Compliance
What Is a BAA? Business Associate Agreements, Explained for Practices

A BAA is the contract that legally binds your vendors to protect patient data. Here is what a Business Associate Agreement is, who needs one, and what it must include.
If you run a dental or medical practice, you have almost certainly heard the phrase "we will sign a BAA," or been told that your vendors need one. It comes up whenever software, hosting, or a web partner touches patient information. And like a lot of compliance language, it often gets said without anyone stopping to explain what it actually means.
A Business Associate Agreement, or BAA, is one of the most important and most overlooked pieces of protecting patient data. This guide explains what a BAA is, who needs one, what it has to contain, and why a vendor's willingness to sign one tells you a great deal about whether you should work with them at all.
What a Business Associate Agreement actually is
A Business Associate Agreement is a contract required by HIPAA between your practice and any outside company that handles protected health information on your behalf. In HIPAA's language, your practice is a covered entity, and the vendor is a business associate. The agreement spells out how that vendor is allowed to use the information and, more importantly, the safeguards they are legally bound to keep around it. You can read the government's own explanation of business associates on HHS.gov.
In plain terms, a BAA is the paperwork that makes a vendor legally responsible for protecting your patients' data, not just verbally reassuring. Without it, you are trusting a handshake. With it, there is an enforceable contract behind that trust.
Who counts as a business associate
A business associate is any vendor that creates, receives, stores, or transmits protected health information as part of the service they provide to you. For a typical practice website and the systems around it, that often includes:
- Your web host. If your site stores or transmits any patient information, the company hosting it is handling PHI.
- Your form or intake tool. Anything that collects appointment requests, medical history, or contact details tied to care.
- Your email or messaging provider. If patient information flows through it.
- Cloud storage and backups. Wherever submitted data ultimately lives.
- Scheduling, billing, and practice-management software. The core systems that run on patient data every day.
If you are unsure which of your tools qualify, the simplest test is to ask: does this vendor ever touch information that connects a person to their care? If yes, they are almost certainly a business associate. For the bigger picture on how this fits together, see our guide on what makes a website HIPAA-compliant.
What a BAA must include
A BAA is not a formality you can scribble on a napkin. HIPAA sets out specific things the agreement has to address, and HHS even publishes sample business associate agreement provisions you can reference. A solid BAA covers, at minimum:
- The permitted uses and disclosures of protected health information, so the vendor cannot use your patients' data for anything you did not agree to.
- A requirement that the vendor implement appropriate safeguards to protect that information.
- An obligation to report any breach or security incident to you, and within a defined timeframe.
- Terms that extend the same protections to any subcontractors the vendor uses.
- What happens to the data when the relationship ends, including returning or destroying it.
A vendor who cannot explain how they meet these terms, or who hesitates to put them in writing, is telling you something important.
Why it matters for your practice
There are three reasons a BAA deserves your attention, and none of them are abstract.
First, it is legally required. If a vendor handles PHI on your behalf and there is no BAA in place, your practice is out of compliance, regardless of how careful the vendor happens to be. Second, it shifts and shares responsibility. A signed BAA makes the vendor accountable for their part in protecting patient data, rather than leaving all of the exposure on you. Third, and most practically, it is a filter. A vendor who readily signs a proper BAA has usually already built the safeguards to back it up. One who dodges the question has not.
Where BAAs show up around your website
Websites are where this gets missed most often, because the data collection can feel invisible. A contact form quietly emails submissions somewhere. An analytics or chat tool loads on a page where patients type sensitive details. Each of those is a place a business associate relationship may exist, and where a BAA should be in force. We go deeper on this in what HIPAA means for your forms, analytics, and chat.
Common misconceptions
- "A BAA makes me automatically compliant." It is a necessary piece, not the whole puzzle. You still need the actual safeguards, from encryption to access controls, to be in place.
- "A SOC 2 report replaces a BAA." It does not. They are different things, and one does not substitute for the other. Our guide on what SOC 2 is explains why.
- "Small vendors do not need one." Size does not matter. If they touch PHI, they need a BAA, whether they are a giant platform or a one-person shop.
- "My vendor is HIPAA compliant, so we are covered." Their compliance does not create the contract between you. The BAA still has to be signed.
What to do about it
You do not need to become a compliance officer. You need a short, honest inventory and a habit of asking one question before you adopt any new tool.
- List every vendor and tool that touches patient information, from your host to your intake form.
- For each one, confirm there is a signed BAA on file, and request one where there is not.
- Before adopting any new tool that will handle PHI, ask up front whether they will sign a BAA. If the answer is no, that is your answer about the tool.
- Keep your signed agreements somewhere you can actually find them.
If you want help sorting out which of your website's vendors need a BAA and whether your current setup is handling patient data responsibly, that is exactly the kind of thing worth getting a clear answer on. You can review our approach on the security and compliance page.
Get your agreements in order
A Business Associate Agreement is not red tape for its own sake. It is the contract that turns a vendor's promise to protect your patients into an enforceable obligation. Getting these in place is one of the more straightforward things you can do to reduce risk, and it doubles as a reliable test of which vendors take security as seriously as you do.
Not sure where your practice stands? Book a free call and we can walk through it, or get a tailored recommendation for your specific setup. No pressure, and no jargon.
Share this article
Jody Hartwell
Jody writes about building secure, modern, HIPAA-conscious websites and better patient experiences for dental, medical, and legal practices.
Trustform Digital
Secure, HIPAA-conscious websites that book more patients
We design fast, secure websites and local SEO for dental, medical, and legal practices, built and protected by a CISSP-certified developer. From dental website design and medical practice websites to local SEO and HIPAA-conscious patient tools, we build around exactly what your practice needs.


