The Analyst Note   Healthcare series · piece 3 of 6 · Last updated July 2026

The BAA that actually protects you.

A Business Associate Agreement allocates liability. It does not make a vendor safe. The regulation fixes a floor of required elements, and every clause that decides where an operator stands after a vendor breach sits above that floor. The vendor's template BAA is written to rest on the minimum. The audit is what moves it.

11 min read · Healthcare series · piece 3 of 6

Questions this article answers

  • Does a signed BAA actually protect us, or just document that we asked?
  • What does the regulation require, and what does it deliberately leave open?
  • How fast does a vendor have to tell us about a breach, and is 60 days really the number?
  • Do we have any right to audit our own vendor, or see who they hand our data to?
  • Who pays for notification, credit monitoring, and forensics after a vendor breach?
  • What do we mark up before signing, clause by clause?

The structural fact about a Business Associate Agreement is that it is a document about who pays when something goes wrong, not a document that stops things from going wrong. Signing one changes the legal posture between an operator and a vendor. It does not change the vendor's firewalls, its patch cadence, or the competence of the subcontractor three layers down that will actually be breached. A mid-market healthcare operator that treats the executed BAA as the moment risk was handled has confused a liability instrument for a safety control. The two are not the same, and the gap between them is exactly where a seven-figure incident lands.

This is the third piece in the Healthcare series. The anchor named two constraints that disqualify vendors before price: the EHR boundary, covered in the previous piece, and the Business Associate Agreement. The BAA is the second constraint, and it is mishandled in a specific way. Operators verify that a BAA exists. They rarely verify what is in it. Because the vendor supplies the template and the template is drafted to the regulatory minimum, the operator who signs without a markup has accepted the vendor's allocation of every risk the regulation left open. That is most of the risk that matters.

A signed BAA is a liability instrument, not a safety guarantee.

The BAA does one thing well and a different thing not at all. What it does well is establish direct liability: under the HIPAA Rules a business associate is itself accountable, subject to civil and in some cases criminal penalties for uses and disclosures its contract does not permit and for failing to safeguard electronic PHI. That accountability is real and it matters. What the BAA does not do is raise the vendor's security posture. No clause encrypts a database. No signature closes an open port. The instrument records obligations and assigns consequences; the engineering that prevents a breach lives entirely outside the paper.

For a buyer this reframes the document's job. The BAA is not the control that keeps PHI safe. It is the mechanism that decides, before anyone knows a breach will happen, who absorbs the cost, who runs the notifications, how fast the operator finds out, and what evidence the operator can demand. Those are negotiated terms. A vendor writing its own template has every incentive to set each of them at the level most favorable to the vendor, which is the regulatory floor, because the floor is defensible and costs the vendor the least. The operator's protection is the distance it negotiates above that floor. Sign the template unaltered and the distance is zero.

The regulation sets a floor of required elements, and the protection lives above it.

45 CFR 164.504(e) enumerates what a BAA must contain, and reading it as a checklist is how operators get lulled. The required elements are the permitted uses and disclosures, a duty not to use or disclose PHI beyond the contract, appropriate safeguards including Security Rule compliance for electronic PHI, reporting of unauthorized uses and of breaches under 45 CFR 164.410, a subcontractor flow-down, making PHI available for access, amendment, and accounting, making internal records available to HHS, and return or destruction of PHI at termination if feasible. A template that recites those ten items is compliant. Compliant is not the same as protective.

The reason is that the regulation states the obligations in their weakest defensible form and leaves the operator-favorable specifics optional. It requires breach reporting but sets only an outer deadline. It requires subcontractor flow-down but does not require the vendor to name the subcontractors. It requires records to be available to the Secretary of HHS but grants the covered entity no audit right of its own. It requires return or destruction at termination, then qualifies it with the phrase "if feasible." Each of those seams is where a template quietly favors the drafter. HHS says as much in its own sample provisions, which repeatedly flag places where "the parties may wish to add additional specificity." The sample is not the ceiling. It is a starting point that the government explicitly invites both sides to negotiate against, and the vendor has usually finished negotiating with itself before the buyer sees the file.

