CUNNINGHAM LAW · WEBSITE PREVIEW FOR REVIEW
Healthcare resources

Cunningham Law · Healthcare

Business Associate Agreement Checklist: Before You Sign

Review a healthcare vendor’s business associate agreement: permitted uses, incident reporting and contract exit questions. Prepare for a discussion with Kim.

Two professionals reviewing paperwork beside a laptop and stethoscope; generated editorial image

A practical starting point

A Business Associate Agreement (BAA) governs a business associate’s handling of protected health information. Review it alongside the service contract and actual workflow, because a signature alone does not verify a vendor’s safeguards.

A vendor sends a BAA with the message, “This takes care of HIPAA.” Before signing, ask what the service actually does. A BAA is important where required, but it does not tell you whether the practice has enabled the right settings, purchased the right service tier or understood where records will go.

This guide gives a practice owner or manager an agenda for reviewing a proposed relationship. It is not a ready-to-sign contract, an exhaustive clause checklist or a substitute for legal review. Some questions concern HIPAA requirements; others are practical protections to negotiate in the broader agreement.

Identify the service before reviewing the paper

Write down the vendor's legal name, the product, the features the practice intends to use, the information involved, and what the vendor intends to do with that information. An agreement covering one product may not cover an optional recording, analytics, or messaging service. Keep the order form and service description with the BAA so the complete arrangement receives attention.

A hypothetical practice buys a scheduling tool and later enables automated call summaries. The additional feature may change what information is created and retained. That is a reason to revisit the arrangement rather than assume an old signature answers every new question.

Separate HIPAA provisions from business terms

HHS's BAA guidance addresses permitted uses and disclosures, safeguards, reporting, assistance with individual rights, HHS access, subcontractors, termination, and return or destruction of information when feasible. Its sample provisions need adaptation; they are not a complete agreement for every transaction.

Distinguish those subjects from price, service availability, insurance, liability allocation, and migration support. Both sets of terms can matter. A service level promise does not replace privacy terms, and a privacy contract does not guarantee that an export will work when the practice needs it.

Ask what happens after an incident

Find the reporting contact and the process for escalation. Does the practice know who answers outside ordinary hours? What information will the vendor provide as an investigation develops? How will corrections or follow-up notices reach the right person?

Write a hypothetical scenario into the review agenda: an account has been accessed unexpectedly, the scope is unknown, and staff need an update. Ask the vendor to describe its communication process without treating the response as a guarantee. Contractual reporting language and actual operational readiness are related but different subjects. Counsel can help evaluate the terms and applicable notification duties.

Understand cloud storage and downstream services

A cloud provider's inability to read encrypted information does not, by itself, remove business associate status when it maintains electronic protected health information. HHS's cloud-computing guidance addresses this distinction. Encryption is an important topic; it is not a universal exception to the need for an appropriate agreement.

For practical review, request an explanation of the service chain. Which provider hosts the application? Which systems support backups, customer service or transcription? Who communicates a material change? You are trying to understand the relationship well enough to manage it, not collect an impressive but unread vendor spreadsheet.

Plan how patients and staff retrieve information

Walk through a sample record request using test data. Can the practice locate the relevant information? Does the export contain the attachments or messages staff expect? Who can perform it, and where will the resulting file be stored?

At termination, consider access during transition, usable export formats and assistance charges. The BAA and service agreement may address different parts of that process. Ask how retained copies and downstream systems are handled. These are review questions, not a direction to delete records that the practice must preserve under other obligations.

Keep the decision usable after signature

Save the final documents, approved features and open issues together. Give staff a short operational summary: which account to use, which optional features remain off and where incidents should be reported. If nobody implementing the system sees the decision, the contract review has not reached the workflow.

HHS's Security Rule overview describes the wider safeguard framework. A vendor contract sits inside that broader work. Use our clinic compliance guide to connect contract review with staff access, systems and incident planning.

Kim Cunningham of Cunningham Law, LLC advises healthcare practices on contracts and compliance. Bring the vendor's proposed documents and a plain language account of the service to a free 30-minute consultation request. Share sensitive materials only after the firm provides appropriate instructions.

Your review checklist

Select the items you want to discuss. This creates a planning agenda, not a compliance score or legal determination. Your selections stay on this page and are not submitted.

0 items selected

Common questions

Does every healthcare vendor need a BAA?

No. The actual role and handling of protected information matter. Review whether a business associate relationship exists rather than relying on the vendor’s industry label.

Does a signed BAA prove that software is compliant?

No. Review the agreement, service configuration, safeguards and actual practice workflow together.

Sources and further reading

General educational information, not legal advice. Application depends on the facts and governing law.

Talk through your practice’s questions.

Kim Cunningham of Cunningham Law offers a free 30-minute consultation. Share a general description of your question so Kim can arrange the next step.

Request a free consultation