The BAA map: EHR, email, fax, biller, scheduler, everyone
Summary
Any vendor that creates, receives, maintains, or transmits your patients' protected health information to do a job for you is a business associate, and you need a signed business associate agreement before they touch it. That sweeps in your EHR, billing service, e-fax, cloud storage, email host, scheduler, transcription, and telehealth platform. It leaves out pure conduits like the postal service and other clinicians you refer to for treatment. If a vendor won't sign, that is your answer about the vendor.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
What makes a vendor a business associate
A business associate is any person or company that creates, receives, maintains, or transmits protected health information to perform a service for you 1Ref 1HHS Office for Civil Rights (2026).Business Associates.The definition of a business associate by function (create, receive, maintain, transmit) and the core contents a BAA must have.. The four verbs are the whole test — creates, receives, maintains, or transmits. If a vendor does any of those with your patients' information, it is a business associate, and the regulation names it as such by function, not by industry 2Ref 2Office of the Federal Register (2026).45 CFR Part 160 — General Administrative Requirements.The regulatory definition of business associate and the narrow conduit exception in 45 CFR Part 160.. What the vendor calls itself does not matter; what it does with the data does.
This is why the answer is almost always yes for a modern practice. The tools that make a one-person office run — the record system, the biller, the fax, the storage — exist precisely to handle patient information, which is what puts them inside the definition.
What the agreement has to say
A business associate agreement is a specific contract, not a line in a terms-of-service page. The rule requires it to spell out the permitted uses and disclosures of the information, require the vendor to safeguard it, require the vendor to report breaches to you, bind any subcontractors to the same terms, make the information available for access, amendment, and accounting, and return or destroy it when the relationship ends 3Ref 3Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The specific contract terms a business associate agreement must contain, including the subcontractor flow-down, under 45 CFR Part 164..
The subcontractor clause matters more than it looks. A business associate's own subcontractors are themselves business associates, and the duty flows down the chain — so the cloud provider your EHR vendor relies on is covered through that chain, not left uncovered because you never contracted with it directly.
The vendor map: who needs a BAA
Walk your practice's tools and ask the four-verb question of each. Most of the digital ones will be business associates. Your EHR, your billing or clearinghouse service, your e-fax, your cloud storage and backup, a hosted email or workspace suite that carries patient information, your scheduler, your transcription vendor, and your telehealth platform all handle protected health information and need a signed agreement 4Ref 4HHS Office for Civil Rights (2026).HIPAA and Telehealth.That a telehealth platform requires a BAA now that the COVID enforcement discretion has ended..
| Vendor | BAA needed? |
|---|---|
| EHR / practice-management system | Yes — it holds the record |
| Billing service or clearinghouse | Yes — it transmits claims with PHI |
| E-fax and secure-messaging services | Yes — PHI in transit and at rest |
| Cloud storage and backup | Yes — it maintains PHI even if it never views it |
| Hosted email or workspace with patient info | Yes — get the covered version and the BAA |
| Telehealth platform | Yes — the COVID enforcement discretion has ended |
| The practice line (VoIP / voicemail) | Yes if it stores voicemails or call data |
| Bookkeeping software with books without PHI | No — it holds no patient information |
Who does not need one
A few relationships look like vendors but are not business associates. The narrow conduit exception covers entities that merely transport information without accessing it beyond what transport requires — the postal service, a courier, an internet or phone carrier moving bits 2Ref 2Office of the Federal Register (2026).45 CFR Part 160 — General Administrative Requirements.The regulatory definition of business associate and the narrow conduit exception in 45 CFR Part 160.. Another clinician you refer a patient to is not your business associate; that is a treatment disclosure between two covered entities. And your own workforce is not a business associate.
The conduit exception is far narrower than it sounds, and it is where practices go wrong. A cloud service that stores your files persistently is not a conduit even if it never opens them — persistence is maintaining, and maintaining is one of the four verbs. Transport is a mail carrier; storage is a business associate.
When a vendor won't sign
Sometimes the answer to whether a tool is safe is the vendor's response to a simple request: will you sign a business associate agreement? A vendor that refuses is telling you it will not stand behind protecting the information — which usually means the tool does not belong in a covered practice. Many consumer apps sit outside HIPAA entirely, and the FTC's Health Breach Notification Rule may be what governs them instead 5Ref 5Federal Trade Commission (2026).Health Breach Notification Rule.That vendors and consumer apps outside HIPAA may be governed by the FTC's Health Breach Notification Rule..
Make the BAA question part of choosing any tool, not an afterthought once you are already dependent on it. It is far cheaper to rule out a vendor before migration than to unwind patient data from a service that would never sign.
Inventory your stack, then enforce it
You cannot sign agreements for vendors you have never listed, so start with the vendor stack. Build one inventory of every tool that touches patient information — the free Security Risk Assessment tool sized for small practices walks you through exactly this as part of the risk analysis the Security Rule requires 6Ref 6Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That the free ONC/OCR Security Risk Assessment tool guides a small practice through the vendor inventory and the risk analysis the Security Rule requires.. For each vendor, record whether a signed agreement is on file and when it was last reviewed.
Missing agreements are a documented enforcement target: OCR has penalized covered entities for handing patient information to vendors with no BAA in place, and a solo practice carries that liability directly 7Ref 7HHS Office for Civil Rights (2026).HIPAA Compliance and Enforcement.That OCR enforces HIPAA, including penalties against practices for missing business associate agreements.. Whether these rules bind you at all comes down to the covered-entity test — if you bill electronically, assume they do, and keep the inventory current.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThe definition of a business associate by function (create, receive, maintain, transmit) and the core contents a BAA must have.
- 2.Office of the Federal Register (2026). 45 CFR Part 160 — General Administrative Requirements. eCFR. link ✓The regulatory definition of business associate and the narrow conduit exception in 45 CFR Part 160.
- 3.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The specific contract terms a business associate agreement must contain, including the subcontractor flow-down, under 45 CFR Part 164.
- 4.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat a telehealth platform requires a BAA now that the COVID enforcement discretion has ended.
- 5.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). link ✓That vendors and consumer apps outside HIPAA may be governed by the FTC's Health Breach Notification Rule.
- 6.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That the free ONC/OCR Security Risk Assessment tool guides a small practice through the vendor inventory and the risk analysis the Security Rule requires.
- 7.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR enforces HIPAA, including penalties against practices for missing business associate agreements.
https://www.gale.care/for-providers/hip-baa-who-needs-one · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.