Which Practice Vendors Require a HIPAA BAA (and Which Do Not)

A single missing business associate agreement cost a small Illinois pediatric practice $31,000 in an April 2017 HHS Office for Civil Rights settlement. The practice had been sending paper records to a storage vendor since 2003 and did not execute a BAA until 2015, a 12-year gap that OCR treated as an ongoing impermissible disclosure. No breach was alleged. The paperwork itself was the violation.

HIPAA compliance requirements vary based on your covered entity type and business associate relationships. Consult your HIPAA compliance officer or a healthcare attorney before implementing privacy practices.

Credentialing and enrollment requirements vary by payer and change frequently. Verify current requirements directly with each payer.

The Short Answer

A vendor needs a BAA when it creates, receives, maintains, or transmits protected health information on the practice's behalf, regardless of whether it ever opens the file. The test is function and access, not industry, not intent, and not whether the vendor calls itself HIPAA compliant on its pricing page. Every service category in the practice services directory that touches claims, charts, or patient contact falls inside that test.

What Actually Triggers a BAA Requirement

The governing text is 45 CFR 164.502(e) and 164.308(b), which require a covered entity to obtain satisfactory assurances, in writing, before disclosing PHI to a business associate. The 2013 HIPAA Omnibus Rule expanded the definition to include subcontractors and made business associates directly liable to OCR, which is why a signed agreement from the vendor no longer ends the practice's exposure at the vendor's front door.

The function test, not the industry test

The question is not whether a company sells to healthcare. It is whether performing the contracted work requires access to PHI. A marketing agency that only writes copy for a practice website needs no BAA. The same agency, given login access to the patient recall list so it can send appointment reminders, does. A shredding company that destroys charts on site needs a BAA. An answering service that takes patient names and callback reasons needs one. A landscaping company does not, even though its crew walks past the front desk daily.

The conduit exception is narrower than most practices assume

OCR's conduit exception covers entities that transport PHI without accessing it other than randomly or infrequently, and without storing it. The canonical examples in OCR guidance are the U.S. Postal Service, private couriers, and internet service providers acting purely as pipes. Cloud storage providers do not qualify, because storage is persistent access, and OCR said so explicitly in its 2016 cloud computing guidance. Practices that classified Dropbox, Google Drive, or a generic file transfer tool as a conduit have the classification backwards.

The practical consequence: a vendor that holds encrypted PHI it cannot decrypt is still a business associate. Encryption reduces breach risk. It does not remove the BAA obligation.

Vendor typeTypical PHI accessBAA requiredWho owns the contract
Billing or RCM companyFull claims, demographics, diagnosis codesYesBilling vendor
EHR and practice management vendorComplete chartYesEHR vendor
Credentialing serviceProvider data only, no patient PHI in most engagementsUsually no; yes if it touches claims dataCredentialing service
Answering service or call centerNames, callback reasons, symptomsYesFront-office vendor
Cloud storage or backupPersistent storage, often encryptedYes, no conduit exceptionIT or MSP
Shredding and record destructionPhysical chartsYesFacilities or compliance
Janitorial, landscaping, HVACIncidental proximity onlyNoFacilities
Postal service and common couriersTransport only, no storageNo, conduit exception appliesFront office
Malpractice carrier and health planPHI exchanged, but as a covered entity or for its own purposesNo, not acting on the practice's behalfLegal and insurance

Classifications reflect typical scopes of work, not quotes. Confirm the actual data flow in each contract before relying on a row.

The Vendors Practices Get Wrong in Both Directions

Two failure patterns show up repeatedly in small practice vendor inventories, and they point in opposite directions.

The first is under-papering. Website hosts, appointment reminder tools, patient survey platforms, transcription services, IT managed service providers with remote desktop access, and increasingly AI scribe and documentation vendors all sit squarely inside the definition and are routinely missed. Remote IT access is the most common gap: an MSP with administrative credentials to the EHR server has broader PHI access than the billing company, and often no signed agreement.

The second is over-papering, which is less dangerous but not free. Practices ask health plans, referring physicians, and malpractice carriers to sign BAAs. None of them should. A health plan receiving a claim is a covered entity acting on its own behalf. A referring physician receiving records for treatment is covered by the treatment exception at 45 CFR 164.506. A malpractice carrier receiving records for defense is receiving them for its own purposes. Sending BAAs to these organizations signals to a surveyor that the practice does not understand the rule, and it slows down the agreements that do matter.

Workforce members are the third category that generates confusion. A W-2 employee, a contracted physician working under the practice's direct control, and a temp staffer supervised day to day by the office manager are workforce, not business associates. They are covered by training and sanctions policies, not by a BAA. A contracted coder working remotely for a coding firm is not workforce, and the firm needs an agreement.