Buyer-side. Supplier-paid. Buyers pay zero. Compensation has zero weight in the Cardinal Index scoring. When we mark up a healthcare vendor's BAA, we are working the clauses that protect the operator, never softening them to suit a supplier. The BAA audit runs before contract signature and independently of how any supplier is compensated. A vendor that resists a reasonable breach-notification window or sub-processor disclosure is telling you something about its operations, and that signal enters the assessment on its own terms.

Sixty days is the outer legal limit, not the notification window you want.

The single clause most worth negotiating is the breach-notification timeline, because the default is far slower than operators assume. 45 CFR 164.410 requires a business associate to notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. Read that literally: a vendor can, without violating the rule, take up to 60 days from the moment it discovers an incident before it tells you. Only when you are notified does your own obligation to notify affected individuals under 45 CFR 164.404 begin, and that carries its own 60-day outer limit. Stacked end to end, the regulatory defaults permit a patient to learn of a breach roughly four months after the vendor first knew.

That is a reputational and regulatory exposure the operator carries, not the vendor. State breach-notification laws often run on shorter clocks than HIPAA, and several trigger from the covered entity's position, so a slow vendor notification can put the operator in default of state law it never breached itself. The buyer-side fix is mechanical and HHS points straight at it: the sample provisions note that the parties may set a stricter timeframe. Replace "no later than 60 days" with a defined short window measured from discovery, commonly 72 hours or five business days, and add a duty to provide a preliminary notice on discovery even before the forensic picture is complete. Define discovery, too, so the vendor cannot argue it never formally "discovered" anything.

The sub-processor question is where concentration risk hides.

The clause operators skip most often is the one the last two years made most important: who sits downstream of your vendor. The regulation requires a business associate to bind its subcontractors to the same restrictions through a flow-down, but it does not require the vendor to tell you who those subcontractors are. A patient-communication platform may run on a cloud transcription service that runs on a shared analytics vendor. Each layer is a business associate of the one above it, and each is a place your data lives. The 2024 Change Healthcare incident, which HHS has tracked as affecting roughly 192.7 million individuals, was a lesson in exactly this geometry: one downstream processor serving a large share of the market turns a single compromise into an industry-wide event.

For a mid-market operator the practical risk is that a breach you had no visibility into becomes your notification obligation and your headline. The buyer-side clause does three things. It requires disclosure of material sub-processors at signing. It requires advance notice, with a right to object, before the vendor adds or changes one. And it requires the vendor to confirm, in writing, that the flow-down obligation is actually executed with each of them, rather than assumed. None of that is granted by the regulation. All of it is standard once the operator asks, and a vendor's refusal to name its downstream processors is itself a finding worth weighing.

Notify — The default is up to 60 days after discovery. First action: replace it with a defined short window (72 hours or five business days) and a duty to give preliminary notice on discovery.
Sub-process — Flow-down is required; disclosure of who is not. First action: require a current list of material sub-processors and advance notice before any change.
Audit — Records go to HHS, not to you, by default. First action: add a right to a current SOC 2 or equivalent attestation on request.
Cost — The regulation is silent on who pays. First action: write indemnification and a duty to fund notification, credit monitoring, and forensics for breaches the vendor causes.

Audit rights, indemnification, and cost allocation are absent unless you add them.

Three of the terms an operator most needs after a breach are the three the regulation never grants, so their absence from a template is not an oversight. The first is a right to evidence. The rule obligates the vendor to open its records to the Secretary of HHS, which does nothing for the operator trying to verify safeguards before an incident. Without a contractual audit right or a standing duty to provide a current third-party attestation such as a SOC 2 Type II, the operator is trusting a claim it cannot check. The second is indemnification. HIPAA does not require a business associate to indemnify a covered entity for a breach it caused, and a template will not volunteer it; whether the vendor makes the operator whole is entirely a matter of what the contract says. The third is cost allocation. Individual notification, credit monitoring, forensic investigation, and call-center support are the real bill after a breach, often the largest line, and the regulation assigns them to no one. Silence defaults them to the covered entity.

