HIPAA BAA Checklist: 10 Required Elements (2026)
Complete BAA checklist for healthcare practices — what must be in a business associate agreement, when one is required, and how to track them.

Business associate agreements are one of the most commonly violated HIPAA requirements — and one of the easiest to fix. OCR has imposed substantial settlements in matters where missing or deficient BAAs were among the violations identified. The gap is often systemic: a practice that has failed to execute a required BAA has usually also failed other Security Rule obligations at the same time.
Most independent practices underestimate the number of vendors that require a BAA. A typical dental office or medical practice has between eight and fifteen business associates. Some have more than twenty. If even one is missing a signed agreement, the practice is noncompliant — regardless of whether that vendor has ever mishandled a single record.
This guide covers what a BAA is, when one is required, what it must contain, and how to manage the full lifecycle from execution to termination.
What Is a Business Associate Agreement?
A BAA is a legally binding contract required under HIPAA (§164.502(e), §164.504(e)) between a covered entity — your practice — and any vendor that creates, receives, maintains, or transmits protected health information on your behalf. The HITECH Act extended this requirement in 2009, and the 2013 Omnibus Rule made business associates directly liable under HIPAA.
The agreement defines three things:
What the vendor can and cannot do with PHI. A BAA specifies the permitted uses and disclosures of protected health information. If a use is not explicitly authorized in the agreement, the vendor is not permitted to perform it.
How the vendor must protect PHI. The agreement requires the business associate to implement appropriate administrative, physical, and technical safeguards — the same standard that applies to covered entities under the Security Rule.
What happens when something goes wrong. The BAA establishes breach notification obligations, requiring the business associate to report any unauthorized access or disclosure to the covered entity within a defined timeframe. Under HIPAA, this must be no later than 60 days from discovery, though many BAAs specify shorter windows.
A BAA is not a formality. It is a regulatory requirement. Without one, sharing PHI with a vendor is itself a HIPAA violation — even if the vendor handles that data perfectly.
When Is a BAA Required?
Any vendor that handles PHI on behalf of your practice requires a BAA. The list is longer than most practices realize.
Common business associates:
- Cloud-based EHR/EMR vendors
- Practice management software providers
- Medical billing companies and clearinghouses
- IT managed service providers
- Cloud storage providers (if used for PHI)
- Email hosting providers (if used for PHI communications)
- Secure messaging platforms
- Cloud fax services
- Patient scheduling tools
- Answering services and call centers
- Transcription services
- Shredding and document destruction companies
- Payment processors that handle treatment-related details
- Consultants with access to PHI (compliance, coding, billing)
Frequently missed business associates:
- IT managed service providers. If your IT company can access your network, your EHR, or your backups, they are a business associate. This is one of the most common gaps — practices assume IT support is a utility, not a HIPAA-regulated relationship.
- Website hosting providers. If your website includes a patient portal, online intake forms, or any mechanism that collects or transmits PHI, the hosting provider needs a BAA.
- Accounting firms. If your accountant receives billing records that contain patient names, diagnosis codes, or treatment information, they are a business associate.
- Attorneys. If legal counsel receives PHI in the course of representing your practice, a BAA is required.
Who does not need a BAA:
- Vendors whose services do not involve the use or disclosure of PHI on your behalf. HHS is explicit that BA status is determined by the service or function performed, not by physical proximity to information — janitorial, electrical, and general facility-maintenance work is generally not a business-associate relationship even where incidental exposure to PHI is possible.
- True conduits — entities providing transmission-only, transient handling of PHI (e.g., the postal service, standard internet service providers, courier services).
- Vendors with no PHI access (office supply companies, general building maintenance).
- Patients themselves, and disclosures for treatment between covered providers.
The conduit exception is narrow. Per HHS cloud-computing guidance, the distinction is about transmission versus persistent storage: a service that stores PHI persistently is a business associate even when it cannot decrypt the data. A cloud fax service that processes and stores fax content is a business associate. The telecommunications carrier that transmits the signal is a conduit.
BAA required or not? Answers for common scenarios
The rule is straightforward — any vendor that creates, receives, maintains, or transmits PHI on your behalf needs a BAA — but the practical questions come up as specific scenarios. Here are answers for the ones we see most often.
Telemedicine platforms — yes. Zoom, Doxy.me, SimplePractice, and any video platform used to deliver care are business associates. They handle PHI the moment a session begins. Free consumer Zoom does not qualify — a Zoom for Healthcare plan with signed BAA is required. Same for standard SimplePractice vs the healthcare-tier plans.