Building the Vendor Inventory: What Practices Actually Do

  1. Pull the accounts payable ledger for the last 24 months: every recurring vendor payment is a candidate. This surfaces more relationships than asking staff, and it catches the $40 per month tools that never went through a procurement review.
  2. Ask one question per vendor: does performing this work require access to patient names, dates, diagnoses, or claims data? A yes, or an unclear answer, means the vendor goes on the BAA list until proven otherwise.
  3. Check for downstream subcontractors: the 2013 Omnibus Rule requires business associates to obtain BAAs from their own subcontractors. Ask each vendor in writing which subcontractors touch practice data, particularly offshore coding and transcription.
  4. Confirm the agreement covers the minimum required terms: permitted uses, safeguards, subcontractor flow-down, breach notification timing, and return or destruction of PHI at termination, per 45 CFR 164.504(e).
  5. Set a breach notification clock shorter than the statutory maximum: HIPAA gives the practice 60 days from discovery to notify affected individuals. A BAA that lets the vendor take 60 days to notify the practice leaves zero working time. Negotiate 10 business days or less.
  6. Re-review at contract renewal, not annually: tie the review to renewal dates so it never becomes an orphaned calendar task. Practices reviewing their broader HIPAA compliance checklist should fold the vendor inventory into that same cycle.

What Goes Wrong

  • Signing the vendor's template without reading the breach clause: most vendor-drafted BAAs set notification at 60 days, which consumes the practice's entire statutory window and leaves it notifying patients late.
  • Treating a compliance badge as an agreement: a vendor stating that it is HIPAA compliant on its website creates no contractual obligation. Only an executed BAA does.
  • Missing the free tools: a personal cloud account used to move a chart, a consumer messaging app used for on-call coordination, and a personal email forwarding rule are all disclosures without agreements. These rarely appear in accounts payable.
  • Losing the executed copies: OCR requests documentation, not assertions. A BAA the practice cannot produce within the response window functions as a BAA that does not exist. Retain executed agreements for six years past termination, per 45 CFR 164.530(j).
  • Assuming termination ends the obligation: if a vendor retains PHI after the engagement ends, the BAA's protections must survive termination. Confirm the return-or-destroy provision and get written confirmation that it happened.

What Should Your Practice Do

Run the accounts payable list, apply the function test to every recurring vendor, and separate the list into three buckets: BAA required, BAA not required with a one-line written rationale, and unclear pending vendor confirmation. The unclear bucket is where the risk sits, and it is usually smaller than practices fear, typically five to fifteen vendors at a solo or small group practice.

The documented rationale matters as much as the signed agreements. OCR's 2017 settlement with the Illinois pediatric practice involved no breach, no complaint about patient harm, and no allegation that records were misused. The finding was that PHI moved to a vendor for years with nothing in writing. A practice that can show its reasoning for every vendor on the list, including the ones it decided did not need an agreement, is in a materially different position than one that can only produce a folder of signed forms. Practices weighing which functions to outsource at all should start with the in-house versus outsourced billing tradeoff, because every outsourced function adds a vendor to this inventory.

Get the full practice management guide at GetPracticeHelp -- with billing benchmarks, credentialing checklists, and revenue cycle best practices.

Frequently Asked Questions

Does a practice need a BAA with its malpractice carrier?
No. A malpractice carrier receiving records to defend a claim is using the information for its own purposes, not performing a function on the practice's behalf, so the business associate definition at 45 CFR 160.103 does not apply. Disclosure is permitted under the health care operations provisions.
Is a BAA required for a cloud storage vendor that only holds encrypted files?
Yes. OCR's 2016 cloud computing guidance states that a cloud service provider storing encrypted PHI is a business associate even when it lacks the decryption key, because persistent storage exceeds the conduit exception. Encryption is a safeguard, not an exemption.
What happens if a practice discovers a vendor has been operating without a BAA?
Execute the agreement immediately and document the date the gap was identified and closed. A missing BAA is an impermissible disclosure, not automatically a reportable breach, and whether notification is required depends on the four-factor risk assessment at 45 CFR 164.402. Retroactive dating of the agreement is not a remedy and creates a separate problem.
How long should a practice keep an expired BAA?
Six years from the later of the date it was created or last in effect, per the HIPAA documentation retention requirement at 45 CFR 164.530(j). This is longer than most state medical record retention periods, so BAAs should not be purged on the chart retention schedule.
Do BAAs need to be renewed every year?
No. Most BAAs are evergreen and remain in force until terminated. What changes is the scope of work, so the review trigger should be a change in the vendor's data access or a contract renewal, not a calendar anniversary.