These belong together because they are the financial spine of the agreement. An operator can accept a vendor's security posture on evidence, price the residual risk, and cap it, but only if the BAA gives it the right to the evidence, a party to hold responsible, and a defined allocation of the cleanup cost. A template that is silent on all three has not left the questions open for later. It has answered them, in the vendor's favor, by default.

The regulatory floor is about to move, so bind the BAA to the Rules as amended.

The floor itself is not fixed, which is the last reason a minimum-tracking template is a poor place to sit. On January 6, 2025, HHS OCR published a Notice of Proposed Rulemaking to modernize the HIPAA Security Rule, the first major proposed overhaul in over two decades. As proposed, it would remove the long-standing distinction between "required" and "addressable" safeguards, effectively making measures such as encryption of ePHI and multi-factor authentication mandatory, and it would add obligations including regular technical asset inventories, compliance audits, and written verifications from business associates that they have deployed required safeguards. The comment period closed in March 2025 and a final rule is anticipated, though its timing and final scope remain uncertain and it has drawn substantial industry pushback on cost grounds.

For procurement the point is not to predict the final text. It is that a multi-year BAA signed today will very likely outlive the current Security Rule. A contract that pins the vendor's obligations to the rules "as in effect" freezes them at a floor that is scheduled to rise, converting the vendor's future compliance work into a renegotiation the operator has to initiate. HHS's own sample provisions offer the alternative: an optional clause defining a reference to the HIPAA Rules as "the section as in effect or as amended," paired with a duty to amend the agreement as needed for compliance. Include both. It costs nothing at signing and it means the vendor's obligations move up with the standard instead of lagging it.

Audit the BAA against a fixed clause set before you sign.

The decision an operator faces here is concrete: accept the vendor's BAA as presented, or treat it as a first draft to be marked up before signature. The answer is to mark it up, because the presented version is optimized for the party that wrote it. The set below is the BAA audit we run at the front of a healthcare engagement, before signature and independent of the commercial terms. Each item names the regulatory default, then the clause that moves the operator off it. Paste it into your contract review and work it line by line.

Reusable artifact · The nine-clause BAA audit

  1. Breach-notification window. Default: up to 60 days after discovery under 164.410. Move to: a defined short window (72 hours or five business days) plus preliminary notice on discovery, with "discovery" defined.
  2. Sub-processor disclosure. Default: flow-down required, disclosure not. Move to: a current list of material sub-processors and advance notice with a right to object before any change.
  3. Audit and evidence right. Default: records available to HHS only. Move to: a right to a current SOC 2 Type II or equivalent attestation on request, and a defined audit or questionnaire right.
  4. Indemnification. Default: none required. Move to: vendor indemnifies the operator for breaches and violations it causes, with the cap examined against your exposure, not the contract value.
  5. Cost of the incident. Default: silent, so it falls to you. Move to: vendor funds individual notification, credit monitoring, forensics, and call-center support for breaches it causes.
  6. Who notifies whom. Default: unspecified. Move to: state explicitly whether the vendor or the operator sends notifications to individuals, OCR, and the media, and on what timeline.
  7. Return or destruction at termination. Default: "if feasible," which is a loophole. Move to: a defined return-or-destroy obligation, a deadline, certification of destruction, and named treatment of backups.
  8. Rules as amended. Default: obligations pinned to current rules. Move to: reference the HIPAA Rules "as amended" and add a duty to amend the BAA for future compliance, ahead of the Security Rule update.
  9. Safeguard specificity. Default: "appropriate safeguards," undefined. Move to: name the minimum controls you require, such as encryption of ePHI at rest and in transit and MFA on privileged access.

What breaks is the allocation, not the paperwork.

The failure modes here are contractual, and none of them is exotic. The first is the template signed unread, where the operator inherits every default the vendor set and discovers the allocation only when a breach makes it real. The second is the checkbox pass, where a compliance reviewer confirms a BAA exists, checks it against the ten required elements, and never asks what the elements say beyond the minimum. The third is the stale agreement, a BAA executed years ago, pinned to a version of the rules that is moving, and never revisited, so the operator's protection erodes quietly as the standard rises around it. Each is a process failure, not a vendor's fault, and each is preventable by the same discipline: read the agreement as an allocation of risk and negotiate the allocation.

