Business Associate Agreements: What Every HIPAA Vendor Relationship Requires
A missing or incomplete Business Associate Agreement is a direct HIPAA violation on its own — no breach required. Here is what a BAA must contain, who needs to sign one, and how Armorstack operates as a business associate for its own healthcare clients.
A Business Associate Agreement (BAA) is the contract HIPAA requires between a covered entity (a healthcare provider, health plan, or clearinghouse) and any vendor — a business associate — that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. It must be in place before PHI is shared, must specify permitted uses, required safeguards, and breach notification obligations, and must flow the same requirements down to any subcontractors the business associate uses. Skipping it is a violation regardless of whether anything ever goes wrong.
When a Vendor Needs to Sign a BAA
HIPAA defines a business associate broadly: any third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate, and that list is much wider than most organizations initially assume. It reaches well beyond obviously health-focused vendors to include managed IT and cybersecurity providers, cloud hosting and backup vendors, billing and revenue-cycle services, transcription services, and any managed service provider with administrative access to systems that store PHI — even if that vendor never intends to look at the data itself.
The determining question is not the vendor’s primary business description, but whether PHI passes through, is stored by, or is accessible to that vendor as part of the services it provides. A BAA must be executed before that access begins — not after the relationship starts, and not only once a problem surfaces.
This obligation also flows downstream: if a business associate uses its own subcontractors to perform functions involving PHI (a cloud provider using a sub-processor, for example), the business associate must obtain a corresponding BAA from that subcontractor. Learn more about the broader framework at HIPAA Compliance for Healthcare Organizations.
What a BAA Must Contain
A precise description of how the business associate is permitted (and not permitted) to use or disclose the PHI it receives, limited to what is necessary to perform the contracted function.
An obligation for the business associate to implement appropriate administrative, physical, and technical safeguards that prevent use or disclosure of PHI beyond what the agreement permits.
A defined obligation for the business associate to report any use, disclosure, or security incident involving PHI to the covered entity, typically within a specific window such as 60 days of discovery.
A requirement that the business associate obtain equivalent BAAs from any of its own subcontractors that in turn create, receive, maintain, or transmit PHI — the same protections have to travel down the chain.
Terms addressing what happens to PHI at termination of the relationship — typically requiring the business associate to return or securely destroy all PHI, or, where that is not feasible, to extend the same protections indefinitely.
Provisions giving the covered entity the ability to terminate the agreement if it learns the business associate has materially violated its terms, and typically to request evidence of compliance.
Armorstack as a Business Associate
Because Armorstack provides managed IT, cybersecurity, and compliance services to healthcare clients — work that routinely involves access to systems storing PHI — Armorstack itself operates as a business associate under HIPAA for those engagements, not merely as a vendor helping a client comply. Armorstack executes a BAA with every covered-entity client as standard practice before any PHI-adjacent work begins, and it flows the same obligations down to any of its own subcontractors that could touch client PHI.
In practice, that means Armorstack’s own administrative, physical, and technical safeguards, breach notification procedures, and subcontractor management are built to satisfy the same BAA obligations Armorstack asks its healthcare clients to hold their other vendors to — and SENTRY’s continuous monitoring plays directly into meeting the breach-detection and notification timelines a BAA requires.
For the full picture of how BAAs fit into a broader HIPAA program — alongside the Security Rule, Privacy Rule, and Breach Notification Rule — see HIPAA Compliance for Healthcare Organizations, or explore all compliance frameworks Armorstack supports.
BAAs, Answered Straight
What is a HIPAA Business Associate Agreement?
A required contract between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on its behalf, obligating the vendor to safeguard that data and defining each party’s HIPAA responsibilities.
When does a vendor need to sign a BAA?
Before it creates, receives, maintains, or transmits PHI on behalf of a covered entity — a much broader group of vendors than most organizations initially assume, including managed IT and cloud providers.
What must a BAA contain?
Permitted uses and disclosures, required safeguards, breach notification obligations, subcontractor flow-down requirements, and terms for returning or destroying PHI at termination.
What happens if a BAA is missing?
Operating without a required BAA is itself a HIPAA violation, regardless of whether a breach occurs, exposing both the covered entity and the business associate to enforcement risk.