Skip to content
ClinicOnCall

Guide

What a BAA actually requires

A business associate agreement is a contract with required terms. It is not a badge, and HHS does not certify answering services as HIPAA compliant.

Updated August 15, 2026

A business associate agreement (BAA) is a contract. Under the HIPAA Privacy and Security Rules, a covered entity may disclose protected health information (PHI) to a business associate only after it obtains satisfactory assurances, in writing, that the associate will safeguard that information. The U.S. Department of Health and Human Services (HHS) publishes this in its Business Associates guidance, last reviewed July 30, 2026 on the HHS site.

Who counts as a business associate

HHS defines a business associate as a person or organization, other than a workforce member, that creates, receives, maintains, or transmits PHI on behalf of a covered entity, or that provides certain services involving disclosure of PHI. Answering services that take patient names, callback numbers, symptoms, or appointment details typically fall in that bucket. So do many AI intake tools and after-hours nurse lines.

HHS examples that sit close to this market include a vendor that provides patient messaging for a clinic, a cloud provider that stores electronic PHI, and a third-party AI chatbot on a patient portal that uses PHI for symptom assessment or scheduling. An answering service that only transfers a caller without creating or keeping PHI might argue it is a conduit. That exception is narrow. HHS says a conduit only provides transmission, including temporary storage, and does not access PHI on a regular basis.

What the contract has to say

The required terms live at 45 CFR 164.504(e). In plain language, the BAA must:

  • Describe the permitted and required uses and disclosures of PHI.
  • Bar the associate from using or further disclosing PHI except as the BAA allows or as the law requires.
  • Require the associate to follow Privacy Rule duties if it is carrying out a covered entity obligation.
  • Flow the same duties down to subcontractors before PHI is shared with them.

The Security Rule adds more when electronic PHI is involved. The associate must agree to follow applicable Security Rule requirements and to report security incidents, including breaches of unsecured PHI, to the covered entity. HHS publishes sample BAA provisions. Those samples are a starting point for counsel, not a form you should sign unread.

What a BAA does not do

  • It does not certify the vendor. HHS does not run a HIPAA certification program for answering services.
  • It does not replace a security review. A signature on a PDF is not evidence of access controls, training, or call-recording retention.
  • It does not let the vendor use PHI for its own marketing unless the contract and the Privacy Rule allow that use.
  • It does not transfer your duty as a covered entity to choose a vendor carefully and to act if you see a material breach of the BAA.

How ClinicOnCall uses this

When a listing says “vendor states it signs a BAA,” we mean the public site said that on a recorded date, and we stored the URL. We do not review the contract. We do not say the vendor is HIPAA certified. Ask your counsel to read the actual BAA, including subcontractors, call recording, overseas agents, and AI tools that may see the same messages.

All guides