A Security Risk Assessment gets most of the attention in HIPAA compliance conversations, but a quieter gap causes just as much exposure for small clinics: the Business Associate Agreement, or BAA. Any 1–10 provider practice that hands protected health information (PHI) to an outside vendor — whether that vendor is a billing company, a cloud-based scheduling tool, or the shredding service that hauls away old charts — is legally required to have a signed BAA with that vendor before the relationship starts. Many small practices never formalize this, not out of carelessness but because the requirement is easy to overlook when a vendor is small, familiar, or "just handling the software side."
This piece walks through what a BAA actually is, when the law requires one, what a compliant agreement needs to contain, and the vendor categories small practices most often forget to cover.
What a Business Associate Agreement Actually Is
A BAA is a legally required contract between a HIPAA-covered entity — your practice — and a business associate: any third-party vendor that creates, receives, maintains, or transmits PHI on your behalf. The agreement obligates that vendor to safeguard PHI and comply with HIPAA in the same way your practice must. It is not a formality or a nice-to-have addendum to a service contract; without it, allowing a vendor to touch PHI is itself a HIPAA violation, independent of whether any data is ever actually mishandled.
When the Law Actually Requires One
A BAA is required any time a vendor creates, receives, maintains, or transmits PHI on a practice’s behalf — and that threshold is lower than most practice owners assume. It covers vendors that merely have access to PHI, even if no one at that vendor ever actively views it. A cloud storage provider hosting encrypted backups of patient records needs a BAA even though a human employee there may never open a single file. A practice cannot permit a third-party vendor to access PHI without a BAA already in place — the agreement has to exist before access begins, not after.
The requirement also extends downstream. If a business associate uses its own subcontractors who will touch PHI — a billing company that outsources data entry, for instance, or a cloud host that uses a separate data center operator — an additional BAA must exist between the business associate and that subcontractor. The practice remains responsible for confirming that chain holds, even though it isn’t a direct party to that second agreement.
What Belongs in a Compliant BAA
A HIPAA-compliant BAA is not a one-page signature form. To hold up under scrutiny, it needs to address each of the following:
- Permitted and required uses and disclosures. The agreement must clearly define exactly how the vendor is allowed to use and disclose PHI, and prohibit any use beyond those defined purposes or what the law requires.
- Appropriate safeguards. The vendor must implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule — meaning the Security Rule’s requirements apply directly to the vendor for any electronic PHI it handles, not just to the practice.
- Breach and incident reporting. The vendor must be obligated to report any unauthorized use or disclosure of PHI, including breaches of unsecured PHI, back to the practice, with clearly defined reporting timelines rather than a vague "as soon as reasonably possible" clause.
- Patient rights support. The vendor must assist the practice in meeting its own obligations to patients — honoring authorization requirements, responding to access requests, and providing an accounting of disclosures when asked.
- HHS audit access. The agreement should explicitly state that the Department of Health and Human Services has the right to audit the vendor’s practices, policies, and records related to PHI.
- Termination and data return or destruction. The agreement must specify what happens to PHI once the relationship ends — generally, all PHI is returned to the practice or destroyed, and if neither is feasible, the same protections must continue to apply indefinitely.
- Subcontractor obligations. Any subcontractor the vendor uses that touches PHI must agree, in writing, to the same restrictions and conditions the vendor itself accepted.
- Right to terminate. The practice should retain the right to end the agreement if the vendor materially breaches it and fails to cure the breach within a reasonable window.
A template downloaded from a generic legal site can miss one or more of these elements, particularly the subcontractor and audit-access provisions. Having a professional familiar with healthcare contracts review a BAA before it’s signed is a reasonable investment relative to what an incomplete agreement can cost later.
Vendor Types Small Practices Commonly Miss
Most practices remember to get a BAA from their EHR vendor. Far fewer think to cover the full list of vendors that also qualify as business associates:
- Electronic health record and practice management software vendors
- Medical billing and claims processing companies
- Cloud storage and hosting providers, including encrypted backup services
- IT support and managed services providers, especially any with remote access to systems containing PHI
- Patient communication platforms — email, SMS, and patient portals used to send or receive PHI
- Transcription services
- Data analytics vendors processing PHI for practice operations
- Legal, actuarial, and accounting firms with access to PHI
- Document shredding and destruction companies handling physical records
- Telehealth platforms operating on the practice’s behalf
The IT support category deserves particular attention for small clinics. A managed services provider that remotely accesses a practice’s systems to install updates or troubleshoot a server is a business associate the moment that access touches anything containing PHI — even if the technician never intentionally opens a patient file. The same logic applies to general-purpose AI tools: publicly available consumer AI assistants do not execute HIPAA BAAs, and entering PHI into one of them is a violation regardless of how the tool is being used.
Keeping BAAs Current
A BAA signed once at onboarding and never revisited is a common gap. Vendor relationships change — a billing company gets acquired, a software vendor adds a new subcontractor, a practice adopts a new patient-communication feature within an existing platform. Reviewing BAAs annually, alongside any point where a vendor relationship materially changes, keeps the paper trail aligned with what’s actually happening operationally. For a 1–10 provider practice juggling clinical work and administrative overhead, this kind of periodic review is easy to defer indefinitely unless it’s built into a recurring compliance calendar.
Conclusion
Business Associate Agreements are one of the more procedural pieces of HIPAA compliance, which is exactly why small practices tend to under-invest in them relative to clinical and Security Rule concerns. But the underlying rule is simple: any vendor that creates, receives, maintains, or transmits PHI on a practice’s behalf needs a signed, complete BAA before that access begins, and practices remain responsible for confirming the same standard holds through any subcontractors involved. For a small clinic evaluating a new billing partner, IT provider, or patient-communication tool, asking directly whether a compliant BAA is in place — and reading it, not just signing it — is one of the more effective, low-cost forms of protection a practice can build into its vendor selection process.