Cloud storage providers — yes, if storing PHI. AWS, Google Cloud, Microsoft Azure, Dropbox Business, and Box all sign BAAs on their commercial tiers. Free tiers do not qualify. If your practice stores any patient files, records, or session recordings in cloud storage, a BAA is required.
SMS providers for appointment reminders — yes, in most cases. If the SMS content includes patient identifiers plus health information (name plus appointment type, "your dental cleaning is tomorrow"), the SMS provider is a business associate. Twilio and other API vendors sign BAAs on HIPAA-eligible product tiers.
Email marketing tools — yes, if segmenting by health data. Mailchimp does not sign BAAs on any tier. HubSpot signs on Enterprise. Constant Contact does not sign. If your email list is segmented by condition, treatment, or specialty, you are handling PHI in the platform.
Website analytics and pixels — usually not, but a compliance minefield. Google Analytics does not sign a BAA and is not appropriate on pages with patient identifiers. Facebook Pixel is worse — using it on healthcare pages has driven multiple OCR enforcement actions and class actions. The safer default: no third-party analytics on any page where PHI could be transmitted or inferred.
Meeting scheduling (Calendly, Acuity) — yes, if intake includes health information. Calendly does not sign BAAs and its terms prohibit PHI. If intake questions ask about reason for visit or health context, you need a HIPAA-eligible scheduling tool with a signed BAA.
IT support and managed service providers — yes, if they can access your systems. Any IT provider that can log into your EHR, backup systems, or workstations is a business associate. Their credentials on your systems mean potential access to PHI, regardless of whether they actually view records.
Subcontractors of your business associates — yes, downstream. If your EHR vendor uses AWS to store your data, that cloud provider is a subcontractor and the BAA chain must extend to them. Your BAA with the EHR must require the EHR to execute a downstream BAA with AWS. Missing a link in the chain is your problem, not just theirs.
When you don't need a BAA: true conduits (transmission-only, transient handling — postal service, standard ISPs, courier services), vendors whose services do not involve the use or disclosure of PHI (office supply companies, janitorial, general facility maintenance), disclosures for treatment between covered providers, and the patients themselves.
What Must a BAA Include?
HHS specifies required provisions for business associate agreements under §164.504(e). A compliant BAA must include all of the following:
1. Permitted uses and disclosures. The specific purposes for which the business associate may use or disclose PHI. This should match the actual services the vendor provides — not a generic catch-all.
2. Prohibition on unauthorized use. An explicit statement that the business associate will not use or disclose PHI other than as permitted by the agreement or required by law.
3. Safeguards requirement. The business associate must use appropriate safeguards to prevent unauthorized use or disclosure of PHI, including implementing the requirements of the Security Rule with respect to ePHI.
4. Reporting obligations. The business associate must report any use or disclosure not provided for by the agreement, any security incident, and any breach of unsecured PHI. Breach notification must occur without unreasonable delay and no later than 60 days from discovery.
5. Subcontractor requirements. If the business associate uses subcontractors that will access PHI, it must ensure those subcontractors agree to the same restrictions and conditions — including executing their own BAAs.
6. Access to PHI. The business associate must make PHI available to the covered entity (or directly to individuals) to satisfy patient access rights under §164.524.
7. Amendment of PHI. The business associate must make PHI available for amendment and incorporate amendments when directed by the covered entity.
8. Accounting of disclosures. The business associate must make information available to support the covered entity's obligation to provide an accounting of disclosures under §164.528.
9. Compliance verification. The business associate must make its internal practices, books, and records available to HHS for determining compliance.
10. Termination provisions. The agreement must authorize termination by the covered entity if the business associate violates a material term, and must require the return or destruction of all PHI upon termination.
HHS publishes sample BAA language in its business associate agreement provisions guidance. It is not a fill-in-the-blank template — it is a reference for the minimum required provisions.
BAA vs MSA vs NDA vs DPA — which agreement covers what
Legal and procurement teams often conflate these agreements. Each serves a different purpose, and using the wrong one leaves the practice exposed.
| Agreement | Purpose | Covers PHI? | Required by HIPAA? |
|---|---|---|---|
| BAA (Business Associate Agreement) | HIPAA-specific — governs handling of protected health information | Yes | Yes, before PHI is shared |
| MSA (Master Service Agreement) | Commercial terms of the vendor relationship (pricing, SLA, IP, indemnification) | Only if PHI provisions are added | No, but common |
| NDA (Non-Disclosure Agreement) | Confidentiality of any information — trade secrets, business plans, patient info | Weakly — not HIPAA-specific | No |
| DPA (Data Processing Agreement) | GDPR and consumer-privacy compliance (California CCPA, similar state laws) | Overlaps but not HIPAA-specific | No |
An NDA is not a BAA. NDAs create general confidentiality obligations but do not require HIPAA-specific safeguards, breach notification timelines, subcontractor requirements, or termination-related PHI return. Substituting an NDA for a BAA is a HIPAA violation.
