
A business associate agreement allocates breach notification obligations, defines permitted uses of protected health information, and governs what subcontractors may do with it. Signing one without reading the subcontractor clause is how offshore exposure goes undiscovered until a contract audit finds it.
A Business Associate Agreement is required whenever a vendor handles protected health information on a practice's behalf. It usually gets signed as a formality. The clauses that matter are the ones nobody reads.
What it actually allocates
Permitted uses. What the vendor may do with PHI, and what they may not. Narrower is better.
Safeguards. What the vendor commits to implement.
Breach notification. How quickly they must tell you, and in what detail. This is the clause with real operational consequence — your own notification obligations run on a clock that starts when you learn of a breach.
Subcontractors. Whether the vendor may pass PHI to others, and on what terms.
Return or destruction at termination, which is easy to agree and hard to enforce later if it is vague.
The subcontractor clause
This is where exposure hides. A vendor may subcontract work — including offshore — and if the clause permits it broadly, PHI can reach parties you never evaluated.
The questions worth asking directly: do you subcontract any part of this work, is any of it performed outside the United States, and are those subcontractors bound by equivalent terms? A vendor who cannot answer plainly has not thought about it.
The practical checks
- Breach notification measured in days, not "promptly".
- Subcontractor use disclosed rather than merely permitted.
- Offshore handling stated explicitly if it occurs.
- Return or destruction with a defined timeframe.
The specific terms are a matter for your own counsel. The point here is that the agreement is doing real work and is worth reading once.
Read the breach notification timing
Your own notification obligations run on a clock, and a BAA permitting the vendor sixty days to tell you can consume most of it before you know anything happened.
Negotiate that period down. It is one of the few BAA terms with a direct operational consequence.
Ask where the data actually goes
The subcontractor clause is the mechanism, but the practical question is who your vendor uses and where they are. That answer belongs in writing, especially where payer or facility contracts restrict offshore handling.
Keep a register
A list of every vendor with a BAA, the date signed, and what data they handle. Most practices cannot produce this, and it is the first thing asked for after any incident.
Review them when vendors change
A BAA signed with a vendor that has since been acquired, changed platforms or added subcontractors may no longer describe what is actually happening.
Refresh them at renewal rather than treating them as permanent. The document is only protective while it is accurate.
Common questions
- What is a business associate agreement?
- A contract required under HIPAA between a covered entity and a vendor handling protected health information, setting out permitted uses, safeguards and breach obligations.
- Who needs a BAA?
- Any vendor that creates, receives, maintains or transmits protected health information on your behalf — billing companies, clearinghouses, software vendors, shredding services.
- What does the subcontractor clause do?
- It requires your vendor to bind their own subcontractors to equivalent terms. Without it, PHI can reach parties you never evaluated.
- Does a BAA transfer liability?
- It allocates obligations between the parties but does not remove your own compliance responsibilities as a covered entity.
- How quickly must a breach be reported to me?
- Whatever the agreement specifies, which is negotiable. A vendor-drafted BAA often allows longer than you would want given your own notification deadlines.
Denials Piling Up?
We handle the revenue cycle end to end — coding by certified coders, claim submission, denial management and appeals, and A/R follow-up, with six reported numbers every month.
