Malek + Malek
contact@malekattorneys.com (208) 215-2411
×
  • About Us
    • Our Firm
    • Team
    • Awards
    • Careers
  • Practices
    • General Counsel
    • Contract Law
    • Mergers & Acquisitions
    • Real Estate Transactions
    • Human Resources Law
    • Corporate Litigation
    • Appellate Law
    • Healthcare Law
  • Licensed States
    • Alaska
    • California
    • Idaho
    • Montana
    • Oregon
    • Utah
    • Washington
    • Wyoming
  • Resources
    • Blog
    • In the News
    • Webinars
    • Newsletter Signup
  • Offices
    • Boise
    • Coeur d’Alene
    • Kennewick
    • Spokane
  • Contact Us
Business

How to Write, Maintain, and Enforce a Business Associate Agreement

Sep 30, 2026

Every healthcare practice works with vendors who touch patient data, from billing companies to cloud storage providers and more. Before protected health information (PHI) is used by an external party, HIPAA requires a signed Business Associate Agreement (BAA). In this blog, we look at what makes up a strong BAA, plus how to maintain and enforce an agreement that protects your practice, vendor relationship, and patients.

Prefer to listen? Watch this video to hear Malek + Malek Attorney Hannah Kimball and Medcurity Senior Business Analyst Jordan Scherich discuss this topic.

This conversation comes from our live Business Associate Agreements webinar, where you can find more details on the session and watch the full recording.

Understanding Business Associate Agreements 

What Is a Business Associate Under HIPAA?

A business associate is any vendor that creates, receives, maintains, or transmits PHI on your behalf. Examples include billing companies, IT vendors, medical records shredding services, or phone answering services. If a vendor touches PHI to perform a service for you, it’s a business associate under HIPAA, and you need a signed BAA before that vendor starts work. A BAA is not required for your own employees, or for vendors with no access to patient-facing data.

Why Business Associate Agreements Matter

The agreement sets the rules for the relationship, including when and how the vendor reports an incident so you can meet your own notification obligations to patients under HIPAA, who bears the cost if something goes wrong, and what happens to your data when the relationship ends.

The consequences of getting this wrong can be significant, with penalties coming from the federal government and potential exposure to class action claims. Often, the risks are unseen and unexpected, like a vendor employee’s laptop getting stolen or a cloud provider having a breach. A well-formed and up-to-date BAA is crucial to minimizing your risk, plus protecting patients’ data and keeping their trust.

When Is a Business Associate Agreement Required?

Under HIPAA, the agreement has to be signed before work begins, not during. A common mistake we see is a practice, or even an individual, starts a free trial with real patient data, or a vendor runs a demo using actual patient records, with a promise to sign an agreement that never materializes. As a best practice, don’t share data or login credentials until the agreement is signed and stored somewhere both parties can access it.

Key HIPAA Business Associate Agreement Requirements and Negotiable Terms

HIPAA requires the following to be in every BAA:

  • Permitted and required uses and disclosures
  • Appropriate safeguards under the Security Rule
  • Reporting of breaches and security incidents
  • Same restrictions for subcontractors
  • Support for individual rights: access, amendment, accounting
  • Books and records available to HHS
  • Return or destruction of PHI at termination
  • Termination for material breach

Beyond those baseline requirements, several terms are negotiable:

  • Liability caps and indemnification
  • Specific notification window
  • Cyber insurance requirements
  • Audit and assessment rights
  • De-identification and secondary data use
  • Where data may be stored or accessed

Let’s take a closer look at a few of these terms.

Limitations of Liability: What It Means and What to Watch

A limitation of liability is a cap on what the vendor will pay. It has nothing to do with what the breach actually costs your practice. Some vendors are quite adept at limiting liability and will include clauses in their Master Services Agreement that override your BAA. Be sure to review both documents together so you can understand your full exposure.

Insurance and Indemnification

It’s a good idea to require the BAA to mandate insurance from the vendor, and include indemnification language directly in the agreement.

Breach Notification Window

When something goes wrong, like a breach of data, HIPAA’s baseline for is “without unreasonable delay and no later than 60 days after discovery” (45 CFR § 164.410). You can negotiate a tighter window, such as 72 hours or five business days, which gives your practice more runway to investigate and respond before your own patient notification clock starts running.