A DPA is not a BAA. GDPR data processing agreements handle consumer privacy under EU law. HIPAA has different requirements for healthcare PHI. Some vendors (Google, Microsoft, AWS) provide combined agreements — verify HIPAA-specific clauses are present, not just a DPA.
An MSA can incorporate a BAA. Some vendors bundle the BAA as an addendum to their MSA. That is acceptable as long as the elements HHS requires (permitted uses, safeguards, breach notification, subcontractor obligations, return or destruction of PHI) are all present.
You typically need MSA plus BAA together. The MSA governs the business relationship. The BAA governs PHI handling. Both are usually required with the same vendor for a complete compliance picture.
The BAA Checklist
Use this checklist to audit and manage your practice's business associate agreements:
1. Inventory every vendor that receives or accesses PHI on your behalf. Walk through every system, service, and relationship in your practice. Include software vendors, service providers, consultants, and any third party that creates, receives, maintains, or transmits PHI in a business-associate capacity. Most practices discover two to five vendors they had not previously considered. (Not every recipient of PHI is a business associate — the relationship and purpose decide.)
2. Determine which vendors are business associates vs. conduits. For each vendor, ask: does this entity create, receive, maintain, or transmit PHI on our behalf? If yes, they are a business associate. If they merely transport data without accessing its content, they are a conduit. When in doubt, treat them as a business associate.
3. Execute a BAA with each business associate before sharing PHI. The BAA must be signed before the vendor receives any protected health information. Retroactive agreements do not cure the period of noncompliance.
4. Verify the BAA covers the specific services you use. A vendor may have a standard BAA that covers their primary product but not ancillary services — analytics, support, integrations. Confirm that every service involving PHI is explicitly covered.
5. Confirm the BAA includes breach notification timelines. The agreement should specify how quickly the business associate must notify you of a breach. HIPAA allows up to 60 days, but shorter windows (24-48 hours) give your practice more time to respond within your own notification obligations.
6. Confirm subcontractor provisions. If the vendor uses subcontractors who will access PHI, the BAA must require the vendor to execute BAAs with those subcontractors. Ask the vendor directly: who else touches our data?
7. Set up tracking for BAA expiration and renewal dates. Some BAAs have fixed terms. Others auto-renew. Know which is which and calendar the dates. An expired BAA is a missing BAA.
8. Review BAAs annually or when vendor relationships change. If you add new services from an existing vendor, change the scope of work, or the vendor undergoes an acquisition, the BAA should be reviewed and updated.
9. Document the BAA inventory as part of your compliance program. Maintain a centralized log of all business associates, BAA status, execution dates, expiration dates, and the services covered. This documentation is what you produce during an OCR investigation.
10. Have a process for terminating BAAs and ensuring PHI return or destruction. When you end a vendor relationship, the BAA requires the business associate to return or destroy all PHI. Document the request, the vendor's confirmation, and the method of destruction or return.
Which SaaS vendors sign a BAA?
Independent practices increasingly build operations on SaaS tools. Not all sign a BAA — and the ones that do usually restrict coverage to specific plans or products. This table covers the vendor questions we get most often.
