BAA & Vendor Management

Business Associate Agreement FAQ

BAA Vendor Vetting: Who Needs One & What to Review

15 questions covering Business Associate definitions, specific vendor BAA requirements for Microsoft 365, Google Workspace, IT companies, shredding services, and more. Plus vendor vetting, review processes, and what to do when a vendor refuses to sign.

BAA Terms and Regulatory References

Business Associate: Under 45 CFR Section 160.103, a Business Associate is a person or entity that performs functions or activities for a covered entity. The work must involve access to Protected Health Information (PHI). This includes claims processing, data analysis, utilization review, billing, and legal, actuarial, accounting, consulting, or financial services.

Business Associate Agreement (BAA): A written contract required under 45 CFR Section 164.502(e) between a covered entity and a business associate. The agreement must set out the permitted and required uses and disclosures of PHI by the business associate. It must also give assurances that the business associate will safeguard the information.

Electronic Protected Health Information (ePHI): As defined in 45 CFR Section 160.103, ePHI is individually identifiable health information. It is transmitted by or maintained in electronic media. This includes patient records, billing data, and insurance information stored or sent electronically.

Vendor vs. Business Associate: A vendor is only a Business Associate if it creates, receives, maintains, or transmits PHI on behalf of a covered entity. A vendor that never accesses, handles, or stores PHI does not meet the definition of a Business Associate and does not require a BAA. More definitions are in the HIPAA compliance glossary.

What a BAA must contain (45 CFR 164.504(e)(2)): The contract must establish the permitted and required uses and disclosures of PHI by the business associate, and must require the business associate to:

  • not use or further disclose PHI other than as the contract permits or as required by law;
  • use appropriate safeguards, and comply with the Security Rule for electronic PHI;
  • report to the covered entity any use or disclosure not provided for by the contract, including breaches of unsecured PHI;
  • ensure that any subcontractors that handle PHI agree to the same restrictions and conditions;
  • make PHI available for patient access, amendment, and an accounting of disclosures (45 CFR 164.524, 164.526, 164.528);
  • make its internal practices, books, and records available to HHS;
  • at termination, return or destroy all PHI if feasible, or extend the contract's protections to it;
  • and the contract must authorize the covered entity to terminate it if the business associate violates a material term.

Full text: eCFR 164.504(e)(2).

Business Associate Agreement FAQ

BAA Basics

A Business Associate, as defined under 45 CFR Section 160.103, is a person or organization that works on behalf of a covered entity. The work must involve the use or disclosure of Protected Health Information (PHI). If the work involves creating, receiving, maintaining, or transmitting PHI, that entity is likely a Business Associate. If that describes your company, our business associate compliance guide covers your own HIPAA obligations.

A BAA is a written contract required under 45 CFR Section 164.502(e). Under this regulation, covered entities must obtain satisfactory assurances from their business associates that PHI will be appropriately safeguarded. The agreement establishes the permitted uses and disclosures of PHI and the responsibilities of each party. Learn more about our BAA management services.

Many people think every vendor needs a BAA. That is not true. Being a vendor and being a Business Associate are not the same thing.

Specific Vendor BAA Requirements

It depends on how you use it. If Microsoft stores, sends, or handles your patient data (ePHI), then yes, you likely need a BAA with them. Microsoft does offer a BAA for qualifying Microsoft 365 plans. Any business using Microsoft 365 to process ePHI should sign one before using the service that way.

If you use Google Workspace to store, send, or handle patient data, you should get a BAA from Google. Google provides a BAA for Google Workspace accounts, and an administrator must accept it in the Admin Console before using Workspace services with ePHI.

In most cases, yes. An IT company with access to systems that hold ePHI meets the Business Associate definition under 45 CFR Section 160.103. That holds true even if it does not store patient data directly. Managed service providers, help desk vendors, and IT support companies often require a BAA.

Yes. A shredding company that handles records with PHI meets the Business Associate definition. It maintains or has access to PHI while destroying them. A BAA is required before the shredding company begins handling your records.

Usually, no. A janitorial service does not often create, receive, maintain, or transmit PHI, so it generally does not meet the Business Associate definition. But if janitorial staff have unsupervised access to areas where PHI is stored or visible, practices should put physical safeguards in place. A confidentiality agreement may also help.

BAA Management

Fix a missing BAA as soon as you find it.

BAAs should be reviewed at minimum annually. Most practices review their BAAs once a year. They also review when the vendor relationship changes in a material way, such as a shift in the scope of services, the types of PHI handled, or the vendor's security posture. Annual review also aligns with the Security Risk Assessment cycle required under 45 CFR Section 164.308(a)(1)(ii)(A).

Vendor Vetting & Due Diligence

One of the biggest mistakes is failing to evaluate vendor risk.

At a minimum, check if a BAA is needed and review vendor risk. Use a short survey, a security review, or both.

Know exactly how patient data will be shared, stored, sent, accessed, or released.

Yes. A vendor can decline to sign any agreement.

Weigh the risks of keeping the vendor. Decide if you can still use them safely or if you need to find a new option.

One Guy Consulting helps practices inventory their vendors, determine which require BAAs, and manage the entire BAA execution process. Our vendor management service includes risk evaluation and ongoing monitoring.

Need Help Managing Your Business Associate Agreements?

Book a free 30-minute intro call. We will review your vendors, tell you which ones need BAAs, and show you how we handle the whole process.

Book Your Free 30 Minute HIPAA Compliance Review

More HIPAA FAQ Resources