Business associate agreements: who in your stack needs one

A business associate is not defined by what the vendor sells. It is defined by what the vendor touches. Under 45 CFR § 160.103, a business associate is a person who, on behalf of a covered entity, “creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter.”

Maintains is the word that catches people. A vendor does not have to read the data, use it, or want it. Holding it is enough, which is why storage, backup and IT support companies are business associates even when nobody at the vendor has any interest in your patients.

And before you start papering anything: if your clinic is not a HIPAA covered entity, there are no business associate agreements to sign. That analysis comes first, and it is at HIPAA for med spas.

Walk the actual stack

Most clinics have agreements with the obvious two and nothing else. Go system by system.

Vendor type Business associate?
EHR or charting system Yes
Online booking and scheduling Yes, if it holds patient detail
Text and email messaging platform Yes. See texting patients
Cloud storage and backup Yes, including general-purpose file storage
IT support with system access Yes
AI scribe or transcription Yes
Answering service Yes
Document shredding Yes, for physical records
Payment processor Usually not, where it handles payment data only
Cleaning and building services Generally not, absent access to records

The two most commonly missed are the general file storage where staff keep photos and spreadsheets, and whoever holds the domain and site if forms land in an inbox.

The clause nobody operates

This is the part that separates a binder from a program. Under 45 CFR § 164.504(e)(1)(ii), a covered entity is not in compliance if it “knew of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate’s obligation under the contract or other arrangement, unless the covered entity took reasonable steps to cure the breach or end the violation,” and if those steps were unsuccessful, terminated the arrangement where feasible.

Signing is not the compliance act. Noticing is. The rule creates an ongoing duty to act on what you know about the vendor, and it makes your inaction the violation.

The same structure runs downhill. Section 164.504(e)(1)(iii) puts the identical obligation on a business associate with respect to its subcontractors, which is how a failure three layers down in a stack you never see becomes a problem with your name on it.

What that means in practice

  • Ask where the data goes. Your vendor’s subcontractors are inside the chain. The agreement should require flow-down terms.
  • Do something with breach notices. A notification from a vendor is the start of the knowledge the rule cares about. File it, assess it, and record what you decided.
  • Keep a register. One page: vendor, what they touch, agreement date, renewal, who owns the relationship. If you cannot produce a list of who holds your patient data, you cannot operate any of this.
  • Be prepared to leave. The rule contemplates termination where a cure fails. That is only credible if you know what it would take to move, which is a question to ask before you sign rather than during an incident.
  • Re-check at renewal. Vendors change what they do. A booking tool that adds a marketing module has changed its data handling.

Where clinics get it backwards

The common pattern is a stack assembled by whoever was available, with agreements collected afterwards by someone told to “get the BAAs.” That produces signatures without a map, which fails the moment anyone asks where a specific record lives.

Build the map first. The agreements follow the map, and the map is the thing a regulator, a buyer’s diligence team and your own incident response all actually need. It is the same discipline we apply to how the structure fits together.

What this means for you

Start with the register rather than the paperwork, because the list of who holds your data is the artifact everything else depends on and most clinics cannot produce it. Then close the gaps, paying attention to general file storage and anything handling forms, which are the two that hide. Treat every vendor breach notice as something requiring a recorded decision, since § 164.504(e)(1)(ii) makes your knowledge the trigger and your inaction the failure. And if you concluded you are not a covered entity, skip all of it and put contractual security and breach terms in your vendor contracts instead, because the data risk is identical even when the statute is not.

Frequently asked questions

Which vendors need a business associate agreement?

Any vendor that creates, receives, maintains or transmits protected health information on your behalf. That reaches EHR, booking, messaging, cloud storage, IT support, transcription and answering services. A payment processor handling only payment data usually is not one.

Does my cloud storage provider need a BAA?

Yes, if patient information is stored there, including general-purpose file storage used informally by staff for photos or spreadsheets. The definition turns on maintaining the information, not on whether the vendor looks at it.

Is signing the agreement enough?

No. Under 45 CFR § 164.504(e)(1)(ii) a covered entity is out of compliance if it knew of a pattern of activity constituting a material breach by the business associate and failed to take reasonable steps to cure it, and if unsuccessful, to terminate where feasible.

What about my vendor’s subcontractors?

The same obligation applies to the business associate with respect to its subcontractors under § 164.504(e)(1)(iii). Your agreement should require those terms to flow down, and you should know where the data actually goes.

Do I need BAAs if my clinic is not a covered entity?

No. Business associate agreements are a HIPAA construct. You should still put security, confidentiality and breach-notification terms into your vendor contracts, because the underlying risk to the data is unchanged.


This is general information, not legal advice. Rules vary by state and change. Confirm your own facts with counsel.

Share this article with a friend

Reviewed by Victor D. Cruz, MD, founder of MDside, licensed in Florida (ME117105) and New York. Last reviewed 2026-09-20.