when the relationship ends, if feasible. Make this an explicit line item in your offboarding checklist, and get written confirmation.