Guide

The Vendor Won't Sign a BAA: When You May Still Use the Tool

Summary

A telehealth vendor that refuses to sign a business associate agreement can still be used only if it is not a business associate at all, or if its own written terms already carry the required assurances. HIPAA makes a written agreement the gate for any vendor that creates, receives, maintains or transmits patient information on a practice's behalf. Refusing a customer's paper is not the same as refusing the obligations, so ask which one you are hearing.

By Gale Editorial · Updated 2026-09-01. Every figure cited to a dated source. How we write.

Can a vendor that won't sign a BAA still be used?

Rarely, and the reason has nothing to do with the vendor's willingness. Federal law decides the question by function. A company is a business associate when it creates, receives, maintains or transmits protected health information on a practice's behalf, for a function these rules regulate. The rule's own examples include claims processing, data analysis and practice management 1. A telehealth platform that carries the session and holds the recording sits inside that description.

The Privacy Rule turns the description into a paperwork gate. A covered entity may disclose protected health information to a business associate, or let it create, receive, maintain or transmit that information, only on satisfactory assurance. 45 CFR 164.502(e)(2) requires that assurance to be documented through a written contract or other written agreement or arrangement meeting the requirements of section 164.504(e) 2. A published trust page does not meet that, and neither does a sales engineer's email.

The Security Rule sets the same gate a second time, and for a telehealth tool it is the one that bites, because everything the tool touches is electronic. Under 45 CFR 164.308(b)(1) a covered entity may permit a business associate to create, receive, maintain or transmit electronic protected health information on its behalf only if it first obtains satisfactory assurances in accordance with section 164.314(a). Paragraph (b)(3) requires those assurances to be in writing 3.

But the rule asks for a written agreement, and it never says whose paper it has to be.

Ask which refusal you are hearing

Three different refusals arrive in the same sentence, and only one of them ends the conversation. A vendor may decline to sign a customer's own template while publishing its own agreement, which the rule accepts. A vendor may claim the conduit exception, the carve-out for a service that only carries information through. A vendor may say it never receives patient information at all, which is a claim about configuration, and it is testable in an afternoon.

So the first move is a written request through the vendor's support channel, asking for one thing: its own HIPAA business associate agreement, or the section of its terms of service that carries those obligations. Keep the reply, including a refusal. The date the practice learned something is a fact the rule cares about later.

Read whatever comes back against the terms the rule names. For electronic information, 45 CFR 164.314(a)(2)(i) sets three 4. The Privacy Rule list at 45 CFR 164.504(e)(2) adds the one solo practices forget until they leave: the obligation at termination to return or destroy the protected health information the vendor holds, or to keep protecting it under the same terms where return or destruction is not feasible 5.

The agreement has to oblige the vendor toWhere the term comes from
Comply with the Security Rule's own requirements for electronic protected health information45 CFR 164.314(a)(2)(i)
Bind any subcontractor that touches that information by an equivalent contract45 CFR 164.314(a)(2)(i)
Report security incidents it becomes aware of, including breaches of unsecured information45 CFR 164.314(a)(2)(i)
Return or destroy the information at termination, or keep protecting it if that is not feasible45 CFR 164.504(e)(2)(ii)(J)

A vendor whose terms already carry all four is answering the right question, whatever its sales team said about signing. The Privacy Rule list at 164.504(e)(2) runs longer than the rows above, so the agreement offered gets read against the whole section.

The conduit argument, and where it stops

A vendor calling itself a conduit is invoking a real exception and usually reaching past it. HHS explained in the 2013 omnibus final rule that the conduit exception is a narrow one, intended to exclude only those entities providing mere courier services, such as the U.S. Postal Service and its electronic equivalents, and that a conduit transports information without accessing it other than on a random or infrequent basis 6.

The same preamble closes the argument a video vendor tends to make next, that the stream is encrypted so nobody there can read it. HHS drew the line at the transient versus persistent nature of the opportunity to access, and said document storage companies maintaining protected health information on behalf of covered entities are business associates regardless of whether they actually view the information 6.

Recordings, transcripts, chat logs and the appointment record are all maintenance. A platform holding any of them is past the exception, whatever its encryption does.

