Which of your vendors need a BAA, and how to actually get one
The legal test for who is a business associate, the vendor-by-vendor walkthrough for an ABA clinic, the narrow truth about the conduit exception, and what a vendor's HIPAA compliant badge does and does not mean.
Last verified: 2026-07-12
Somewhere in your clinic right now, PHI is sitting on a computer you do not own, run by a company you found on the internet. That is not a scandal; it is how modern practice works. The question HIPAA asks is narrower and colder: does that company owe you anything, in writing, about what happens to that data? For most clinics the honest answer is “some of them,” and nobody is sure which.
Here is the test, the walkthrough, and the mechanics of actually getting the paper signed.
The test
A business associate is a person or entity, outside your workforce, that creates, receives, maintains, or transmits PHI in the course of performing functions or services for you or on your behalf: claims processing, billing, data analysis, practice management, quality assurance, and similar functions, or services like legal, accounting, consulting, and administrative support that involve access to PHI (45 CFR 160.103).
Read the four verbs again: creates, receives, maintains, or transmits. “Maintains” is the one that catches people. A vendor that merely stores your PHI, never looks at it, never processes it, is a business associate, because storage is maintenance.
And the obligation is yours before it is theirs: you may disclose PHI to a business associate only after obtaining satisfactory assurances, in a written contract, that it will safeguard the information (45 CFR 164.502(e); for ePHI, 45 CFR 164.308(b)). No signed BAA, and every day PHI flows to that vendor is itself an impermissible disclosure. The violation is not the vendor’s breach that might happen later. The violation is the unpapered relationship, today.
The conduit exception is smaller than you have been told
There is a genuine exception for mere conduits: entities that transport information without accessing it other than randomly or infrequently, the way the postal service carries a letter or an internet service provider moves packets. It covers couriers and pipes.
It does not cover storage, and this is the point HHS has made explicitly in its cloud computing guidance: a cloud service that maintains ePHI is a business associate even if it holds only encrypted data and lacks the decryption key. “They can’t read it anyway” is an excellent security posture and a nonexistent legal defense. If your session videos sit in a cloud bucket, the bucket’s owner is your business associate, encrypted or not.
The walkthrough
The vendors an ABA clinic actually uses, and where each lands.
| Vendor | BAA? | Why |
|---|---|---|
| Practice management / EHR | Yes | Creates, receives, and maintains the core clinical record. |
| Data collection platform | Yes | Session data about identifiable children is PHI, and the platform maintains it. |
| Telehealth platform | Yes | Transmits sessions; the pandemic-era enforcement pass for consumer video apps ended in 2023. |
| Billing company / clearinghouse | Yes | The definitional example: claims processing on your behalf. |
| Cloud storage and file sync | Yes | Maintains ePHI; encryption without the key does not change the answer. |
| Email provider, if PHI moves through it | Yes | Workspace and 365 both sign BAAs on business tiers; consumer tiers do not, which is your answer about consumer tiers. |
| AI notetaker or scribe | Yes | Receives session audio and creates clinical text; a business associate the moment it is switched on. |
| Text messaging platform for parent communication | Yes | Transmits and usually stores PHI. |
| E-signature service | Yes | Consent forms and plans carrying PHI are created and maintained there. |
| IT support / managed service provider | Yes | Access to systems holding ePHI is access to ePHI. |
| Shredding and disposal company | Yes | Receives PHI to destroy it; destruction is a service performed on PHI. |
| Answering service | Yes | Receives client names and callbacks, which is PHI. |
| Accountant or lawyer, if the work involves PHI | Yes | Named in the definition itself; if the engagement never touches PHI, no. |
| Payroll provider | Usually no | Employment records you hold as an employer are not PHI; it becomes yes only if client PHI flows to them. |
| Another treating provider | No | Disclosures for the recipient's treatment of the client are provider-to-provider, not business associate. |
| The payer | No | A health plan is its own covered entity, not your business associate. |
| Internet service provider, phone carrier, postal service, courier | No | The actual conduit exception: transport without access. |
| Cleaning crew, landlord | No | No PHI function performed for you; incidental exposure is handled by safeguards, not contracts. |
Two edge notes. Your workforce never needs a BAA: employees, trainees, and volunteers under your direct control are inside the entity (45 CFR 160.103), and the RBT is workforce, not vendor. And subcontractors chain: your business associate must bind its own subcontractors to the same restrictions (45 CFR 164.502(e), 164.504(e)), which is their paper to sign, not yours, but your BAA must require it.