The remedy is not a better vendor. It is refusing to let "we have a signed BAA" stand in for "we know where we stand if this vendor is breached." Those are different sentences, and only the second one survives an incident.

What this means for procurement.

What closes the procurement decision here is a BAA that has been marked up before signature, not merely collected after it. The presence of an agreement is table stakes and proves nothing about the operator's position. The terms above the floor, the notification window, the sub-processor disclosure, the audit right, the indemnity, and the cost allocation, are what determine whether a vendor breach is a managed event or an uncapped liability. The prudent operator runs the nine-clause audit while it still has leverage, which is before signing, and treats a vendor's resistance to reasonable terms as data about the vendor rather than a hurdle to clear.

The category mechanics of the vendors most likely to hold PHI under a BAA, the patient-communication and contact-center platforms, sit in our contact center vendor selection hub, the vertical view is in the Healthcare library, and the security-officer framing of these decisions is in our CISO briefing. The next piece in the series moves from the contract to the wire, and takes up multi-location connectivity: campus versus hub-and-spoke architecture across a healthcare group. The constraint set does not change. The resolution of each constraint is where the work is.

How Cardinal handles a BAA review.

When a buyer engages us on a healthcare technology decision, the BAA is reviewed as a risk-allocation document before the commercial terms are settled, not filed as a formality after. The Cardinal Method runs the nine-clause audit against the vendor's template, marks up the terms that sit on the regulatory floor, and pins the agreement to the HIPAA Rules as amended so the operator's protection tracks the standard rather than lagging it. A vendor's willingness to negotiate the notification window, sub-processor disclosure, and indemnity is recorded as part of the assessment. Only vendors whose contracts leave the operator in a defensible position advance.

See the Cardinal Method →  ·  Healthcare coverage →  ·  Contact center selection →

In short

  • A BAA allocates liability; it does not make a vendor safe. Your protection is the distance you negotiate above the regulatory floor.
  • 45 CFR 164.504(e) lists ten required elements. A template that recites them is compliant, not protective, because the operator-favorable specifics are left optional.
  • Sixty days is the outer limit for breach notification, not a target. Negotiate a defined short window and preliminary notice on discovery.
  • Sub-processor disclosure, audit rights, indemnification, and cost allocation are not granted by the regulation. If they are not written in, they do not exist.
  • The Security Rule floor is proposed to rise. Bind the BAA to the HIPAA Rules "as amended" and run the nine-clause audit before you sign.

This is piece 3 of the Healthcare series. The anchor sets out both dispositive constraints; piece 2 covers EHR integration. The next piece takes up multi-location connectivity architecture.

Sources

  • HHS Office for Civil Rights — "Business Associate Contracts" (sample business associate agreement provisions; required elements; optional stricter breach-notification timeframe) — hhs.gov
  • eCFR — "45 CFR 164.504(e) — Uses and disclosures: Organizational requirements" (business associate contract implementation specifications; subcontractor flow-down; return/destroy "if feasible") — ecfr.gov
  • eCFR — "45 CFR 164.410 — Notification by a business associate" (breach notice without unreasonable delay and no later than 60 calendar days after discovery) — ecfr.gov
  • HHS Office for Civil Rights — "Breach Notification Rule" (covered-entity and business-associate notification obligations) — hhs.gov
  • Federal Register — "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information" (NPRM, January 6, 2025; proposed removal of the required/addressable distinction, mandatory encryption and MFA, business-associate written verifications) — federalregister.gov
  • HHS Office for Civil Rights — "Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information" (reported breaches affecting 500+ individuals; Change Healthcare incident, ~192.7M) — ocrportal.hhs.gov

All linked sources were live at time of publish (July 2026). Verify before quoting in a procurement document.

Want a calibration on your specific stack?

Run the Tier 1 benchmark.

Submit your current UCaaS, CCaaS, SD-WAN, or security contract. We return a benchmark PDF in five business days showing where you are paying above peer median. Free. No follow-up sales drip.

Run the Tier 1 benchmark →