← Back to Compliance Insights

July 14, 2026  ·  Jonah Gobah

The Vendor You Forgot About Is Your Biggest HIPAA Risk

Ask a small practice owner if they're HIPAA compliant, and most will point to their EHR system, maybe their front-desk privacy screen, possibly a HIPAA training video the staff watched once. Ask about their Business Associate Agreements, and you'll often get a pause.

That pause is the risk.

What a BAA actually is

Under 45 CFR § 164.314(a), any vendor who creates, receives, maintains, or transmits protected health information on your behalf — a Business Associate — needs a signed agreement with you before they touch that data. Not a terms-of-service checkbox. A specific, signed contract that spells out how they'll protect PHI, what happens if there's a breach, and what they're allowed to do with the data.

This applies far more broadly than most practices assume. It's not just your EHR vendor. It's:

  • Your billing and claims processing service
  • Your appointment scheduling and reminder software
  • Your cloud backup or file storage provider
  • Your IT support contractor, if they can access systems with patient data
  • Your answering service, if they take messages involving patient information
  • Your practice management consultant, if they review your records

Why this gets missed

Most of these relationships start informally. You sign up for a scheduling tool with a credit card, not a legal review. Your cousin's IT company has "always just handled it." Your billing service came recommended by another practice, so nobody thought to check their paperwork. None of that is negligent in spirit — it's just how small businesses actually operate. But HHS doesn't grade on intent. If a vendor touching PHI doesn't have a signed BAA, that's a gap regardless of how the relationship started.

What happens without one

Two things, typically. First, if that vendor has a breach — their systems get compromised, an employee mishandles data — and there's no BAA in place, liability doesn't stay contained to them. You share it, and you likely can't demonstrate you took reasonable steps to prevent it. Second, in a routine audit, "list your Business Associates and provide signed agreements" is a standard request. An incomplete list, or a vendor with no agreement on file, is an immediate finding — even if nothing has ever gone wrong with that vendor.

The fix is mechanical, not expensive

This isn't a legal-fees problem. Most vendors serving healthcare practices already have a standard BAA template ready to send — because they deal with this constantly. The actual work is:

  1. Listing every vendor with any possible access to PHI
  2. Confirming which ones qualify as Business Associates
  3. Requesting, signing, and filing an agreement with each
  4. Tracking expiration and renewal dates, since many BAAs have terms

That last step is where things quietly lapse — a BAA gets signed once, filed away, and nobody notices two years later when it's expired or the vendor relationship has changed scope.

If you haven't done a full vendor inventory recently, that's the place to start. Not because you're likely doing something wrong on purpose — because this is the kind of gap that exists by default until someone deliberately checks for it.

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles