Skip to main content

How-to

The BAA checklist: what to check before sending PHI to a vendor

HIPAA has no certification. The business associate agreement is the artefact. The ten clauses 45 CFR 164.504(e) requires, where vendors narrow them, and what to verify first.

Solomon AmosPublished 9 Sep 2026Updated 18 Sep 202611 min read

Hands signing a contract with a fountain pen
Photo by Scott Graham on Unsplash

There is no HIPAA certification and no HIPAA registry. The Department of Health and Human Services does not certify vendors, and no badge on a trust centre changes that. What exists is a contract, the business associate agreement (BAA), whose required content the Privacy Rule sets out at 45 CFR 164.504(e). Send protected health information (PHI) to a vendor without one and the covered entity, not the vendor, is the party in breach. This checklist covers the clauses the rule requires, the places vendors narrow them, and the order in which to check.

35.8%
of 2025 healthcare data breaches occurred at business associates
HIPAA Journal, 2025 healthcare data breach report
21
OCR enforcement actions resolved in 2025
Second-highest annual count in HIPAA history
0
HIPAA certifications that exist
HHS does not certify vendors or products

Why the contract is the evidence

HIPAA regulates covered entities (providers, plans, clearinghouses) and their business associates (anyone that creates, receives, maintains or transmits PHI on their behalf). The Privacy Rule allows a covered entity to share PHI with a business associate only under a contract with specific content, and since the 2013 Omnibus Rule business associates are directly liable for Security Rule compliance and for their own subcontractors. The BAA is therefore both the permission and the allocation of liability. A vendor that says it is "HIPAA compliant" and will not sign a BAA is offering nothing a covered entity can use.

The contract must establish the permitted and required uses and disclosures of protected health information by the business associate.
A team reviewing printed documents at a table
The BAA is read by legal, security and the business owner. Each checks a different clause; the checklist below assigns them. · Photo by Annie Spratt on Unsplash

The ten required elements

ClauseWhat 164.504(e) requiresWhere vendors narrow it
Permitted and required usesOnly what the contract allows and the law requiresExcludes support tickets, analytics, product improvement or AI training unless named
No further use or disclosureNone beyond the contract or as required by lawDe-identification carve-outs; check the standard used
SafeguardsAppropriate safeguards; Security Rule compliance for ePHIPoints to the vendor’s own programme; ask for the SOC 2 or ISO evidence behind it
ReportingReport any use or disclosure not provided for, any security incident, any breach of unsecured PHIReporting windows of 30 to 60 days; "unsuccessful" incidents reported in aggregate
SubcontractorsFlow the same restrictions down in writingA named subprocessor list with a change notice period
Individual rightsSupport access (164.524), amendment (164.526), accounting (164.528)"Reasonable assistance" only; check response times
Covered entity obligationsComply with the Privacy Rule where performing the covered entity’s dutiesRarely limited
Books and recordsMake internal practices available to HHSRarely limited
TerminationReturn or destroy PHI, or extend protections if infeasibleDestruction after a retention window; backups excluded for a period
Authorised terminationCovered entity may terminate for material breachCure periods of 30 days or more

The first column follows 164.504(e)(2). The third column is what CertReports sees most often in published BAAs.

Where vendors limit the BAA

Most published BAAs are narrower than the marketing page. Three limits matter most. The covered products: often only an enterprise tier, and never beta features. The covered features: AI assistants, integrations, marketplace apps and support attachments are frequently excluded. The configuration you must apply: encryption settings, audit logging, retention and sharing controls that are your responsibility to switch on. A "HIPAA eligible" service is one you can configure to be covered, not one that is covered by default.

The covered services definition

Read the definition of "Covered Services" or "HIPAA Eligible Services" before anything else. Large cloud providers publish a list of eligible services and everything not on the list is out of scope. SaaS vendors tie coverage to a plan tier. If your plan or feature is not named, the BAA does not cover you, whatever the sales deck said.

Breach timing

Under 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Covered entities then owe individuals notice within 60 days of their own discovery under 164.404. A BAA that gives the vendor the full 60 days leaves you with little time; many covered entities negotiate ten business days or fewer.

The checklist

  1. 1

    Confirm the vendor offers a BAA at all

    Look on the trust centre or legal page. CertReports records a public BAA offer as a HIPAA row with a source link. No public offer means "no public evidence", not "no BAA"; ask. The HIPAA hub lists every vendor with a public offer.
  2. 2

    Match products and tiers to the order form

    Read the covered services definition. If your plan is not listed, stop here and ask for a written confirmation or an upgrade.

  3. 3

    Read the exclusions

    AI features, beta features, support attachments, marketplace apps and integrations are the usual carve-outs. Decide whether your workflow touches any of them.

  4. 4

    Check the configuration duties

    Many BAAs require you to enable encryption, restrict sharing or disable features. Assign an owner to each duty before go-live and record it.

  5. 5

    Check subprocessors and flow-down

    The vendor must bind its subcontractors to the same terms. Ask for the subprocessor list and the notice period for changes.

  6. 6

    Check reporting windows against your own duties

    Compare the vendor’s incident and breach reporting timelines with 164.410 and your own 60-day clock under 164.404.

  7. 7

    Ask for the security evidence behind it

    A BAA says the vendor will safeguard PHI; a SOC 2 Type II or ISO 27001 certificate shows that someone checked. See healthcare vendors with public HIPAA evidence and their other frameworks.
Rows of servers in a data centre corridor
Safeguards in a BAA point at the vendor’s security programme. The programme is what the SOC 2 or ISO evidence describes. · Photo by Taylor Vick on Unsplash

What 2025 enforcement tells a buyer

Business associates are now the fastest-growing source of healthcare breaches. HIPAA Journal’s 2025 report puts 35.8 percent of reported breaches at business associates against 57.5 percent at providers, and the largest breach of the year, at Conduent Business Services, exposed the PHI of more than 62 million people through a business associate. OCR resolved 21 enforcement actions in 2025, and the finding that recurs across them is the absence of an accurate risk analysis before the incident. For a buyer, that is the question to put to a vendor: when was your last risk analysis, and does your SOC 2 or ISO scope cover the systems that will hold our PHI?

Business associates have become the single fastest-growing source of healthcare data breaches.

What CertReports says and does not say

A "vendor-stated" HIPAA row on CertReports means the vendor publicly offers a BAA and the index captured the page with a date and a snapshot. It never means the vendor is HIPAA compliant, because compliance is a property of how you use the service under the contract, not of the vendor alone. There is no registry to verify against, which is why HIPAA rows are never registry-verified.

If you are the vendor

Publish the BAA, the covered services list and the configuration duties on your trust centre. Reviewers will find them in minutes instead of asking sales, and the CertReports row will link straight to them.

People also ask

What must a HIPAA business associate agreement include?

The elements in 45 CFR 164.504(e)(2): permitted uses and disclosures, no further use, safeguards, reporting of incidents and breaches, subcontractor flow-down, support for individual rights, Privacy Rule compliance where applicable, HHS access to books and records, and return or destruction at termination.

Can a SaaS company be HIPAA certified?

No. HHS does not certify vendors or products. A vendor can sign a BAA and can hold SOC 2 or ISO 27001 evidence for its safeguards, but "HIPAA certified" describes nothing that exists.

What is the difference between HIPAA eligible and HIPAA compliant?

Eligible means the vendor will cover the service under a BAA if you configure it as required. Compliant is a property of the whole arrangement, including your configuration and your own policies, not a label a vendor can carry alone.

Who is liable if a business associate breaches PHI?

Since the 2013 Omnibus Rule, business associates are directly liable for Security Rule compliance and for their subcontractors. The covered entity remains responsible for having a compliant BAA in place and for its own notification duties.

How quickly must a business associate report a breach?

Without unreasonable delay and no later than 60 days after discovery, under 164.410. Many covered entities negotiate shorter windows in the BAA because their own 60-day clock to notify individuals starts at their discovery.

Do subcontractors of a business associate need a BAA?

Yes. The business associate must bind any subcontractor that handles PHI to the same restrictions in writing. Ask for the subprocessor list and confirm each entry is covered.

HIPAABAAbusiness associatehealthcarevendor review
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like