The BAA is HIPAA’s supply-chain control, and its logic is unforgiving: the moment PHI reaches an unpapered vendor, the violation is complete, whether or not anything bad ever happens. Since 2013 the obligation runs all the way down the subcontractor chain, and OCR has settled repeatedly on missing-BAA facts alone. The operational answer is an inventory discipline, every vendor relationship mapped against PHI flows, no procurement path that lets PHI move before signature, because retrofitting agreements after a breach is the one thing the rule cannot forgive.
| Trigger | Vendor creates, receives, maintains, or transmits PHI for you |
|---|---|
| Required terms | 45 CFR 164.504(e) list |
| Subcontractors | Flow-down BAAs at every tier (Omnibus Rule) |
| Conduit exception | Transmission-only, random/infrequent access |
| Cloud storage | BA status even without decryption keys |
| No BAA | Independent violation; settlements to $750K+ |
Running the BAA program
Inventory vendors against PHI flows. The BAA list should reconcile with the risk analysis’s data-flow map; unmatched vendors are findings waiting to be made.
Gate procurement. No PHI-touching service goes live without an executed BAA; make it a contracting checkpoint, not a compliance cleanup.
Diligence the chain. Subcontractor lists and downstream BAA confirmations belong in vendor reviews; the cloud computing guide covers CSP-specific terms.
Wire BAAs into breach response. Vendor breach-reporting deadlines feed your own 60-day clock; the breach playbook shows the timeline math.
Third-party scripts on patient-facing pages can create surprise business associates: see who is receiving your visitors’ data with a free scan.