← Back to Compliance Insights

August 11, 2026  ·  Jonah Gobah

What Is a Business Associate Agreement? A Practical Guide for Healthcare Practices

If you run a medical practice, chances are you work with a long list of outside companies.

Your EHR provider. Your billing company. Your IT provider. Your cloud backup company. Your answering service. Your document management provider. Maybe even a consultant who needs access to patient information.

Most of these relationships are routine. You sign a contract, pay the invoice, and move on.

But when a vendor handles Protected Health Information (PHI) on your practice's behalf, there is another question you need to ask: do we need a Business Associate Agreement?

For many healthcare practices, the answer is yes. And this is one of those areas of HIPAA compliance that is easy to overlook until someone asks you to produce the agreement.

What exactly is a Business Associate Agreement?

A Business Associate Agreement (BAA) is a written contract or other written arrangement between a HIPAA covered entity and a business associate that establishes how the business associate may use and disclose PHI and requires appropriate safeguards for that information.

The U.S. Department of Health and Human Services (HHS) explains that covered entities generally must have a written business associate contract or arrangement when they engage a business associate.

In plain English: if another company is handling PHI for your practice, you need to understand whether that company is a business associate and, if so, make sure the appropriate BAA is in place.

The BAA isn't just another document to put in a filing cabinet. It establishes responsibilities between your practice and the vendor.

Who is a business associate?

A business associate is generally a person or organization that performs certain functions or services for a covered entity that involve the use or disclosure of PHI. Some common examples can include:

  • Medical billing companies
  • Certain IT service providers
  • Cloud service providers that store or maintain ePHI
  • Medical transcription companies
  • Healthcare clearinghouses
  • Certain consultants
  • Practice management vendors
  • Certain data storage or document management providers

The exact determination depends on what the vendor does and whether it has access to PHI. For example, simply purchasing software doesn't automatically create a business associate relationship. HHS specifically notes that merely selling software to a covered entity does not make the vendor a business associate if the vendor doesn't have access to the covered entity's PHI.

That's why practices shouldn't simply assume that every vendor needs a BAA. The relationship and the vendor's access to PHI matter.

What should a BAA cover?

A BAA should establish the permitted and required uses and disclosures of PHI and require the business associate to appropriately safeguard that information. HHS identifies several important provisions that a compliant business associate contract generally needs to address, including safeguards, reporting certain unauthorized uses or disclosures and breaches, assistance with certain individual rights, access to information for HHS compliance purposes, return or destruction of PHI when the relationship ends when feasible, and requirements concerning subcontractors.

In practical terms, your BAA should answer questions such as:

What can the vendor do with PHI? The agreement should establish the permitted uses and disclosures.

How must the vendor protect PHI? The business associate must appropriately safeguard the information.

What happens if something goes wrong? The agreement needs to address reporting of unauthorized uses or disclosures and breaches.

What happens when the relationship ends? The agreement should address the return or destruction of PHI when feasible.

What about subcontractors? Business associates generally need to ensure that applicable subcontractors agree to the same restrictions and conditions regarding PHI.

These aren't details you want to figure out after a security incident.

A BAA is not the same as a vendor contract

This is another common source of confusion. Your service agreement might say: "Vendor will provide IT support services for the practice." That's your business relationship.

A BAA addresses the vendor's handling and protection of PHI under HIPAA. Depending on the relationship, the BAA may be a separate agreement or incorporated into another contract. The important point is that the HIPAA requirements need to be addressed appropriately. HHS states that the required assurances must be in writing.

What happens if a practice doesn't have the required BAA?

This is where things can become uncomfortable.

Imagine that your practice has been using an outside billing company for three years. The billing company handles PHI. Then your practice discovers there is no BAA on file.

Now you have a compliance issue that could have been prevented simply by properly identifying the relationship and documenting it. And during an investigation or audit, being unable to produce an agreement can create additional questions: Who has access to our PHI? What are they permitted to do with it? What safeguards are they required to maintain? When was the relationship reviewed? What happens if the relationship ends?

Good compliance isn't just about having the right answer. It's about being able to show your work.

Your BAA checklist

For each vendor that may qualify as a business associate, your practice should consider documenting:

Vendor information — Vendor name, services provided, primary contact, date relationship began.

PHI access — Does the vendor access PHI? What type of PHI? How is PHI transmitted? Where is PHI stored?

Agreement — Is a BAA required? Has the BAA been signed? When was it signed? Who signed it? Where is the agreement stored?

