Curogram Blog

What Is a BAA? Medical Practice Guide (2026)

Written by Jo Galvez | 7/24/26 11:00 PM
💡 A BAA, or business associate agreement, is the written contract HIPAA requires before your practice hands patient data to an outside vendor. It sets what that vendor may do with protected health information, which safeguards it has to run, how fast it must report a breach, and what happens to your records when the contract ends.

Federal rules list the required elements at 45 CFR 164.504(e), and OCR has fined practices for the missing paperwork alone. A seven-clinic pediatric group in Illinois paid $31,000 in 2017 after sending records for 10,728 patients to a storage vendor with no signed agreement on file. Texting platforms need one because they store message history rather than simply passing it along. Get the BAA executed before the first patient text goes out.


Most practice owners meet the BAA the same way. A vendor emails a PDF during onboarding, somebody signs it, and it lands in a folder nobody opens again. That habit is where the trouble usually starts.

A business associate agreement is the contract that makes an outside company legally answerable for the patient data you hand it. Without one on file, every phone number, appointment time, or chart you pass along counts as an improper disclosure under HIPAA. How good that vendor's security happens to be has no bearing on it. The missing signature is the violation.

We spend our days inside front desks and billing queues, and this question surfaces in the same spot every time. Someone wants to start texting patients. The office manager asks whether the tool is HIPAA compliant. Nobody can produce a signed agreement, and half the time the vendor doesn't have one to give, because the product was built for salons and pizza shops.

Our position is plain. A BAA is the cheapest piece of compliance work your practice will do all year, and it is the first document OCR asks for when something goes wrong. It also protects almost nothing on its own. You still need patient consent, encrypted channels for anything clinical, and staff who know which details belong in a text.

What follows is the business associate agreement explained without the legal wrapper: the five parts federal rules require, why texting vendors sit inside the definition, and the questions worth asking before anyone signs.

What Is a BAA? Business Associate Agreement, Defined

Two parties sign a BAA. Your practice, which HIPAA calls a covered entity, and the vendor, which HIPAA calls a business associate. Every clause after that describes what the second party owes the first.

The Two Parties and the Written Promise

Under 45 CFR 164.502(e), you cannot disclose protected health information to an outside company until you hold satisfactory assurances in writing that the company will safeguard it. A BAA is that writing. Nothing substitutes for it. A vendor's security page, a SOC 2 report, and a confidentiality clause buried in the master service agreement all fail the requirement on their own.

Who needs one? Your EHR host, billing company, answering service, transcription vendor, shredding company, cloud backup provider, and any patient texting platform. If a company touches patient data to perform work for you, it is in scope.

Your bank and your malpractice carrier usually sit outside, since they act for themselves rather than on your behalf.

Who Counts as a Business Associate

HIPAA's definition turns on four verbs. A business associate creates, receives, maintains, or transmits PHI on behalf of a covered entity. That third verb arrived with the 2013 Omnibus Rule, and one word pulled cloud hosts, storage firms, and messaging platforms into scope.

Some relationships fall outside. When you send records to a reference lab for a patient's treatment, HHS says no BAA is needed, because the lab acts as a provider rather than as your contractor. A courier carrying a sealed chart sits outside too.

What decides the question is whether the company performs regulated work for you and needs patient data to do it. How sensitive the data feels has nothing to do with the answer.

Why the Practice Pays When the Paperwork Is Missing

Business associates have been directly liable to OCR since the 2013 Omnibus Rule put HITECH into effect. Your practice stays on the hook anyway.

The Center for Children's Digestive Health, a seven-clinic pediatric group in Illinois, found that out in 2017. Starting in 2003, it sent inactive patient records to a storage vendor called FileFax. Records belonging to 10,728 people moved over twelve years. Neither company could produce a signed BAA dated earlier than October 12, 2015.

FileFax was the party that left charts in an unlocked dumpster. The practice paid $31,000 to OCR and accepted a two-year corrective action plan for the absent agreement.

What On File Actually Means

An executed BAA carries two signatures and a date that precedes the first disclosure of PHI. OCR asked CCDH for exactly that and got nothing usable.

Keep the signed copy for six years past the date the agreement ends, which is what 45 CFR 164.530(j) requires of HIPAA documentation. Store it somewhere your office manager can reach in under a minute, not in a sales rep's email thread.

Practices we work with keep one vendor table: company name, service provided, BAA signed date, renewal date, and the person who owns the relationship. When a vendor gets acquired, that table tells you which agreements need a fresh look.


