Business associate agreements are the paperwork everyone assumes is handled and almost no one has actually handled. We see it constantly: a company sails through product diligence, then an enterprise buyer’s counsel asks for the BAA inventory — and the deal goes quiet for six weeks while someone reconstructs which vendors touch PHI and discovers that half the agreements were never signed.
The same gaps surface in OCR investigations. After a breach at a vendor, the first question is “show us the BAA,” and “we thought we had one” has been the expensive answer in multiple enforcement settlements over the years.
This post covers the seven BAA mistakes that actually surface in audits and deals — not theoretical drafting nits, but the failures that stall revenue and generate findings. First, thirty seconds of grounding.
What a BAA is and when it’s required
A business associate is any entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity — or on behalf of another business associate. Before PHI flows to such a vendor, HIPAA requires a written contract with specific mandatory provisions (45 CFR §164.504(e) spells out the required terms; §164.308(b) and §164.502(e) establish the obligation).
The required contents include: permitted uses and disclosures, a commitment to appropriate safeguards, breach and security incident reporting to the upstream party, subcontractor flow-down, support for individual rights (access, amendment, accounting of disclosures), availability of records to HHS, and return or destruction of PHI at termination.
Two boundary cases people get wrong in both directions. “Mere conduits” — entities that only transport data without accessing it, like the postal service or a pure network carrier — don’t need BAAs. But cloud service providers storing PHI do need BAAs even if the data is encrypted and they never view it; HHS guidance has been explicit about that for years. When in doubt, the test is whether the vendor persistently handles PHI on your behalf, not whether they look at it.
Now, the seven mistakes.
Mistake 1: No BAA at all with a vendor that handles PHI
The most common failure is the simplest: PHI flows to a vendor and no BAA exists. This usually isn’t recklessness — it’s drift. Someone in ops adopts a transcription tool. Engineering wires up an error-tracking service that captures request payloads. Support starts using a new helpdesk platform. Nobody thought of any of these as “PHI vendors,” and nobody owns the question.
Why it hurts: disclosing PHI to a vendor without a BAA is an impermissible disclosure by itself — no breach required. And if that vendor is breached, you have the worst possible fact pattern: an incident plus a missing agreement, which is exactly the combination that has produced enforcement settlements.
The fix is a process, not a document: maintain a PHI data map (every system and vendor touching PHI), and gate new vendor onboarding with one question — “will this touch PHI?” — routed to whoever owns compliance. Your risk analysis inventory (see our step-by-step guide) and your BAA tracker should reconcile perfectly; when they don’t, one of them is wrong.
Mistake 2: The BAA that was drafted but never signed
Almost as common, and more embarrassing: the BAA exists as an email attachment, a redline, or a DocuSign envelope that expired unsigned. Everyone proceeded as if it were done. Years later, diligence counsel asks for executed copies, and “executed” turns out to be a strong word.
An unsigned BAA gives you approximately nothing. You can’t enforce its breach-notification terms against the vendor, and from a regulator’s view, no satisfactory assurance was ever obtained.
The fix: track BAAs to full execution — countersigned copy in hand, filed in a system of record with the date and the signatory’s authority. Do a one-time audit now: for every vendor on your PHI map, can you produce the executed PDF in under five minutes? Deals literally move at the speed of that answer. Our HIPAA templates include a vendor tracking sheet built for exactly this.
Mistake 3: No subcontractor flow-down
Since the 2013 Omnibus Rule, subcontractors of business associates are themselves business associates, and the flow-down obligation runs down the chain: the covered entity gets a BAA from its business associate, and that business associate must get BAAs from its own subcontractors that handle PHI.
Where this bites: you’re a health tech company (a business associate) using a cloud host, an email provider, an analytics processor, and an offshore development shop with production access. Each of those handling PHI needs a BAA from you. Your customer’s BAA with you does not cover them, and your customer has no relationship with them at all.
In diligence, sophisticated buyers now ask directly: “List your subcontractors that access PHI and confirm BAAs are in place with each.” A blank stare at that question reads as “we haven’t mapped our own supply chain,” which is usually accurate.
The fix: inventory your downstream chain, sign BAAs with each PHI-handling subcontractor, and add a contractual requirement that they do the same with theirs. Also check whether your upstream BAAs require you to disclose or get approval for subcontractors — many do, and silently adding a new processor can put you in breach of contract even when HIPAA itself is satisfied.
Mistake 4: Signing the vendor’s BAA without reading what it disclaims
Big platforms offer standard, sometimes click-through BAAs. Signing them is fine — expected, even. Not reading them is the mistake, because the most important part of a platform BAA is usually its scope limitations:
- Covered services lists. Cloud BAAs typically apply only to enumerated services. Use a service outside the list with PHI and you’re outside the BAA entirely, no matter what you signed.
