HIPAAmart

Third-party risk · 9 min read

Business Associates

Learn when a vendor is a business associate, what a BAA should cover, and how subcontractors extend your compliance responsibilities.

Reviewed August 2026

Definition

A business associate is generally a person or entity that performs certain functions or services for a covered entity involving the use or disclosure of protected health information.

In practice

  • A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.

Who this applies to

  • Covered entities engaging service providers
  • Vendors and consultants handling PHI on behalf of a covered entity
  • Business associates engaging subcontractors that handle PHI

What the rule asks for

  • Identify whether the relationship and services fall within the business associate framework.
  • Use a written business associate agreement when required.
  • Define permitted uses, safeguards, incident reporting, subcontractors, and return or destruction of PHI.
  • Maintain vendor oversight proportional to the risk and services involved.

How teams put it into practice

  • Classify vendors by data access, system privilege, and operational impact.
  • Review the BAA alongside security documentation and actual product behavior.
  • Track renewal dates, subprocessors, security reviews, and offboarding evidence.

Common mistakes

  • Assuming a vendor's marketing statement is a substitute for a signed agreement.
  • Signing a BAA without validating retention, support access, logging, and deletion behavior.
  • Ignoring subcontractors and cloud service dependencies.

Questions that come up

Does a BAA make a vendor HIPAA compliant?

No. A BAA allocates obligations between parties. Each organization remains responsible for its own safeguards, oversight, and compliance decisions.

References