Skip to main content
HIPAA Compliance

What Is a Business Associate Agreement (BAA) and Who Needs One?

If a vendor touches your patient data — even indirectly — you need a signed BAA on file before ePHI moves. Here's a plain-English breakdown of what that means, what has to be in the document, and what happens if you skip it.

What Is a Business Associate?

A Business Associate is any person or entity that creates, receives, maintains, or transmits ePHI on behalf of a covered entity. If a vendor sees, stores, moves, or processes your patient data — they qualify.

Common Business Associates in Home Care

  • EHR/EMR vendors (PointClickCare, MatrixCare, WellSky)
  • Billing and clearinghouse services
  • IT service providers (like Arsi Tech Group)
  • Microsoft (for M365/Azure services processing ePHI)
  • Cloud storage and backup providers

What Must a BAA Contain?

  • Permitted uses and disclosures of ePHI
  • Obligations to safeguard ePHI
  • Breach notification requirements (60-day window)
  • Subcontractor flow-down requirements
  • Return or destruction of ePHI on termination

What If You Don't Have a BAA?

HHS can fine covered entities up to $100,000 per violation per year for missing BAAs. The average HIPAA settlement in 2024 was $490,000. A missing BAA is one of the fastest ways an otherwise-compliant agency lands on the OCR breach portal.

We Draft and Manage BAAs for MN Healthcare Providers

One monthly fee. All your vendors covered. No missing signatures on your compliance binder.

Talk to Us About BAAs