| Vendor | BAA Available? | Plan Required |
|---|---|---|
| Amazon Web Services (AWS) | Yes | Any account — BAA covers HIPAA-eligible services only |
| Microsoft Azure | Yes | Any commercial subscription |
| Google Cloud Platform | Yes | Any account — BAA required before ePHI use |
| Microsoft 365 (Outlook, Teams, OneDrive) | Yes | Business and Enterprise tiers |
| Google Workspace (Gmail, Drive incl. Forms, Meet) | Yes | No edition floor — Google's BAA names no subscription edition; a super admin accepts it in the Admin console. Legacy free edition and non-admin users excluded |
| Dropbox | Yes | Business or Enterprise |
| Box | Yes | Business and above |
| Zoom | Yes | Paid Pro (BAA at checkout), Business, Business Plus, Enterprise, or Zoom for Healthcare |
| Slack | Conditional | Eligible enterprise plan, plus the "Slack - HIPAA Enabled" SKU, plus the specific organization or workspace designated HIPAA-enabled — coverage does not extend to every workspace you own |
| Twilio | Yes | HIPAA-eligible products with signed BAA |
| SendGrid (Twilio Email API) | No | Expressly excluded — Twilio states it will not sign a BAA for SendGrid. It is not on the HIPAA Eligible Services list at any plan |
| Stripe | No | No BAA offering identified. Stripe's Services Agreement bars providing PHI as Third Party Data; HIPAA section 1179 separately disapplies the statute to payment-processing activity, which is not the same as a BAA |
| DocuSign | Conditional | Sales-managed HIPAA-enabled offering only — not included on self-serve Personal, Standard, or Business Pro |
| Adobe Sign / Acrobat Sign | Yes | Enterprise |
| HubSpot | Yes | Enterprise tier only — HIPAA Sensitive Data support covers specified features within Smart CRM, Marketing/Sales/Service/Content/Data Hub, not every feature |
| Salesforce | Yes | By named service, not edition — the BAA must include the specific HIPAA Covered Service (Sales Cloud, Health Cloud, Service Cloud, Marketing Cloud Engagement and others). Tableau Bridge, Data Connect and Server excluded |
| Notion | Yes | Enterprise plan to be eligible, BAA signed, HIPAA compliance switched on in workspace settings. Beta Services are excluded; Notion AI is not |
| Calendly | No | Not available at any tier |
| Mailchimp | No | Not available at any tier |
| Loom | No | Not available at any tier |
| ChatGPT (consumer) | No | HIPAA coverage limited to ChatGPT for Healthcare, ChatGPT Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, API with Modified Retention, or API FedRAMP with Modified Retention |
| Render, Fly.io, Supabase | Varies | Some sign on request — verify directly with vendor |
Read the platform-specific breakdowns for full configuration guidance: Microsoft Teams, Google Workspace, Zoom, Slack, Dropbox, DocuSign, ChatGPT, Calendly, Mailchimp, Loom.
Common BAA Mistakes
Using a vendor before executing the BAA. This is the most frequent violation. Practices sign up for a new EHR, billing service, or cloud tool and start using it immediately. The BAA gets added to a to-do list and never completed. Every day of use without a signed BAA is a day of noncompliance.
Assuming "HIPAA compliant" means you have a BAA. A vendor's marketing page may claim HIPAA compliance. That does not mean a BAA exists between you and that vendor. Compliance is the vendor's state. A BAA is a contract between two specific parties. You still need to execute one.
Using generic BAA templates without reviewing the terms. Not all BAAs are created equal. A vendor-provided BAA may limit their liability, extend breach notification timelines to the maximum 60 days, or exclude certain services from coverage. Read the terms. Negotiate where necessary.
Not tracking expiration dates. BAAs with fixed terms expire silently. If your agreement lapsed six months ago and a breach occurs today, OCR will find that you operated without a BAA for six months.
Not updating BAAs when services change. You signed a BAA covering your vendor's billing software. Then you added their patient portal. The portal involves different PHI flows and may not be covered by the original agreement. Any new service involving PHI requires a BAA review.
Not addressing subcontractors. Your business associate uses a cloud hosting provider to store your data. That cloud provider is a subcontractor — and the chain of BAA obligations must extend to them. If it does not, there is a gap in your compliance program.
Real Enforcement: What Happens Without BAAs
OCR has made missing BAAs a priority enforcement target. These are public enforcement actions from the HHS breach portal and resolution agreements:
Raleigh Orthopaedic Clinic, P.A. — $750,000 settlement (2016). OCR investigated after a breach report and found that Raleigh Orthopaedic had transferred x-ray films of approximately 17,300 patients to a third-party vendor for digitization and silver recovery from the films — without executing a business associate agreement with that vendor. The absence of the BAA was the specific violation cited in the resolution.
North Memorial Health Care — $1,550,000 settlement (2016). Following the theft of an unencrypted laptop from a contractor, OCR identified two Security Rule failures: North Memorial had not executed a BAA with the contractor before providing access to the ePHI of 289,904 patients, and North Memorial had not conducted an organization-wide risk analysis. The BAA gap was one of multiple violations, not the sole basis for the penalty.
Care New England Health System — $400,000 settlement (2016). In a September 2016 resolution, OCR found that Care New England failed to update its BAA with an affiliated hospital after the Omnibus Rule changed the required provisions — the practice was operating under an outdated BAA that no longer reflected the current regulatory requirements.
The pattern is consistent: OCR does not treat a missing BAA as a minor oversight. It treats it as evidence of a compliance program that is not functioning. The financial penalties reflect that assessment.
Business-associate oversight in enforcement
Additional matters where OCR cited BAA failures.
Each summary reflects what OCR itself stated in the resolution agreement or press release. BAA execution and vendor oversight recur across matters that also involve risk analysis, access controls, and device-media failures.
