Skip to main content

HIPAA

The BAA checklist: what to check before sending PHI to a vendor

HIPAA has no certification. The business associate agreement is the artefact; here is what it must cover and how vendors limit it.

Last updated 17 Sep 2026

HHS declined to create HIPAA certification criteria in 2003 (68 FR 8334). A vendor that says it is "HIPAA compliant" is making a claim; the enforceable artefact is the business associate agreement.

Does the vendor sign one at all?

Many vendors publish a BAA page, some only sign on request, and some refuse or exclude products. CertReports records the availability (public, on request, none) with the page and the capture date.

Which products and plans are covered

BAAs frequently cover only enterprise plans or specific products. Check the covered-services list against what you are buying, and whether AI features are excluded.

The clauses that matter

  • Permitted uses and disclosures of PHI, and any de-identification rights the vendor keeps.
  • Safeguards, and whether a HIPAA-mapped SOC 2 or HITRUST assessment backs them.
  • Breach notification timelines (HIPAA requires notice without unreasonable delay, no later than 60 days).
  • Subcontractor flow-down: the vendor must bind its own subprocessors.
  • Return or destruction of PHI at termination.

What a buyer still cannot see

Whether the vendor signed a BAA with anyone else is never public. CertReports records only whether the vendor offers one and where it says so.