- Configuration conditions. Many BAAs require you to use the services in specified configurations — encryption enabled, certain features disabled. The agreement assumes a shared-responsibility split; the BAA doesn’t make a misconfigured bucket compliant.
- Feature carve-outs. AI features, human review programs, and beta features are frequently excluded or governed by separate terms.
The fix: for each platform BAA, extract three facts into your tracker — which services are covered, what configuration is required, and what’s excluded. Then verify your actual usage matches. The number of teams running PHI through a non-covered service of a provider they “have a BAA with” is larger than anyone would like.
Mistake 5: Treating the BAA as due diligence
A BAA is a legal instrument, not a security assessment. It obligates the vendor to safeguard PHI; it doesn’t verify they can. The Security Rule’s “satisfactory assurances” language is about the contract, but your own risk analysis obligation (§164.308(a)(1)) extends to risks your vendors introduce — and enforcement patterns show OCR probing whether organizations understood their vendors’ security posture, not just their paperwork.
The commercial version of this mistake: assuming a signed BAA ends the conversation with your enterprise customer. Their questionnaire will still ask how you vet vendors, and “we get BAAs” without any assessment behind it is a scored-down answer.
The fix: right-size vendor diligence to risk. For a vendor holding your entire PHI database, review their independent audit reports, ask about encryption, access control, and breach history, and revisit annually. For a low-volume peripheral tool, a short questionnaire may suffice. Document whatever you do — the documentation is the point.
Mistake 6: Breach clauses that don’t work under pressure
BAA breach-notification terms get negotiated by people who will never handle an incident, and it shows. The problems surface at the worst possible time:
- No timeline, or vague ones. HIPAA requires business associates to notify the covered entity “without unreasonable delay” and within 60 days of discovery — but the covered entity’s own 60-day clock to notify individuals runs from its discovery, which effectively includes its business associate’s. A BAA that lets a vendor sit on an incident for 60 days can consume your entire notification window. Well-drafted agreements specify short vendor-notification periods (commonly measured in days, not weeks).
- No content requirements. You need affected individuals, data elements, and incident details to make notification decisions. If the BAA doesn’t require them, expect a fight while the clock runs.
- Mismatched chains. If you’re a business associate in the middle, your downstream BAAs must give you time to meet your upstream obligations. A 10-day upstream commitment with 30-day downstream terms is a trap you signed yourself.
The fix: read your breach clauses as if the incident is happening today, align timelines across your chain, and rehearse the workflow. Our HIPAA checklist covers the breach-response sequence end to end.
Mistake 7: The zombie BAA — outdated, expired, or orphaned
BAAs age badly when no one owns them:
- Pre-Omnibus relics. Agreements predating 2013 that lack subcontractor flow-down and breach-notification terms required by current rules.
- Terminated relationships with unreturned PHI. The vendor is gone, the agreement required return or destruction of PHI at termination, and nobody executed that clause. Their backups still hold your patients’ data.
- Scope drift. The BAA describes a narrow integration from 2021; the relationship now involves entirely different data flows nobody papered.
- Acquisitions. Your vendor was acquired; who’s the counterparty now, and did the agreement survive assignment?
The fix: an annual BAA review pass. Confirm each agreement matches the current relationship, chase termination obligations for offboarded vendors (and get written destruction certifications), and refresh anything drafted under pre-2013 assumptions.
How to clean this up in 30 days
- Week 1: Build or refresh the PHI vendor map. Reconcile it against your accounts-payable list — payments surface vendors your compliance docs forgot.
- Week 2: Locate executed BAAs for every mapped vendor. Sort into signed, unsigned, missing, and outdated.
- Week 3: Close gaps. Send agreements for missing/unsigned; for vendors that won’t sign, cut off PHI or replace them. Map your subcontractor chain and fix flow-down.
- Week 4: Read the fine print on platform BAAs (covered services, configurations), align breach timelines, and stand up the tracker with an owner and an annual review date.
One caution as you do this: no vendor and no consultant can make you “HIPAA certified” — HHS operates no certification program, and a certificate logo on a BAA vendor’s site is marketing, not law. What holds up in audits and deals is an executed-BAA inventory, a documented vendor-diligence process, and an independent assessment when you need outside validation.
If you want help pressure-testing yours, our HIPAA gap assessment includes a full BAA and vendor-chain review, or start with the free HIPAA readiness assessment to see how your current posture scores. Questions about a specific vendor situation? Book a 20-minute call — BAA chain questions are genuinely our favorite kind.