Subcontractors’ Use of Data

Your vendor likely relies on its own subcontractors. Under HIPAA, they’re responsible for how those subcontractors handle your data. During the negotiation process, ask and document their answers to these questions:

  1. What vendors do you use?
  2. How will they use our data?
  3. Where are they located?
  4. What agreements do you have with them?

Ask again at renewal because vendors change who they are working with and how. If a vendor won’t answer, or won’t hold its own subcontractors accountable, that’s a reason to consider walking away from the agreement since they are demonstrating noncompliance with HIPAA.

De-Identified Data, AI Tools, and the 18 HIPAA Identifiers 

De-identified data technically falls outside of HIPAA’s protections. This means that, once data is de-identified, a vendor may not be obligated to return it, and it can be used to train artificial intelligence (AI) tools or shared with other vendors without your knowledge.

This can happen unintentionally, especially in our digital world. Staff may use an AI tool in a way that feels harmless, without realizing it involves patient data. This has become one of the fastest-growing sources as analytics and AI products become more common, both as standalone products and embedded in existing products.

To reduce risk, your BAA needs to define how de-identified data can and can’t be used and confirm that the vendor removes HIPAA’s 18 specified identifiers.

How to Keep Business Associate Agreements Current 

It’s common for BAAs to need updates over multi-year vendor engagements as vendors change their scope of work and their policies. Maintain an inventory of every tool your practice uses, and store all signed agreements in one place. Appoint a specific person to own vendor relationships, and when that role changes hands, make reviewing the inventory and BAAs part of the transition.

Proposed HIPAA Security Rule Update: What It Could Mean for BAAs 

HHS published a Notice of Proposed Rulemaking on January 6, 2025, proposing the first update to the HIPAA Security Rule since 2013 (McDermott Will & Emery, July 2026). As of this writing, HHS’s most recent Unified Agenda projects final action for July 2027, pushed back from an earlier May 2026 estimate.

The proposed changes include that business associates would need to report the activation of contingency plans within 24 hours, and covered entities would need written verification at least once every 12 months, and that their business associates have specific technical safeguards in place. If finalized, many BAAs will need to be revised to reflect these requirements.

Common Business Associate Agreement Pitfalls 

Most problems surface at the beginning or end of a vendor relationship. Train your staff to be cautious of these red flags:

  • Signing up for a free trial before a BAA is in place
  • Ending a relationship without a certificate of destruction, so the old vendor still holds your data
  • Agreements that were never countersigned
  • Agreements that are outdated and don’t reflect current HIPAA requirements
  • Auto-renewed agreements with vendors that have been acquired, renamed, or no longer exist
  • Scope creep, where a vendor adds a new service, an AI feature, for instance, that the original BAA never addressed

BAA Checklist: What to Do Now

Proper BAA management starts with an audit of your current practices. Follow these steps to help keep BAA management achievable while protecting yourself and patients.

  1. Inventory every vendor tool your practice uses, including free tools and ones paid for with a credit card
  2. Rank vendors by risk, and start with the riskiest. 
  3. Work with an attorney to review any existing BAAs or negotiate new agreements, going in order of risk.
  4. Sign (or update) a BAA before more data is shared or work begins
  5. Set a renewal reminder and build in an annual review
  6. Build an offboarding checklist that cuts off access and secures proof of data destruction

How a HIPAA Compliance Attorney Can Help 

A healthcare attorney can draft or review your agreement terms, negotiate with vendors on your behalf, flag legal changes that affect your existing contracts, and enforce the return or destruction of data when a relationship ends. Look for an attorney who practices in both healthcare law and HIPAA compliance specifically.

If your practice hasn’t reviewed its vendor agreements in the past year, or you’re bringing on a new vendor and aren’t sure where to start, Malek + Malek’s healthcare team can help you review, draft, or negotiate BAAs that actually protect your practice.

Frequently Asked Questions (FAQs)

What Is a Business Associate Agreement?

A Business Associate Agreement (BAA) is a contract required under HIPAA between a healthcare entity and any vendor that creates, receives, maintains, or transmits protected health information on the entity’s behalf. It sets rules for how the vendor handles that data and what happens if something goes wrong.

Who counts as a business associate?

Any vendor with access to PHI to perform a service for you: billing companies, IT support, records shredding, answering services, and similar vendors. Your own employees and vendors without PHI access don’t need a BAA.

