A Business Associate Agreement is a contract between your practice and any outside company or person that creates, receives, stores, or transmits patient data on your behalf. It legally obligates that vendor to protect the data the same way you're required to, and it spells out what happens if that vendor has a breach — including whether and how quickly they have to tell you.
HIPAA doesn't just recommend this. A signed BAA is required before any protected health information is shared with a vendor, full stop. Without one, sharing that data is itself a HIPAA violation — even if the vendor never mishandles anything.
The obvious ones are easy: your practice management software, your cloud backup provider, your IT support company. Practices usually have those covered.
The ones that get missed are the vendors that don't feel like "tech" — the answering service that takes after-hours calls and messages, the billing or collections agency, the document shredding company, the marketing platform that syncs patient appointment reminders, even a web developer who was given access to a patient portal for a support ticket. If patient data passes through them in any form, they need a BAA on file before that access happens, not after.
Missing BAAs are one of the most commonly cited findings in OCR settlements — not because the vendor caused a breach, but because the practice couldn't produce the agreement when asked. If that vendor later has an incident and your practice never had a signed BAA in place, you're treated as though you handed over patient data with no protections at all, regardless of what the vendor's own security actually looked like.
It's also one of the easiest things for an auditor to check. A risk analysis or written policy takes time to evaluate; a request for "your current list of Business Associate Agreements" either produces a folder of signed contracts or it doesn't.
The fix isn't complicated, but it does take someone actually doing it: build a full inventory of every vendor that touches patient data in any way, confirm a signed BAA exists for each one, and put a process in place so a BAA gets signed before a new vendor is ever given access — not months later when someone remembers.
Building and maintaining that vendor inventory and BAA library is part of what we document in a compliance audit and keep current through Managed Compliance, so practices in Nashville, Hendersonville, Gallatin, Lebanon, and Mount Juliet have a real answer — with the paperwork to back it up — the moment anyone asks.
Get a free 30-minute readiness check — no pressure, just clarity on what you need.
Get My Free Readiness Check