What a BAA Must Contain

Federal rules spell out the required elements at 45 CFR 164.504(e), and HHS publishes sample provisions you can hold a vendor's draft against. Five pieces do most of the work.

Required element

What it obligates the vendor to do

What to check in the draft

Permitted uses

Use PHI only for the services you named

Any right to reuse data for product or ad purposes

Safeguards

Follow the administrative, physical, and technical controls in Subpart C

Current SOC 2 Type II report and last risk analysis date

Breach notification

Report breaches of unsecured PHI to your practice

A window shorter than the 60-day outer limit

Subcontractor flow-down

Bind its own subcontractors to the same terms

A written list of subprocessors and where they host data

Termination

Return or destroy PHI once the contract ends

Export format plus a deletion deadline counted in days


Permitted Uses and Disclosures

This clause states what the vendor may do with your patient data and nothing beyond it. Read it slowly.

Watch for language granting rights to use data for product development, analytics, or advertising. Some platforms reserve the right to retain de-identified or aggregated data forever. That may well be legal. You still want to know before signing, because de-identification standards vary and your patients never picked that vendor.

Ask for the clause to name the actual services: appointment reminders, two-way messaging, digital forms, payment requests. A broad grant covering any purpose related to the services leaves you nothing to enforce later.

Safeguards You Can Actually Verify

The agreement has to commit the vendor to the administrative, physical, and technical safeguards in Subpart C of 45 CFR Part 164. Every vendor will sign that sentence. Fewer can show their work.

Request the current SOC 2 Type II report under NDA. Ask when the last HIPAA risk analysis was completed and who performed it. Confirm whether data is encrypted at rest and in transit, and who holds the keys.

A vendor that cannot name the month of its most recent risk analysis probably has not run one lately. Curogram carries SOC 2 Type II certification alongside HIPAA compliance, and we expect prospective clients to ask for the documentation during evaluation.

Breach Notification and the Clock You Inherit

When a vendor discovers a breach of unsecured PHI, it owes you a report. Under 45 CFR 164.410, that report is due without unreasonable delay and no later than 60 calendar days from discovery.

Sixty days is a ceiling, and it happens to be your ceiling too. You owe affected patients notice within 60 days of discovery under 164.404. A vendor that uses its full window leaves you zero days to work with.

Negotiate something tighter. Five business days is a fair ask of any software vendor with real logging in place. Put the number in the BAA rather than in a reassuring sales email.

Subcontractor Flow-Down

Your texting platform does not deliver messages by itself. An SMS aggregator carries the traffic. A cloud provider hosts the database. A voice or transcription service may handle overflow calls.

Each of those companies is a subcontractor, and 45 CFR 164.504(e)(1)(iii) requires your vendor to hold BAAs with every one of them. Protection has to run the full length of the chain.

Ask for the list in writing. A vendor that cannot name its own subprocessors has not mapped where your patient data ends up.

Termination and Getting Your Data Back

Contracts end. Vendors get acquired. Your BAA should say what happens to PHI on the way out.

Standard language requires the vendor to return or destroy all PHI, and to keep protecting anything it cannot feasibly return. Push for specifics: export format, days until deletion, whether backups are covered, and written confirmation once it is finished.

The phrase upon request appears in most drafts with no deadline attached. Replace it with a number of days. 

Does My Texting Vendor Need a BAA?

Yes, in nearly every case. The argument against it leans on something called the conduit exception, and that rule is far narrower than vendors tend to suggest.

What the Conduit Exception Actually Covers

HHS drew the line in the preamble to the 2013 Omnibus Rule at 78 FR 5571-72. A conduit moves data and does nothing else, with access described as transient rather than persistent. The Postal Service, private couriers, and internet service providers passing traffic are the examples HHS gives.

Storage breaks the exception. Once a company retains your data beyond the moment of delivery, the carve-out stops applying, and HHS said the same about cloud providers in its cloud computing guidance.

Electronic fax companies argued conduit status for years and lost, since faxes sit in archives. Texting platforms occupy the same position.

Where a Texting Platform Stores Your Patient Data

Open your texting tool and look at what fills the screen. Message threads running back months. Patient names paired with mobile numbers.

Appointment times pulled from your EHR sit there too, alongside delivery receipts and read logs.

All of that is maintained PHI, held by a vendor on your behalf. That places the company inside the business associate definition, so BAA requirements for HIPAA texting apply from the first message you send.

Delivery carriers are a separate matter. A common carrier moving the SMS packet may well qualify as a conduit, which is why your platform vendor's agreement matters more than the carrier's.

A Twenty-Minute Check on Any Vendor

Five steps, running in order, will settle the question for almost any product on your shortlist.

1. Search the vendor's site for a business associate agreement. A dedicated page or a link inside the terms is a good sign. A HIPAA blog post with no agreement anywhere has answered you.

2. Ask sales to email the BAA before the demo call ends. Track how long it takes to arrive. Vendors with a real program send it the same day.

3. Read the permitted uses clause first. Any grant reaching beyond the services you named goes straight onto your questions list.

4. Ask where message history lives and how long it stays there. If threads sit in the vendor's dashboard, that vendor maintains PHI.

5. Confirm who countersigns. A template you signed and emailed into a support queue is not executed until it comes back with their signature on it.

Why Consumer Messaging Apps Stay Off the Table

Consumer texting apps and general business SMS tools built for restaurants, salons, and retail run no BAA program at all. Their terms of service usually prohibit regulated data outright. A company that never built for healthcare has no agreement to hand you.

Personal phones create the same gap in a smaller package. Staff texting patients from their own numbers leaves no audit trail, no retention control, and no way to recover a thread once that person resigns.

It happens on the Monday the office line backs up. Three patients need rescheduling, the phone keeps ringing, and someone at the front desk reaches for the fastest tool within arm's length. That is the moment a compliance program either holds or does not.

What Our BAA Covers, and What Stays With You

Vendors talk about compliance in the abstract. It is more useful to see where one platform draws its lines, so here is how ours works.

What We Sign, and When

Curogram is a business associate. We execute a BAA with every client before onboarding begins, alongside a PHI acknowledgment that spells out how the platform is meant to be used. Our platform holds SOC 2 Type II certification and operates under HIPAA.

We connect with any EMR and run as an add-on to it, a complement to your system of record rather than a replacement for it. Your charts stay where they are. We handle the messaging layer on top.

Two channels exist inside the product. Standard SMS carries reminders and general notices. Secure messaging carries anything clinical, and the patient verifies identity before the content opens.

The Line Between Plain SMS and the Secure Channel

Our client agreement is direct about a limit worth understanding. Standard SMS is not encrypted, so PHI does not belong in it. The examples below come straight from the acknowledgment every client signs.

Message type

Fine over standard SMS

Belongs in Secure Messaging

Appointment reminder

Hi John, you have an appointment on January 25 at 2 PM. Reply YES to confirm.

The specialty, the condition, or the treating physician

Test result

You have a secure message from XYZ Family Practice. Click the link to verify your identity.

The actual result value

Balance due

You have a balance due of $50. Click the link to see details and pay.

The treatment the balance is for

Prescription

Your prescription is ready for pickup at your pharmacy.

Drug name and dosage


Your EMR Vendor's BAA Does Not Cover Ours

This trips up more practices than any other point on the page. You already signed a BAA with your EHR company. That agreement binds the EHR company to you, and it stops there.

Every vendor touching patient data needs its own signed agreement with your practice. Add a texting platform on top of eClinicalWorks or Athenahealth and you now hold two BAAs, one with each company. The EHR's paperwork extends to its own subcontractors, never to a tool you bolted on afterward.

Direction of data flow matters here as well. Our sync pulls appointment and demographic data one way, from your EMR into Curogram. Nothing writes back into the chart. Your compliance officer will ask which system holds the authoritative record, and the answer stays your EHR.

What Stays Your Responsibility

A BAA covers our conduct as your vendor. Four duties stay on your side of the line, and our client agreement names each one.

Train staff and patients on proper platform use. Restrict access to authorized personnel only. Keep data entry accurate so clinical details never drift into an unsecured field. Leave the default SMS templates alone rather than editing PHI into them.

Post the disclaimer where patients will read it. Add a line to every outbound template telling patients not to reply by text with health information. Patients will answer a reminder with a full symptom list if nobody warns them. Consent sits on your side too, and patient consent and TCPA rules cover ground a BAA never touches.

None of this takes a compliance department. It takes a fifteen-minute staff huddle, a laminated card at the front desk, and an office manager who spot-checks sent messages once a month.

Compliant Reminders Still Perform

Practices sometimes assume the safe version of texting works worse. Our numbers say otherwise.

Across current clients, appointment confirmation rates average above 75%. No-show rates run 53% below the industry average. Atlas Medical Center cut no-shows from 14.20% to 4.91% inside three months, based on our internal data.

None of those messages carried PHI over standard SMS. A date, a time, a reply keyword: that was the entire payload.

Covina Arthritic Clinic tells a similar story on the volume side, moving from 369 confirmations a month to more than 1,300 after automating the process. Staff stopped dialing patients one at a time. The message wording stayed inside the same compliant boundary the whole way through.

Five Questions to Ask Before Signing a BAA With Software Vendors

Compliance officers get thirty minutes with a vendor, if that. These five questions surface most of what matters, and the hesitation you hear tells you as much as the answers.

1. Will You Sign a BAA Before We Send Any Patient Data?

Timing carries more weight than the answer itself. CCDH's agreement existed. It carried a date twelve years after records started moving, which is precisely why OCR opened a compliance review rather than accepting the paperwork.

A vendor that says yes but wants to start the EHR sync first is asking you to accept that same exposure. Get the executed copy back before the integration turns on. Sales teams can move faster on this than they admit when a deal is close.

Watch for a second pattern too. Some vendors will send the BAA promptly and then take six weeks to counter-sign it. Until their signature lands, you are running an unexecuted agreement, which is what OCR found at CCDH.

2. Who Are Your Subcontractors, and Do They Hold BAAs With You?

Ask for the list in writing. For a texting platform, expect an SMS aggregator, a cloud host, and possibly a voice or transcription provider.

Then ask where those companies store data. A subprocessor operating outside the United States changes your risk analysis, and in a handful of states it changes your obligations too.

Ask how you find out when the list changes. Vendors swap infrastructure providers without telling anyone, and a BAA that requires written notice of new subprocessors gives you a chance to review before your data moves.

3. How Quickly Will You Tell Us About a Breach?

Sixty days is the regulation's ceiling. Ask the vendor to commit to five business days in writing, and get the escalation contact named in the agreement rather than left to a support queue.

Settle who drafts the patient notification and who pays for mailing and credit monitoring. That conversation goes much better before signing than during an incident.

One more detail people skip: ask what the vendor's report will actually contain. A useful notice names the affected patients, the data elements exposed, and the time window. A one-line email saying an incident occurred leaves your privacy officer with nothing to file.

4. What Happens to Our Data if We Cancel?

Ask for the export format, the deletion timeline in days, and whether backups fall inside the deletion. Request written confirmation once it is done.

Practices switching platforms routinely discover their old vendor still holds three years of message history nobody thought to ask about.

Set the expectation while you still have negotiating room. During the sales cycle, a vendor will commit to a 30-day deletion window and a CSV export of message threads. After you cancel, that same request drops to the bottom of a support queue.

5. When Was Your Last Risk Analysis?

A vendor should name the month without checking a file. Reports older than twelve months are stale, and a risk analysis is a Security Rule requirement under 45 CFR 164.308(a)(1).

Pair that with a request for the SOC 2 Type II report under NDA, and read the exceptions section rather than the cover letter. Auditors list the controls that failed testing, and that page is where a vendor's real posture shows up.

Run all five past any candidate and you have a working BAA checklist a medical practice can reuse for the next vendor, plus a starting point for a broader HIPAA texting compliance checklist.

 

Conclusion: Get the Agreement Signed Before the First Text Goes Out

A BAA costs a signature and an afternoon of careful reading. The gap cost one seven-clinic practice $31,000 and a two-year corrective action plan, with no breach of its own systems involved.

That gap is worth naming plainly, because practices tend to budget for security software and forget the contracts entirely. A firewall does not close this exposure. A signature does.

Pull your vendor list this week. Find the texting tool, the billing service, the backup provider, the answering service, and the shredding company. Mark which agreements you can produce with signatures and dates on them. Whatever you cannot produce is your work queue, and it is usually shorter than people fear.

Rank what you find by how much data each vendor holds. A shredding company with quarterly pickups and a texting platform storing eighteen months of patient threads carry different weight, though both need the same signature. Start with the ones holding the most.

For texting specifically, the question settles quickly. A platform that keeps message history is maintaining PHI on your behalf, so it needs a BAA. Any vendor without one to give has already answered your compliance question. That single test will clear or disqualify most of a shortlist in an afternoon, and it applies just as cleanly to the rest of your HIPAA-compliant patient texting stack.

Curogram signs a BAA before onboarding, runs on SOC 2 Type II controls, and connects with any EMR your practice already uses. Book a demo, and we will walk through the agreement itself.



Frequently Asked Questions