What are the HIPAA penalties for not having a BAA?

Working with a vendor on PHI without a signed BAA is a HIPAA violation on its own, separate from any breach. Penalties can come from the federal government, and a breach without a BAA in place can also expose your practice to potential class action claims.

How often should we review our BAAs?

At least annually, and again anytime a vendor relationship changes materially, such as a merger, a new service offering, or a change in where your data is stored.

Does de-identified data need to be covered in our BAA?

Yes. HIPAA doesn’t protect de-identified data by default, which means your BAA is the only place setting rules for how a vendor can use it, including whether it can train AI tools with it.

This blog is not legal advice and does not create an attorney-client relationship with our firm. The content is intended to promote a general understanding of legal concepts and should not be relied upon as a substitute for obtaining legal advice from a qualified attorney regarding the reader’s specific circumstances. Readers should consult legal counsel for advice concerning their individual situations. All content is provided without any representations or warranties regarding completeness, accuracy, or timeliness.

Business Associate Agreement
Topics Covered Here
Contents hide
Understanding Business Associate Agreements
What Is a Business Associate Under HIPAA?
Why Business Associate Agreements Matter
When Is a Business Associate Agreement Required?
Key HIPAA Business Associate Agreement Requirements and Negotiable Terms
Limitations of Liability: What It Means and What to Watch
Insurance and Indemnification
Breach Notification Window
Subcontractors’ Use of Data
De-Identified Data, AI Tools, and the 18 HIPAA Identifiers
How to Keep Business Associate Agreements Current
Proposed HIPAA Security Rule Update: What It Could Mean for BAAs
Common Business Associate Agreement Pitfalls
BAA Checklist: What to Do Now
How a HIPAA Compliance Attorney Can Help
Frequently Asked Questions (FAQs)
What Is a Business Associate Agreement?
Who counts as a business associate?
What are the HIPAA penalties for not having a BAA?
How often should we review our BAAs?
Does de-identified data need to be covered in our BAA?

Related Articles

Why AI Contract Review Is Not Enough to Protect Your Business

Paste a contract into a chatbot, ask it to flag unusual language, and within seconds, you have a summary that sounds thorough and uses the right legal terms. It...

Read more
How to Terminate an Employee Without Creating a Lawsuit

By the time a business owner or HR lead calls an attorney about an employee problem, the issue has usually been building for weeks, if not months. This slow...

Read more
Idaho’s Bathroom Bill: What Business Owners Need to Know

Idaho’s House Bill 752 was originally scheduled to take effect on July 1, 2026, but faces an uncertain future. At the time of this writing, it is pending a...

Read more

Ready to work with us?

This field is for validation purposes and should be left unchanged.
We are committed to keeping you up to date on legal matters that may impact you. We send 1-2 informative emails per month.
Consent: By hitting submit, you understand that we do not become your attorneys. That only happens if we both agree to the representation.(Required)

Our vision is to be a force of justice for the world. Since 2015, Malek + Malek has partnered with businesses and healthcare providers across Idaho, Washington, and the Pacific Northwest, delivering tailored legal counsel in business law, corporate litigation, and regulatory compliance so you can focus on changing the world for the better.

About Us
  • Our Firm
  • Team
  • Awards
  • Careers
Practice Areas
  • General Counsel
  • Contract Law
  • Mergers & Acquisitions
  • Real Estate Transactions
  • Human Resource Law
  • Corporate Litigation
  • Appellate Law
  • Healthcare Law
States We Practice In
  • Alaska
  • California
  • Idaho
  • Montana
  • Oregon
  • Utah
  • Washington
  • Wyoming
Resources
  • Blog
  • In the News
  • Webinars
  • Newsletter
Contact Us
  • Get In Touch
  • contact@malekattorneys.com
  • (208) 215-2411
Office Locations
Boise
101 S. Capitol Boulevard, Suite 301
Boise, ID 83702
208.473.7009
Coeur d’Alene
601 E. Front Avenue, Suite 304
Coeur d’Alene, ID 83814
208.215.2411
Spokane
601 W. Riverside Avenue, Suite 1320
Spokane, WA 99201
509.606.1500
Kennewick
Columbia Center Heights Executive Suites
Kennewick, WA 99336
509.606.1500

© 2026 Malek + Malek. All Rights Reserved.

  • Disclaimer
  • Privacy Policy
  • Sitemap