A vendor needs a business associate agreement when it creates, receives, maintains, or transmits protected health information on your behalf. That is the whole test, from the federal definition at 45 CFR 160.103, and every list of examples is just that sentence applied. It does not matter whether the vendor thinks of itself as a healthcare company, whether it ever looks at the data, or whether the data is encrypted. What matters is the function: if PHI passes through the vendor's hands, or sits on the vendor's systems, because you hired it, a BAA belongs in place before the first byte moves. This article sorts the common vendor categories into yes, no, and the borderline cases where buying teams argue.
The test, in one sentence
Ask two questions about any vendor:
- Will it create, receive, maintain, or transmit PHI? Note "maintain": storage alone counts. A vendor that hosts data it never opens is still performing a business associate function.
- Is it doing so on our behalf? This separates vendors (BAA) from other covered entities receiving PHI for their own treatment or payment purposes (no BAA needed for that disclosure).
Two yeses mean BAA. For what the agreement itself must contain once you have concluded one is needed, see what a BAA obligates a vendor to do.
Vendors that need a BAA
| Vendor type | Why |
|---|---|
| EHR, practice management, patient portal vendors | Create, maintain, and transmit PHI as their core function |
| Cloud hosting and storage holding PHI | "Maintain" includes storage, even encrypted, even no-view (HHS cloud computing guidance) |
| Billing companies, clearinghouses, coding services | Receive and process PHI on your behalf |
| IT providers and MSPs with access to systems holding PHI | Access to maintain systems is access to PHI |
| Transcription, dictation, and AI scribe services | Receive clinical content to produce the record |
| E-fax, secure email, patient texting platforms | Transmit and typically store message content containing PHI |
| Answering services taking clinical messages | Receive PHI from patients on your behalf |
| Shredding and record storage companies | Maintain and dispose of records containing PHI |
| Data analytics, population health, quality reporting vendors | Receive identifiable data to perform services for you |
| Collection agencies pursuing patient balances | Receive PHI (at minimum, identity and account details) to perform payment activities on your behalf |
Who does not need one
- Your own workforce. Employees, students, and volunteers under your direct control are covered by training and policies, not BAAs.
- Other providers treating the patient. Sending records to a specialist for treatment is a permitted disclosure between covered entities, not a business associate relationship.
- Pure conduits. Services that only transport data, with no storage beyond transient technical necessity: the postal service, couriers, and internet service providers. The exception is narrow, and it is the most abused concept on this list; more below.
- Janitorial, maintenance, and similar services. Incidental proximity to PHI is not a business associate function. A cleaning crew that might glimpse a fax cover sheet needs facility access controls, not a contract.
- Banks processing standard payment transactions. Clearing a patient's card payment falls under a specific statutory carve-out for financial institutions' payment processing.
- Vendors receiving only de-identified data. If data is properly de-identified under the HIPAA standard before it leaves your systems, it is no longer PHI. The de-identification itself has to be real, which is a separate diligence question.
The borderline cases that generate the arguments
"We're just a conduit." The conduit exception covers transmission-only services where any storage is transient and technical, like a router buffering packets. A vendor that stores your messages, files, or faxes so you can retrieve them later is maintaining PHI and is a business associate. If the data is at rest on their systems as a feature, the exception does not apply, whatever the sales deck says.
"The data is encrypted and we can't read it." HHS addressed this directly in its cloud computing guidance: a no-view cloud provider storing encrypted ePHI is still a business associate, key or no key. Encryption changes the risk profile and belongs in the security addendum; it does not change the classification.
"We're a general-purpose tool, not a healthcare product." The definition looks at function, not industry. A generic file-sharing tool, calendar, or note-taking app becomes a business associate the day your staff put PHI in it. This is the reasoning behind buying the healthcare tier of mainstream software: the vendor signs a BAA for that tier and scopes its service accordingly. If the vendor offers no BAA on any tier, the tool is not usable for PHI at all.
Free tiers and consumer accounts. Almost never covered by a BAA, even when the paid tier of the same product is. The document follows the account type, and so does your compliance position.
Subcontractors: the chain does not stop with you
A business associate's subcontractors that handle PHI are themselves business associates, and the regulation requires BAAs down the chain: you sign with your vendor, your vendor signs with its hosting provider, and so on to wherever the PHI stops. You do not sign with your vendor's subcontractors directly, and you are entitled to ask any vendor two questions before trusting the chain: which subcontractors will hold our data, and do you have BAAs with each of them? A vendor that cannot answer has told you the chain is unmanaged.
When a vendor refuses to sign
A refusal is an answer. Disclosing PHI to a vendor performing business associate functions without a BAA in place is a violation on your side, before anything ever goes wrong on theirs. The options, in descending order of preference: the vendor signs (most healthcare-serious vendors have a standard BAA ready); you choose a competitor that signs; or you restructure the workflow so the vendor never receives PHI, and verify the restructuring holds in practice. "They promised to be careful" is not a fourth option. The regulation text is at 45 CFR 160.103 (definitions) and 45 CFR 164.502(e) (disclosures to business associates), and HHS publishes its cloud computing guidance for the storage cases.