The BAA Is a Liability Contract, Not Paperwork
Most practices treat the business associate agreement as a box to check: the vendor sends it, someone signs it, it goes in a folder. But a BAA is the one document that governs what happens when a vendor — your billing company, your cloud host, your IT provider — suffers a breach involving your patients' PHI. When that day comes, the terms you skimmed decide who notifies whom, who pays, and how exposed you are. These ten questions turn signing a BAA from a reflex into a decision.
1. Does This Vendor Actually Need a BAA?
Start here, because the answer runs both directions. A vendor that creates, receives, maintains, or transmits PHI on your behalf requires a BAA — no exceptions. But a vendor that never touches PHI does not, and demanding one from a landscaper wastes everyone's time. The trap is the middle: cloud storage, email, and backup providers that "just hold the data" are business associates even if they never look at it. When in doubt, if PHI can pass through or rest with them, you need the agreement.
2. Who Is Responsible for Breach Notification — and On What Timeline?
When a business associate has a breach, they must notify you. But HIPAA sets an outer limit of 60 days, and 60 days can consume your entire notification window before you even learn of the incident. Ask: how quickly must this vendor notify us — and push for far shorter than the legal maximum. A tight notification clause (say, within a few days of discovery) is one of the most valuable terms you can negotiate, because your own clock to notify patients starts whether or not the vendor told you promptly.
3. Are Subcontractors Covered?
Your vendor almost certainly uses other vendors — a cloud host under your billing company, for example. HIPAA requires your business associate to bind their subcontractors with equivalent agreements. Ask: does this BAA obligate the vendor to flow these protections down to every subcontractor that touches our PHI? Without that chain, your data can end up somewhere with no agreement governing it at all.
4. What Happens to Our Data When the Relationship Ends?
Contracts end. The BAA should say what happens to your PHI when yours does — return or destruction of all copies, or, if that is infeasible, continued protection with no further use. Ask: at termination, will they return or destroy our PHI, and will they certify they did? A vendor that keeps a copy of your patient data indefinitely after you leave is a breach waiting to happen on someone else's watch, with your name on the records.
5. Will They Give Us Their Security Documentation?
A BAA is a promise; security documentation is evidence. Ask: can you provide a recent third-party security assessment (SOC 2, HITRUST, or equivalent)? A vendor genuinely handling PHI should have something to show. Vague reassurance without any documentation is a signal to slow down — you are trusting them with data you are legally responsible for.
6. How Do They Encrypt Our Data — At Rest and In Transit?
Encryption is the single control that most often turns a lost device or intercepted transfer into a non-event. Ask: is our PHI encrypted both when stored and when moving between systems, and to what standard? "In transit only" leaves your data readable the entire time it sits on their servers — which is most of the time.
7. Who Can Access Our Data on Their Side?
A vendor's employees are a path to your patients' records. Ask: how do you limit and monitor which of your staff can access our PHI? You are looking for least-privilege access and audit logging on their end. The Memorial Healthcare and other insider cases were not sophisticated hacks — they were employees with more access than they needed and no one watching.
8. Does the BAA Address Liability and Indemnification?
The standard BAA satisfies HIPAA but says little about who pays when things go wrong. That is negotiated in the underlying service contract. Ask: if a breach originates on your side, who bears the notification costs, credit monitoring, and penalties? You will not always win this negotiation, especially with large vendors on take-it-or-leave-it terms — but you should know where you stand before you sign, not after the breach.
9. Can They Use Our Data for Anything Else?
Some vendors reserve rights to use "de-identified" data for their own analytics or product development. That may be fine — or it may be more than you want. Ask: what, exactly, are you permitted to do with our data beyond providing the service, and how is any de-identification performed? Read this clause specifically; it is where the surprises live.
10. Is This BAA Actually Current?
A BAA signed years ago against an older service arrangement may no longer reflect what the vendor does with your data today. Ask: when was this agreement last reviewed, and does it match the current scope of services? Set a recurring reminder to revisit every active BAA, because both your relationship and the regulations evolve. An outdated BAA is one an auditor will notice.
Signing Is the Start of the Obligation, Not the End
The BAA is not filed and forgotten — it is the beginning of an ongoing relationship you are accountable for. Maintain a living vendor inventory, keep every signed agreement retrievable, and revisit them on a schedule. If you are an MSP or manage compliance for others, the stakes multiply: your own BAA obligations as a business associate stack on top of your clients'. Either way, the goal is the same — when a vendor breach happens, you already know exactly what the agreement says, because you asked these questions before you signed.
Related Reading
- Your own BAA obligations as an MSP
- When a vendor outage becomes your problem
- 9 things OCR auditors actually ask for
- 10 HIPAA security tips to implement this week
Call to Action
Want a single place to track every vendor, every signed BAA, and every renewal date — so a missing agreement never surfaces during an audit? Schedule a walkthrough of HIPAA Security Suite, or take the 3-minute readiness quiz to find your biggest gap right now.