Compliance

Business Associate Agreements: The BAA Program, Done Right

Every vendor touching PHI needs a BAA — and most organizations have gaps. What a BAA must contain, the subcontractor trap, and how to inventory them.

Who needs a BAA

Any vendor that creates, receives, maintains, or transmits PHI on your behalf: EHR hosting, billing companies, cloud providers, shredding services, email hosting, answering services, data analytics firms. If PHI touches their systems, you need a signed BAA before — not after — they touch it. No BAA, no PHI sharing.

What a BAA must contain

Turn reading into quotes. Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes, no obligation.

Request quotes

The subcontractor trap

Your BAA is with your vendor. But if their subcontractor touches your PHI, that subcontractor is also a business associate — and needs its own BAA with your vendor. Chains of three or four are normal in cloud-hosted healthcare. Ask your vendors who their subprocessors are; most can't answer cleanly on the first try.

The inventory most orgs skip

Maintain a living BAA register: vendor, PHI involved, BAA signed date, renewal/termination terms, subprocessor list. Review it annually and whenever you onboard a vendor. Assessors ask for this inventory early — "we think legal has them somewhere" is not an answer.

BAA red flags

BAAs are one of eight checks in our readiness quiz — and a standard line in every assessor quote scope.

Keep reading

There's No Such Thing as HIPAA Certification

HHS OCR does not certify anyone. What 'HIPAA certified' vendors are actually selling — and what real compliance looks like instead.

How to Choose a HIPAA Assessment Firm: 9 Questions to Ask

No government body accredits HIPAA assessors — so vetting is on you. The nine questions that separate real healthcare assessors from generalists.

HIPAA Risk Assessment Cost in 2026: What Organizations Actually Pay

The assessment fee is the smallest line item. A full first-year cost breakdown: analysis, readiness, program build, and staff time — with planning ranges.

Questions

Do we need BAAs with vendors that only store encrypted PHI?

Yes. Storage is maintenance of PHI — the encryption doesn't remove the BAA requirement. (It does affect breach-notification analysis, which is a separate question.)

What if a vendor won't sign a BAA?

Don't share PHI with them. If the service inherently involves PHI, find a vendor that will sign — this is non-negotiable.

Turn reading into quotes

Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes.

Get a free quote