How business associate agreement works
A BAA typically covers the permitted uses and disclosures of protected health information, the safeguards the business associate must apply, a requirement to report any breach or unauthorized use to the covered entity within a set timeframe, and what happens to the data when the relationship ends, such as returning or destroying it.
Any vendor that touches this information as part of its work, including a billing company, IT provider or offshore support team, needs a signed BAA before it begins handling that data, not after. A covered entity that fails to get a BAA in place with a vendor handling this data is itself out of compliance with HIPAA, regardless of the vendor's own practices.
Example
A dental practice hires a billing support provider to post insurance payments. Before any patient data is shared, the practice and the provider sign a BAA specifying the provider will encrypt the data, restrict access to trained staff, and notify the practice within 5 business days of any suspected breach, consistent with HIPAA's breach notification expectations.
Business associate agreement in QuickBooks Online vs Xero
Not software-specific: a BAA is a legal contract rather than a software feature, though cloud providers such as Google Workspace and Microsoft 365 offer their own BAA to customers handling protected health information on their platforms. Businesses typically maintain a signed BAA on file with every vendor and cloud service that touches this data.
Common mistakes
- Letting a vendor begin working with protected health information before a BAA is signed, which leaves the covered entity out of compliance from the first day of the engagement.
- Signing a BAA with vague breach notification language instead of a specific timeframe, which can delay a practice's own required response if the vendor discovers a problem late.
- Forgetting what happens to the data at engagement end, which can leave protected health information sitting with a vendor with no contractual obligation to return or destroy it.
Why it matters
A signed BAA is what makes a vendor relationship involving patient data compliant under HIPAA, so skipping it or signing one with weak terms puts a healthcare provider at regulatory and financial risk. For a medical or dental practice choosing a billing or bookkeeping provider, a BAA covering safeguards, breach notification and data handling at offboarding is a non-negotiable part of vetting any vendor that will touch protected health information.
Related terms
How LedgerBPO handles business associate agreement
We sign a business associate agreement with every healthcare client before handling protected health information, covering safeguards, breach notification and data handling at the end of an engagement. Our compliance page has more detail on how we structure BAAs and the training our staff complete before working on healthcare accounts.