BAA Terms and Regulatory References
Business Associate: Under 45 CFR Section 160.103, a Business Associate is a person or entity that performs functions or activities on behalf of, or provides services to, a covered entity that involve access to Protected Health Information (PHI). This includes claims processing, data analysis, utilization review, billing, and legal, actuarial, accounting, consulting, or financial services.
Business Associate Agreement (BAA): A written contract required under 45 CFR Section 164.502(e) between a covered entity and a business associate. The agreement must establish the permitted and required uses and disclosures of PHI by the business associate and provide satisfactory assurances that the business associate will appropriately safeguard the information.
Electronic Protected Health Information (ePHI): As defined in 45 CFR Section 160.103, ePHI is individually identifiable health information that is transmitted by or maintained in electronic media. This includes patient records, billing data, and insurance information stored or sent electronically.
Vendor vs. Business Associate: A vendor is only a Business Associate if it creates, receives, maintains, or transmits PHI on behalf of a covered entity. A vendor that never accesses, handles, or stores PHI does not meet the definition of a Business Associate and does not require a BAA.
Business Associate Agreement FAQ
BAA Basics
A Business Associate, as defined under 45 CFR Section 160.103, is a person or organization that performs functions or activities on behalf of a covered entity involving the use or disclosure of Protected Health Information (PHI). If the work involves creating, receiving, maintaining, or transmitting PHI, that entity is likely a Business Associate.
A BAA is a written contract required under 45 CFR Section 164.502(e). Under this regulation, covered entities must obtain satisfactory assurances from their business associates that PHI will be appropriately safeguarded. The agreement establishes the permitted uses and disclosures of PHI and the responsibilities of each party. Learn more about our BAA management services.
Many people think every vendor needs a BAA. That is not true. Being a vendor and being a Business Associate are not the same thing.
Specific Vendor BAA Requirements
It depends on how you use it. If Microsoft stores, sends, or handles your patient data (ePHI), then yes, you likely need a BAA with them. Microsoft does offer a BAA for qualifying Microsoft 365 plans, and any organization using Microsoft 365 to process ePHI should execute one before using the service for that purpose.
If you use Google Workspace to store, send, or handle patient data, you should get a BAA from Google. Google provides a BAA for Google Workspace accounts, and an administrator must accept it in the Admin Console before using Workspace services with ePHI.
In most cases, yes. An IT company that has access to systems containing ePHI meets the definition of a Business Associate under 45 CFR Section 160.103, even if it does not store patient data directly. Managed service providers, help desk vendors, and IT support companies typically require a BAA.
Yes. A shredding company that handles records containing PHI meets the definition of a Business Associate because it maintains or has access to PHI during the destruction process. A BAA is required before the shredding company begins handling your records.
Usually, no. A janitorial service does not typically create, receive, maintain, or transmit PHI, so it generally does not meet the Business Associate definition. However, if janitorial staff have unsupervised access to areas where PHI is stored or visible, practices should implement physical safeguards and may consider a confidentiality agreement as a precaution.
BAA Management
Fix a missing BAA as soon as you find it.
BAAs should be reviewed at minimum annually. Most practices review their BAAs once a year or when there is a material change in the vendor relationship, such as a change in the scope of services, the types of PHI handled, or the vendor's security posture. Annual review also aligns with the Security Risk Assessment cycle required under 45 CFR Section 164.308(a)(1)(ii)(A).
Vendor Vetting & Due Diligence
One of the biggest mistakes is failing to evaluate vendor risk.
At a minimum, check if a BAA is needed and review vendor risk. Use a short survey, a security review, or both.
Know exactly how patient data will be shared, stored, sent, accessed, or released.
Yes. A vendor can decline to sign any agreement.
Weigh the risks of keeping the vendor. Decide if you can still use them safely or if you need to find a new option.
One Guy Consulting helps practices inventory their vendors, determine which require BAAs, and manage the entire BAA execution process. Our vendor management service includes risk evaluation and ongoing monitoring.
Need Help Managing Your Business Associate Agreements?
Book a free 30-minute intro call. We will review your vendors, tell you which ones need BAAs, and show you how we handle the whole process.
Book Your Free Intro CallMore HIPAA FAQ Resources
- HIPAA compliance FAQ covering basics, risk assessments, training, and policies
- HIPAA audit readiness frequently asked questions
- HIPAA technology and security frequently asked questions
- BAA management service details
- Vendor risk management services
- Real-world HIPAA compliance case studies
- Full pricing comparison with plan details