Where a service genuinely only transmits, the line is softer than either side of the sales call admits: HHS said the question of access on a routine basis is fact specific, based on the nature of the services provided and the extent to which the entity needs access to perform them 6. So the question worth putting to the vendor is what it retains, and for how long.

Keeping patient information out of the tool

The rule attaches to the information, so a tool that never receives protected health information needs no agreement at all. That exit is real, and it is narrower than it sounds. Under 45 CFR 164.514(a), health information that does not identify an individual, and with respect to which there is no reasonable basis to believe the information can be used to identify an individual, is not individually identifiable health information 7.

Two routes reach that conclusion, and improvising is not one of them. Section 164.514(b)(1) accepts a documented determination by a person with appropriate knowledge and experience applying statistical and scientific principles. Section 164.514(b)(2) accepts removal of the listed identifiers, and only where the practice has no actual knowledge that the remaining information could identify the person 7.

A live session carrying a face and a voice cannot be reconfigured this way. Other tools can: a scheduling sheet rebuilt without names, a whiteboard used only for teaching material, a transcription step that runs on the practice's own machine before anything leaves it. Price that engineering against the cost of moving to a vendor that will paper the relationship, and decide on the numbers.

What running it anyway puts on the practice

The exposure lands on the practice, and it starts the moment information moves. 45 CFR 164.402 presumes a breach whenever protected health information is acquired, accessed, used or disclosed in a manner the Privacy Rule does not permit, unless the covered entity demonstrates a low probability that the information was compromised, through a risk assessment of at least four listed factors 8. The presumption runs against the practice, and the demonstrating is the practice's own work.

Continuing after learning is its own failure. Under 45 CFR 164.504(e)(1)(ii), a covered entity falls out of compliance if it knew of a pattern of activity or practice amounting to a material breach or violation of a business associate's obligation, unless it took reasonable steps to cure the breach or end the violation and, where those steps were unsuccessful, terminated the contract or arrangement if feasible 5.

That is what makes the written request worth sending even when the answer is predictable. It fixes a date, and it turns whatever happens next into a recorded decision instead of a drift.

None of this settles one particular arrangement. Whether a named vendor's terms clear 164.314(a)(2)(i) and 164.504(e)(2) is a reading of that vendor's contract, and it is worth an hour of a health care attorney's time before a full caseload moves onto a platform. Federal law is the floor here, not the ceiling; state privacy and telehealth law can reach the same relationship, and a state health department or attorney general's office is where that overlay is published.

What to do before the next session

Work it vendor by vendor rather than all at once. List the vendor stack, mark which tools receive or retain patient information, and send the same written request to each of those. The replies sort into three piles: a signed agreement already on file, terms of service that carry the required obligations, and no written assurance of any kind. The third pile is the one with a deadline attached.

  • Write down, for each tool, what it receives and what it retains. The retention answer decides the conduit question before any argument about it starts.
  • Ask for the vendor's own agreement in writing and keep the reply. Which vendors need a BAA follows from what each one holds.
  • Compare any agreement offered against the four terms above before accepting it, and note in the file who read it and when.
  • For anything still in the third pile, set a replacement date and record who is deciding. The rule's own remedy for an arrangement that cannot be cured is termination where feasible.
  • Apply the same test outward, past the video platform. A transcription service, a billing contractor and a baa-covered overseas assistant raise one question, and it is answered by one document.

Common questions

No. Compliance is a claim about a product; the rule asks for a document. The Privacy Rule requires satisfactory assurances to be documented in a written contract or other written agreement, and the Security Rule requires the same before the vendor handles any electronic patient information. Ask for the agreement itself, or for the clause of the terms of service that carries the obligations, and read that instead of the marketing page.

Usually yes, when it carries the required terms. Nothing in the rule requires a practice's own template, only a written agreement. At minimum it has to oblige the vendor to comply with the Security Rule, to bind subcontractors that touch electronic information, to report security incidents including breaches, and to return or destroy the information when the relationship ends. Read those four before accepting it.

Then the conduit exception may reach it, and what it retains decides the question. HHS treats the exception as narrow, aimed at courier services and their electronic equivalents, and treats a company that maintains information as a business associate whether or not it ever looks at it. Recordings, transcripts and appointment records are maintenance. Ask what is retained, and for how long.