Advocate Health Care Network
2016 · $5,550,000OCR found that Advocate failed to conduct an accurate and thorough risk analysis of all ePHI, failed to implement policies and procedures governing physical access and workstation use, and failed to obtain satisfactory assurances in the form of a written business associate agreement from a business associate that stored ePHI on its behalf.
Corrective action: Multi-year corrective action plan across risk analysis, BAA execution, and device/media controls.
Athens Orthopedic Clinic
2020 · $1,500,000Following an unauthorized network intrusion, OCR found that Athens Orthopedic Clinic had systemic non-compliance with the Security Rule including failure to conduct a risk analysis, failure to implement audit controls, failure to implement access controls, and failure to enter into BAAs with vendors.
Cottage Health
2018 · $3,000,000Following two breaches exposing patient records to the internet, OCR found that Cottage Health failed to conduct an accurate and thorough risk analysis, failed to perform periodic technical and non-technical evaluations in response to environmental or operational changes, and failed to obtain a written business associate agreement from a vendor.
Each summary reflects what OCR itself stated in the resolution agreement or press release. Related-provisions column reflects the CFR sections Patient Protect associates with the matter based on the resolution agreement, CAP, and/or press release, not necessarily language quoted verbatim from the underlying document.
How Patient Protect Handles BAAs
BAA lifecycle management is built into the Patient Protect platform as Vendor & BAA Governance. Instead of tracking agreements in spreadsheets or filing cabinets, every step is centralized and automated:
Creation. The agreement is generated from your current organizational data rather than filled into a cached PDF, so what goes out reflects the practice as it is today. Have counsel review the template against §164.504(e) before you rely on it — that review is yours to make and no vendor, us included, should tell you a generated document is legally sufficient.
Execution. Electronic signature, so an agreement can be sent, signed and countersigned without printing and scanning.
Tracking. Every business associate sits in one of six states: None, Staging, Pending, Active, Expired or Revoked. The value is that Expired is a state you can see rather than a date nobody checked.
Expiration alerts. The platform raises an alert before an agreement lapses, surfaced in-app on your Scoreboard and held in the Event Log.
It gates messaging. This is the part worth knowing: without an active agreement, ePHI to that vendor is blocked rather than flagged. The agreement state does something, instead of only being recorded.
One inventory to produce. When someone asks which vendors you have agreements with and what state they are in, that is a screen rather than an afternoon.
Included in Basic, from $39/month, with no long-term contract. Start your free trial.
Frequently Asked Questions
Do I need a BAA with every vendor?
No — only with vendors that create, receive, maintain, or transmit PHI on your behalf. Your office supply vendor does not need a BAA. Your EHR vendor, billing company, and IT provider do. The determining factor is whether the vendor handles protected health information as part of the services they provide to your practice.
What if a vendor refuses to sign a BAA?
You cannot share PHI with that vendor. This is not a negotiation — it is a regulatory requirement. If a vendor refuses to sign a BAA, you must either find a vendor that will or restructure the relationship so the vendor never accesses PHI. Continuing to use a vendor that refuses a BAA is a HIPAA violation.
Is a verbal agreement sufficient?
No. HIPAA requires BAAs to be documented in writing. A handshake, a verbal promise, or an email exchange does not satisfy the requirement. The agreement must be a written or electronic document with signatures from both parties.
How often should BAAs be renewed?
HIPAA does not specify a renewal frequency. However, BAAs should be reviewed annually as part of your compliance program and updated whenever vendor relationships change — new services, scope changes, acquisitions, or subcontractor modifications. If your BAA has a fixed term, ensure renewal happens before expiration.
Does a BAA protect me from liability?
A BAA defines responsibilities — it does not eliminate your liability as a covered entity. If your business associate causes a breach, the BAA establishes their obligations for notification and remediation. But OCR can still investigate and penalize the covered entity for inadequate oversight, failure to act on known violations, or systemic compliance failures. A BAA is a required safeguard, not a liability shield.
What is the difference between a business associate and a subcontractor?
A business associate performs services directly for a covered entity that involve PHI. A subcontractor performs services for the business associate — not for the practice directly — that involve PHI. Under the Omnibus Rule, subcontractors are held to the same standards as business associates and must have their own BAAs in place. The chain of accountability extends through every entity that handles PHI, regardless of how many layers deep the relationship goes.
BAAs are not paperwork for the sake of paperwork. They are the contractual mechanism that extends HIPAA's protections to every vendor in your PHI ecosystem. Missing one is not an oversight OCR overlooks — it is a standalone violation with standalone penalties.
If you are not sure how many of your vendors have signed BAAs, that uncertainty is the problem Patient Protect solves. Start your free trial and see your full BAA status in your first session.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