What the contract must actually say
The required contents live at 45 CFR 164.504(e), with the Security Rule’s additions at 45 CFR 164.314(a). The contract must: establish the permitted uses and disclosures, no broader than what you could do yourself except the associate’s own management and data aggregation; require appropriate safeguards, including Security Rule compliance for ePHI; require reporting to you of improper uses and disclosures, security incidents, and breaches of unsecured PHI; require the same restrictions flow down to subcontractors; support the individual rights, access, amendment, and accounting; make records available to HHS; require return or destruction of PHI at termination where feasible; and let you terminate for material violation.
One clause deserves your pen rather than the vendor’s template: the breach reporting deadline. The regulation gives a business associate up to 60 days to report a breach to you, and your own notification clocks run from your discovery. A vendor’s day 59 report leaves you one day. Negotiate the contract number down: five to ten business days is common and reasonable, and a vendor who refuses to report a breach to you inside two weeks is telling you something.
The badge and the paper
Every vendor in the walkthrough will advertise itself as HIPAA compliant. Understand precisely what that phrase is: a claim that the product can be configured and operated in a compliant way. It is not a legal undertaking to you. A vendor’s HIPAA compliant badge is marketing; the signed BAA is the legal instrument. The corollary cuts both ways: a signed BAA with a sloppy vendor does not make the arrangement safe, and a genuinely secure product without a BAA is still an impermissible disclosure.
Mechanics of getting it signed, honestly stated: with enterprise health vendors it is routine, a standard document behind a request form or account tier. With general-purpose platforms it is a plan feature: business tiers sign, consumer tiers do not, and a consumer tier that will not sign has answered your procurement question for you. If a vendor has no BAA process at all, that is not a negotiation to win; that is a vendor that has told you PHI is not its business, and believing them is the correct response.
“A vendor's HIPAA compliant badge is marketing; the signed BAA is the legal instrument.”
Sequence matters: the BAA is signed before PHI flows, not after the pilot, because the violation begins with the first record, not the invoice. And when the relationship ends, the return-or-destruction clause is the one you actually invoke; a departed vendor quietly holding six years of session data is an inventory problem you no longer control.
The list is the program
Every obligation on this page collapses into one artifact: a current list of your vendors, which of them touch PHI, and where each signed BAA lives. It is page one of vendor risk in your risk analysis, it is the first thing an investigator asks for after the risk analysis itself, and it is the thing that quietly rots as staff adopt new tools. The AI notetaker nobody vetted did not appear on the list, which is exactly the problem: the list is only as good as the habit of asking, before any new tool touches a child’s data, what does this vendor hold, and have they signed.
The short version
- Anyone outside your workforce who creates, receives, maintains, or transmits PHI while working for you is a business associate, and sharing PHI with them without a signed BAA is itself a violation.
- Cloud storage is a business associate even if the data is encrypted and the vendor cannot read it; the conduit exception covers couriers and pipes, not storage.
- The walkthrough below covers the vendors an ABA clinic actually uses, from the practice management system to the AI notetaker.
- A HIPAA compliant badge means the vendor can support compliance; only a signed BAA makes them legally obligated to.
- Put a breach-reporting deadline in the contract far shorter than 60 days; your vendor's day 59 report leaves you one day of your own clock.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Definitions, including business associate and subcontractor45 CFR 160.103https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- Disclosures to business associates45 CFR 164.502(e)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- Business associate contracts, Security Rule45 CFR 164.308(b)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Business associate contract contents45 CFR 164.504(e)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
- Organizational requirements, Security Rule BAA contents45 CFR 164.314(a)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.314
- HHS guidance on HIPAA and cloud computingHHS.gov, Office for Civil Rightshttps://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- HHS guidance on business associatesHHS.gov, Office for Civil Rightshttps://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
Every vendor, every BAA, one honest list.
WiseUpHIPAA keeps your vendor inventory, tracks which ones touch PHI, holds the signed BAAs against them, and shows you honestly which relationships are papered and which are exposure.