Skip to main content
The PC is a HIPAA covered entity. The MSO handles protected health information on the PC’s behalf, which makes it a business associate, and a written business associate agreement (BAA) is required before the MSO touches any PHI.

Prerequisites

  • Both entities formed
  • A privacy officer identified for the PC
  • An inventory of every vendor that will handle PHI

Who needs a BAA with whom

Banks are generally not business associates for ordinary payment processing. HIPAA excludes financial institutions’ payment activities from the business associate definition. That is why you don’t need a BAA to receive payer EFTs, and also why you must never put PHI in a bank memo field, because the exclusion covers processing payments, not receiving clinical data.

What the BAA must contain

The required elements are specified at 45 C.F.R. § 164.504(e).1 A compliant BAA must:

Steps

1

Execute the MSO–PC BAA before the first patient

Not after go-live. The MSO handles PHI from the moment it operates scheduling or billing.One BAA per PC. Each professional entity is a separate covered entity. A ten-PC group has ten BAAs with the MSO.
2

Inventory every vendor that touches PHI

Walk the data flow:
  • EHR / practice management
  • Clearinghouse
  • Billing service or RCM vendor
  • Cloud hosting and infrastructure
  • Patient statement and communication vendors
  • Answering service, transcription, interpretation
  • Analytics and data warehouse tooling
  • AI and LLM providers, and any model gateway or proxy
  • Document storage and shredding
  • Collections agency
  • IT support with system access
A denial analytics warehouse built from 835 data holds PHI. Teams building it as a finance project routinely miss the BAA, the encryption requirement, and its inclusion in the risk analysis. See HIPAA for MSO-PC operators.
3

Execute subcontractor BAAs

The MSO, as a business associate, must have BAAs with its own subcontractors. Those subcontractors are business associates in their own right and are directly liable under HIPAA.
4

Read the vendor's BAA rather than signing it unread

Most vendors present their own form. Check:
  • Breach notification timeline — is it short enough for the PC to meet its own 60-day deadline?
  • Whether the vendor may use PHI for its own purposes such as product improvement, and whether that is acceptable
  • Indemnification and liability caps
  • Whether subcontractors are permitted and how they’re controlled
  • Return or destruction obligations at termination
  • Where data is stored, including offshore
5

Build the BAA inventory

A single register: vendor, what PHI they handle, BAA execution date, renewal or review date, breach notification window, and the internal owner.
6

Review annually and on every new vendor

Add to the compliance calendar. See Set up your compliance calendar.

Verify it worked

  • A BAA between the MSO and each PC, executed before PHI was handled
  • All nine required elements present
  • Every PHI-handling vendor identified
  • Subcontractor BAAs executed
  • Breach notification windows short enough to meet the covered entity’s deadline
  • BAA inventory maintained with review dates
  • Analytics and data warehouse infrastructure included
  • No BAA sought with the bank for ordinary payment processing, and no PHI in bank fields

Common failure modes

Sources

  1. 45 C.F.R. § 164.504(e). eCFR. HHS OCR, Business Associate Contracts.