Ongoing management — When was the vendor last reviewed? Has the vendor's services changed? Has its access to PHI changed? Does the agreement need to be updated? When should the relationship be reviewed again?

This is where many practices move from having a BAA to actually managing their business associate program.

Don't forget about your business associate's subcontractors

There's another layer that practices sometimes overlook. A business associate may use subcontractors that have access to PHI. HIPAA's business associate provisions address these relationships as well — HHS explains that a business associate agreement generally must require applicable subcontractors to agree to the same restrictions and conditions concerning PHI.

For a small practice, this can become difficult to track manually. You may know your billing company. But do you know which other organizations it uses to provide its services?

That doesn't mean the practice has to personally manage every aspect of the subcontractor's operations. But it does mean your vendor compliance program should account for the contractual requirements that apply to the business associate relationship.

The problem with managing BAAs manually

This is where things often break down for smaller practices. A practice might have:

  • Vendor contracts → Email
  • BAAs → Shared folder
  • Vendor list → Excel spreadsheet
  • Renewal dates → Calendar
  • Risk assessments → Word document
  • Security reviews → Someone's inbox

Everything exists. Nothing is connected.

Then six months later, someone asks: "Which vendors have access to PHI, and do we have current BAAs for all of them?" Now someone has to spend half a day searching. That's not a good compliance process.

How Truvidence makes Business Associate management easier

This is one of the reasons we built Truvidence.

Instead of treating BAAs as isolated documents, Truvidence connects them to your broader compliance program. Within the platform, a practice can maintain a centralized record of its business associates and track important information such as:

  • Vendor name
  • Risk level
  • Services provided
  • PHI access
  • BAA status
  • Agreement dates
  • Review status
  • Supporting evidence
  • Renewal information

The goal is simple: know who has access to your PHI, know whether the appropriate agreement is in place, and know what needs attention.

See your BAA program at a glance

Rather than opening a spreadsheet, you can see your BAA program through a centralized dashboard. For example:

  • BAA Health Score — 76%
  • Signed Agreements — 18
  • Missing Agreements — 2
  • Expiring Soon — 3
  • High-Risk Vendors — 4

That turns BAA management from a filing exercise into something you can actively monitor.

Truvidence can also connect BAAs to vendor risk

A vendor shouldn't be viewed in isolation. Suppose your practice uses an outside diagnostic company. You may want to know: What risk level is the vendor? Does it handle PHI? Is the BAA signed? When was the vendor last reviewed? Where is the supporting documentation? When is the next review?

Truvidence brings those pieces together so your team can see the broader compliance picture.

Keep the evidence with the record

One of the most useful parts of a BAA management process is being able to connect the agreement to supporting evidence. For example:

Example Diagnostics 🛡 Risk Rating: High · ✅ BAA: Signed · 📄 Agreement: Uploaded 📅 Last Review: July 2026 · 📅 Next Review: July 2027 · 📁 Supporting Evidence: Available

Instead of simply saying "we have a BAA," you can demonstrate it. That's an important difference.

Compliance is more than signing the agreement

A signed BAA is important, but it shouldn't be the end of the process. Your vendor relationships change. Services change. Technology changes. Access levels change. Vendors change. Your compliance program should be able to change with them.

That's why a good BAA management process should include ongoing review and documentation, not just collecting signatures.

One more important point

A BAA does not magically make a vendor compliant. HHS notes that business associates have direct obligations under HIPAA, including certain obligations under the Security Rule, and that a BAA provides the contractual assurances required between the parties.

So don't think of a BAA as "we signed the document, so we're done." Think of it as: we've formally established the relationship, responsibilities, and safeguards — and now we need to manage that relationship appropriately.

That's a much healthier way to approach HIPAA compliance.

Make BAA management one less thing to worry about

For a small medical practice, HIPAA compliance can sometimes feel like an endless collection of documents, deadlines, policies, and spreadsheets. It doesn't have to be that way.

A well-managed Business Associate program gives your practice a clearer picture of who handles PHI, what agreements are in place, and where attention is needed.

Truvidence brings that process into one HIPAA Compliance Operating System — along with risk assessments, compliance documentation, evidence management, employee training, incident response, and ongoing compliance monitoring.

Instead of asking "where did we put that BAA?" you can ask "which vendors need my attention today?" That's the difference between simply storing compliance documents and actually managing your compliance program.

This article is for general educational purposes and does not constitute legal advice. Whether a particular vendor relationship requires a Business Associate Agreement depends on the facts and applicable HIPAA requirements. Practices should consult qualified legal or compliance professionals when appropriate.

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles