
Yes. If your IT company creates, receives, maintains or transmits patient information for your practice, it is a HIPAA business associate, and you need a business associate agreement for HIPAA compliance before it touches that data (45 CFR 164.502(e) and 164.504(e)). That usually includes a managed IT provider, because it runs the servers, backups and email where PHI lives.
This is general information, not legal advice. We read the rules on the eCFR and in the Federal Register in September 2026; HHS’s guidance pages at hhs.gov refused our automated requests, so we cite the regulations directly. Our HIPAA compliance service for medical and dental practices covers the safeguards we build; this post covers the contract that comes first.
What is a HIPAA business associate?
45 CFR 160.103 defines a business associate as a person or company that, on behalf of a covered entity, creates, receives, maintains or transmits protected health information for a regulated function such as billing, claims processing or practice management, or that provides legal, accounting, consulting, management, administrative or similar services involving PHI. A subcontractor that handles PHI for a business associate is one too.
The exception vendors hope for is narrow. In the 2013 Omnibus Rule, HHS called the conduit exception “a narrow one,” limited to courier-style transmission such as the Postal Service or an internet service provider, and said a company that maintains PHI is a business associate “even if the entity does not actually view” it (78 FR 5572). By that reasoning, a backup vendor storing your encrypted data still maintains PHI.
| Vendor | Business associate? | Why |
|---|---|---|
| Managed IT provider with admin access | Usually yes | Its access reaches the systems that store ePHI |
| Cloud email and file storage | Yes | It stores PHI; Microsoft and Google offer standard BAAs |
| Offsite or cloud backup service | Yes | Maintaining PHI counts even without viewing it |
| Billing company | Yes | Billing and claims work are named in the definition |
| Internet service provider | No | Mere data transmission is a conduit |
| Another provider treating the patient | No | Disclosures for treatment are excluded |
Which rule made business associates directly liable?
The HITECH Act of 2009 created direct liability, and HHS wrote it into the regulations with the 2013 Omnibus Rule (78 FR 5566), which made business associates “directly liable for compliance with certain of the HIPAA Privacy and Security Rules’ requirements” and brought subcontractors into the definition. The BAA did not become optional: the practice still has to obtain one before sharing PHI.
What must a business associate agreement include?
45 CFR 164.504(e)(2) and 164.314(a) set the minimum terms. The agreement must:
- state the permitted and required uses and disclosures of PHI, and bar any others except as required by law;
- require appropriate safeguards and Security Rule compliance for electronic PHI;
- require reports of any use or disclosure the contract does not allow, breaches of unsecured PHI, and security incidents;
- make subcontractors that handle the PHI agree to the same restrictions;
- support patients’ rights to access, amendment and an accounting of disclosures;
- follow the Privacy Rule for any of the practice’s obligations the vendor carries out;
- open the vendor’s books and records on PHI to HHS;
- return or destroy the PHI at the end, or extend its protections if that is not feasible;
- let the practice terminate if the vendor violates a material term.
Microsoft and Google offer standard agreements instead of signing yours: Microsoft says it cannot use a customer’s BAA, and Google offers its amendment for acceptance in the Admin console (both checked September 2026). Check theirs against this list; our summaries of Microsoft’s HIPAA BAA and Google Workspace’s BAA terms cover both.
Does my IT company need to sign a BAA?
If it can reach your patient data, plan on yes. Typical triggers: administering the Microsoft 365 or Google Workspace tenant that holds clinical email, managing the server or cloud storage behind your practice management system, running backups, and remote support on workstations that hold PHI. Ask which of its own vendors, such as backup or remote monitoring platforms, touch your data, and whether it holds a BAA with each. We sign business associate agreements, and our HIPAA work keeps a vendor and BAA register current as systems change.
What happens if a vendor will not sign a BAA?
Then it cannot handle your PHI. Under 45 CFR 164.502(e) and 164.308(b), you may let a business associate create, receive, maintain or transmit PHI only after getting satisfactory assurances documented in a written agreement. Choose a vendor that will sign, or restructure the work so the vendor never receives PHI, for example by giving it properly de-identified data.
If PHI already went to a vendor without an agreement, treat it as a possible impermissible disclosure. Under 45 CFR 164.402 it is presumed to be a breach unless a documented risk assessment shows a low probability of compromise, so bring in counsel early. If a signed vendor shows a pattern of material violations, the practice must take reasonable steps to cure it and, failing that, terminate where feasible (164.504(e)(1)(ii)).
A proposed yearly check on vendors
HHS’s January 2025 Security Rule proposal (90 FR 898) would require written verification, at least every 12 months, that each business associate has deployed the required technical safeguards, certified by someone authorized to act for the vendor. It was still a proposed rule in September 2026, but the question is fair to ask vendors now.
Where NetSys fits
A HIPAA compliance audit compares your BAA register with the vendors that actually touch PHI. We support medical practices and dental offices from one office in Brooklyn, on site in our published coverage areas and remotely elsewhere. In our multi-site medical practice case study, the next compliance review returned 0 findings on its infrastructure portion.
Frequently asked questions
Are business associates exempt from HIPAA compliance requirements?
No. Since the 2013 Omnibus Rule, business associates are directly liable for compliance with parts of the Privacy and Security Rules, including the Security Rule’s safeguards for electronic PHI. They must also notify the covered entity of breaches of unsecured PHI without unreasonable delay and within 60 calendar days of discovery (45 CFR 164.410).
Is an NDA enough instead of a BAA?
No. A BAA has required terms set by 45 CFR 164.504(e) and 164.314(a), including breach and security incident reporting, subcontractor flow-down, support for patient access, HHS access to records, and return or destruction of PHI at the end. Unless an NDA contains every one of those terms, it does not document the assurances HIPAA requires.
How long should a practice keep its BAAs?
Keep each one for at least six years. The Security Rule requires documentation, including the written contracts that record a business associate’s assurances, to be kept for six years from the date it was created or last in effect, whichever is later (45 CFR 164.316(b)(2)(i)). Keep each vendor’s current version too.
Does a BAA with our IT company cover its subcontractors?
No, each link needs its own agreement. Your BAA binds your IT company, and HIPAA then requires the IT company to obtain written satisfactory assurances from any subcontractor that creates, receives, maintains or transmits your PHI on its behalf (45 CFR 164.502(e)(1)(ii) and 164.504(e)(5)). Ask your provider for that list.
Do AI vendors need a BAA too?
Yes, whenever staff send them PHI. An AI chatbot or transcription tool that receives patient details is maintaining or transmitting PHI for you. Several vendors offer BAAs only on specific business plans, so the plan matters as much as the vendor. Our comparison of which AI tools sign a BAA lists them.
Sources (checked September 2026)
- 45 CFR 160.103, definition of business associate, checked September 2026.
- 45 CFR 164.502(e) and 45 CFR 164.504(e), required contract terms, checked September 2026.
- 45 CFR 164.314(a) and 45 CFR 164.316, Security Rule terms and documentation, checked September 2026.
- 45 CFR 164.402 and 45 CFR 164.410, breaches and vendor notice, checked September 2026.
- Omnibus Rule, 78 FR 5566, conduits at 78 FR 5572, checked September 2026.
- Security Rule proposed rule, 90 FR 898, checked September 2026.
- Microsoft HIPAA and HITECH Act offering, checked September 2026.
- Google Workspace BAA acceptance steps, checked September 2026.
Related reading
ComplianceIs Google Workspace HIPAA Compliant? BAA, Plans and Setup
Read Article
ComplianceMicrosoft 365 HIPAA Compliance: The BAA, Copilot and Required Settings
Read Article
FAQIT for Home Care Agencies: 11 Questions Owners Ask
Read ArticleAlso on this topic: Managed IT for Medical and Dental Practices in 2026 · vCISO vs CISO: What Mid-Sized Companies Need
Discuss hipaa compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