Document what is known and the date it was learned, then decide with a record. A disclosure not permitted under the Privacy Rule is presumed to be a breach unless the practice shows a low probability that the information was compromised, so a documented risk assessment belongs in the file either way. The rule also expects reasonable steps to cure, and termination where feasible if those steps fail.

No. Encryption is a safeguards question and the business associate question is a separate one. HHS drew the line at whether the opportunity to access information is transient or persistent, and said storage companies holding protected health information are business associates regardless of whether they view it. Encrypted storage is still storage. Encryption changes the risk assessment after an incident; it does not decide whether the agreement was required.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Health and Human Services (2000). § 160.103 Definitions. Electronic Code of Federal Regulations (eCFR), Title 45, Part 160, Subpart A. linkThe functional business-associate test in 45 CFR 160.103: a person who creates, receives, maintains or transmits protected health information on behalf of a covered entity for a regulated function, and the rule's illustrative list including claims processing, data analysis and practice management.
  2. 2.U.S. Department of Health and Human Services (Office for Civil Rights) (2026). § 164.502 Uses and disclosures of protected health information: General rules.. Electronic Code of Federal Regulations (eCFR), Title 45, Subtitle A, Subchapter C, Part 164, Subpart E. link45 CFR 164.502(e)(1)(i) and (e)(2): a covered entity may let a business associate create, receive, maintain or transmit PHI only on satisfactory assurance, documented through a written contract or other written agreement or arrangement meeting the requirements of 164.504(e).
  3. 3.U.S. Department of Health and Human Services (2026). § 164.308 Administrative safeguards. Electronic Code of Federal Regulations, 45 CFR Part 164 Subpart C (Security Rule). link45 CFR 164.308(b)(1) and (b)(3): the Security Rule's independent gate for electronic PHI, permitting a business associate to handle it only if satisfactory assurances under 164.314(a) are obtained, and requiring those assurances to be documented in writing.
  4. 4.U.S. Department of Health and Human Services (2026). § 164.314 Organizational requirements. Electronic Code of Federal Regulations, 45 CFR Part 164 Subpart C (Security Rule). link45 CFR 164.314(a)(2)(i): the three Security Rule terms a vendor's own agreement must contain to do the work of a BAA, namely compliance with subpart C, an equivalent contract binding subcontractors, and reporting of security incidents including breaches of unsecured PHI.
  5. 5.U.S. Department of Health and Human Services (2026). 45 CFR 164.504 - Uses and disclosures: Organizational requirements. Electronic Code of Federal Regulations (eCFR). link45 CFR 164.504(e)(2), including the return-or-destroy obligation at termination, as the Privacy Rule list to check a vendor's terms against; and 164.504(e)(1)(ii), the duty to cure, end or terminate on a known pattern amounting to a material breach.
  6. 6.U.S. Department of Health and Human Services, Office of the Secretary (2013). Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules. Federal Register, 78 FR 5566 (January 25, 2013). linkHHS's explanation of the conduit exception in the 2013 omnibus final rule: that it is narrow and limited to mere courier services and their electronic equivalents, that entities maintaining PHI are business associates regardless of whether they view it, and that routine access by a transmission service is a fact-specific determination.
  7. 7.U.S. Department of Health and Human Services (Office for Civil Rights) (2026). § 164.514 Other requirements relating to uses and disclosures of protected health information.. Electronic Code of Federal Regulations (eCFR), Title 45, Subtitle A, Subchapter C, Part 164, Subpart E. link45 CFR 164.514(a) and the two permitted de-identification methods at (b)(1) expert determination and (b)(2) removal of the listed identifiers with no actual knowledge of re-identifiability, as the only routes by which information stops being PHI.
  8. 8.U.S. Department of Health and Human Services (2009). § 164.402 Definitions. Electronic Code of Federal Regulations (eCFR), Title 45, Part 164, Subpart D. link45 CFR 164.402: an impermissible use or disclosure is presumed to be a breach unless the covered entity demonstrates a low probability of compromise through a risk assessment of at least four listed factors.

https://www.gale.care/for-providers/pq-vendor-refuses-to-sign-baa · 8 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)