The Business Associate Agreement is one of the most overlooked documents in a medical practice, right up until it is the most important one. If a vendor can see, store, or touch your patients' protected health information, HIPAA requires a signed BAA with that vendor. Most practices have some of them. Very few have all of them. That gap is exactly where a manageable incident turns into a reportable one.
What a BAA actually is
A Business Associate Agreement is a contract that binds a vendor who handles protected health information on your behalf to HIPAA's requirements. It spells out how they will safeguard the data, what they can and cannot do with it, and their obligations if there is a breach. It is not paperwork for its own sake. It is the mechanism that extends your compliance obligations to the vendors you depend on, and it is one of the first things the Office for Civil Rights looks for after an incident.
Who needs one
The test is simple: if a vendor can access, store, transmit, or process your patients' data, they need a BAA. That includes more vendors than most practices realize:
- Your IT provider or managed services provider
- Cloud and hosting providers
- Your EMR or practice management vendor
- Backup and storage providers
- Email providers, when email contains patient information
- Billing companies, RCM partners, and offshore billers
- Shredding and disposal companies that handle records
Notably, Microsoft will sign a BAA for Microsoft 365 under most business plans, but the coverage only applies when the environment is configured correctly. A BAA on file does not make a misconfigured system compliant.
Where practices get exposed
The common failure is not refusing to sign BAAs. It is losing track of them. A practice signs BAAs with its major vendors at setup, then adds a new e-prescribing service, a new cloud tool, a new billing partner, and never circles back. Two years later, several vendors are touching patient data with no agreement in place. If one of those vendors has a breach, the practice is exposed for the gap, and "we meant to" is not a defense. Given that HIPAA penalties in 2026 run as high as 2,190,294 dollars per violation for willful neglect, that exposure is not theoretical.
What good BAA management looks like
- A living inventory of every vendor that touches patient data, kept current as vendors are added and removed.
- A signed, current BAA on file for each one.
- Configuration that actually matches the agreement, because a BAA with a misconfigured system is a false sense of security.
- A review on a regular cadence, so new vendors do not slip through.
How Galleon helps
As your IT partner, we sign a BAA with you, and we help you keep the rest of your vendor agreements in order as part of a real compliance posture. We handle the technical safeguards behind the BAA, HIPAA risk assessments, access controls, encryption, and audit logging, and we produce the documentation that holds up under review. We have walked practices through real breach situations involving the OIG and legal counsel, so we know what the evidence needs to look like before it is needed.
If you are not certain that every vendor touching your patient data has a current BAA on file, that uncertainty is the finding. Explore our Regulatory Compliance service, take the free IT Risk Assessment, or schedule a discovery call.