Prerequisites
- Both entities formed
- A privacy officer identified for the PC
- An inventory of every vendor that will handle PHI
Who needs a BAA with whom
What the BAA must contain
The required elements are specified at 45 C.F.R. § 164.504(e).1 A compliant BAA must:Steps
1
Execute the MSO–PC BAA before the first patient
Not after go-live. The MSO handles PHI from the moment it operates scheduling or billing.One BAA per PC. Each professional entity is a separate covered entity. A ten-PC group has ten BAAs with the MSO.
2
Inventory every vendor that touches PHI
Walk the data flow:
- EHR / practice management
- Clearinghouse
- Billing service or RCM vendor
- Cloud hosting and infrastructure
- Patient statement and communication vendors
- Answering service, transcription, interpretation
- Analytics and data warehouse tooling
- AI and LLM providers, and any model gateway or proxy
- Document storage and shredding
- Collections agency
- IT support with system access
3
Execute subcontractor BAAs
The MSO, as a business associate, must have BAAs with its own subcontractors. Those subcontractors are business associates in their own right and are directly liable under HIPAA.
4
Read the vendor's BAA rather than signing it unread
Most vendors present their own form. Check:
- Breach notification timeline — is it short enough for the PC to meet its own 60-day deadline?
- Whether the vendor may use PHI for its own purposes such as product improvement, and whether that is acceptable
- Indemnification and liability caps
- Whether subcontractors are permitted and how they’re controlled
- Return or destruction obligations at termination
- Where data is stored, including offshore
5
Build the BAA inventory
A single register: vendor, what PHI they handle, BAA execution date, renewal or review date, breach notification window, and the internal owner.
6
Review annually and on every new vendor
Add to the compliance calendar. See Set up your compliance calendar.
Verify it worked
- A BAA between the MSO and each PC, executed before PHI was handled
- All nine required elements present
- Every PHI-handling vendor identified
- Subcontractor BAAs executed
- Breach notification windows short enough to meet the covered entity’s deadline
- BAA inventory maintained with review dates
- Analytics and data warehouse infrastructure included
- No BAA sought with the bank for ordinary payment processing, and no PHI in bank fields
Common failure modes
Sources
- 45 C.F.R. § 164.504(e). eCFR. HHS OCR, Business Associate Contracts.