A vendor sends a BAA with the message, “This takes care of HIPAA.” Before signing, ask what the service actually does. A BAA is important where required, but it does not tell you whether the practice has enabled the right settings, purchased the right service tier or understood where records will go.
This guide gives a practice owner or manager an agenda for reviewing a proposed relationship. It is not a ready-to-sign contract, an exhaustive clause checklist or a substitute for legal review. Some questions concern HIPAA requirements; others are practical protections to negotiate in the broader agreement.
Identify the service before reviewing the paper
Write down the vendor's legal name, the product, the features the practice intends to use, the information involved, and what the vendor intends to do with that information. An agreement covering one product may not cover an optional recording, analytics, or messaging service. Keep the order form and service description with the BAA so the complete arrangement receives attention.
A hypothetical practice buys a scheduling tool and later enables automated call summaries. The additional feature may change what information is created and retained. That is a reason to revisit the arrangement rather than assume an old signature answers every new question.
Separate HIPAA provisions from business terms
HHS's BAA guidance addresses permitted uses and disclosures, safeguards, reporting, assistance with individual rights, HHS access, subcontractors, termination, and return or destruction of information when feasible. Its sample provisions need adaptation; they are not a complete agreement for every transaction.
Distinguish those subjects from price, service availability, insurance, liability allocation, and migration support. Both sets of terms can matter. A service level promise does not replace privacy terms, and a privacy contract does not guarantee that an export will work when the practice needs it.
Ask what happens after an incident
Find the reporting contact and the process for escalation. Does the practice know who answers outside ordinary hours? What information will the vendor provide as an investigation develops? How will corrections or follow-up notices reach the right person?
Write a hypothetical scenario into the review agenda: an account has been accessed unexpectedly, the scope is unknown, and staff need an update. Ask the vendor to describe its communication process without treating the response as a guarantee. Contractual reporting language and actual operational readiness are related but different subjects. Counsel can help evaluate the terms and applicable notification duties.
Understand cloud storage and downstream services
A cloud provider's inability to read encrypted information does not, by itself, remove business associate status when it maintains electronic protected health information. HHS's cloud-computing guidance addresses this distinction. Encryption is an important topic; it is not a universal exception to the need for an appropriate agreement.
For practical review, request an explanation of the service chain. Which provider hosts the application? Which systems support backups, customer service or transcription? Who communicates a material change? You are trying to understand the relationship well enough to manage it, not collect an impressive but unread vendor spreadsheet.
Plan how patients and staff retrieve information
Walk through a sample record request using test data. Can the practice locate the relevant information? Does the export contain the attachments or messages staff expect? Who can perform it, and where will the resulting file be stored?
At termination, consider access during transition, usable export formats and assistance charges. The BAA and service agreement may address different parts of that process. Ask how retained copies and downstream systems are handled. These are review questions, not a direction to delete records that the practice must preserve under other obligations.
Keep the decision usable after signature
Save the final documents, approved features and open issues together. Give staff a short operational summary: which account to use, which optional features remain off and where incidents should be reported. If nobody implementing the system sees the decision, the contract review has not reached the workflow.
HHS's Security Rule overview describes the wider safeguard framework. A vendor contract sits inside that broader work. Use our clinic compliance guide to connect contract review with staff access, systems and incident planning.
Kim Cunningham of Cunningham Law, LLC advises healthcare practices on contracts and compliance. Bring the vendor's proposed documents and a plain language account of the service to a free 30-minute consultation request. Share sensitive materials only after the firm provides appropriate instructions.

