HIPAA Series: BAAs - Every Vendor Contract You Signed Before 2026 Needs a Second Look
Most covered entities have more business associates than they think.
The billing company makes the list. The EHR vendor does too, usually. But what about the answering service that fields after-hours patient calls? The e-fax platform that converts incoming referrals to email attachments? The cloud backup provider? The IT firm with persistent remote access to your servers? The transcription service that processes your clinical notes? The consultant who implemented your telehealth workflow two years ago and still has a login?
Every one of those relationships is a business associate relationship under HIPAA if the vendor creates, receives, maintains, or transmits protected health information on your behalf. Every one requires a current, compliant business associate agreement (BAA). And every agreement signed before the 2026 Security Rule update - which I’d bet covers most agreements currently in your files - almost certainly doesn't reflect what the proposed rule requires.
Business associates get 240 days total from the final rule's publication to update their agreements - 180 days for the core security requirements, plus an additional 60 days specifically for BAA-language updates. That doesn't mean this project should start last. Most companies have more contracts to review than they realize, and vendor negotiations take time that the calendar won't extend.
What changed
BAAs have been a HIPAA requirement since 2003, when the Privacy Rule first established the covered entity/business associate framework. The 2013 Omnibus Rule updated them significantly - extending direct HIPAA liability to business associates themselves, adding breach notification obligations codified in 45 CFR § 164.410, and tightening language requirements. Entities that updated their agreements in 2013 or 2014 are now twelve years behind.
The 2026 proposed rule requires business associates to implement the same core security controls now required of covered entities: MFA across all systems accessing ePHI, encryption of ePHI at rest and in transit, and documented security risk analysis. A BAA that doesn't specifically require these controls doesn't meet the proposed standard, regardless of how well-drafted it was when signed.
The specific changes the proposed rule introduces to BAA requirements:
Mandatory security control specifications. The general obligation language in most pre-2026 BAAs: "vendor will implement appropriate administrative, physical, and technical safeguards," doesn't satisfy the new standard. The proposed rule requires BAAs to address MFA and encryption specifically, because these are now required controls rather than addressable ones.
Annual written verification. Under the proposed rule, covered entities must obtain written verification from business associates annually that required safeguards are deployed and operating, not just an attestation, but evidence of control deployment comparable to a SOC 2 report or equivalent documentation. Having a signed BAA on file is a compliance floor, not a ceiling. Knowing your vendor is actually compliant requires ongoing verification.
Contingency plan activation notification. The proposed rule introduces a 24-hour notification requirement when a business associate activates its contingency plan. This means when the BA has experienced an event serious enough to trigger its disaster recovery or incident response procedures it notifies the covered entity. Many current agreements have no specific timeline for this type of notification or use vague language that doesn't create an enforceable obligation.
BA-to-covered-entity breach notification. Under existing law, codified at 45 CFR § 164.410, a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery. That clock runs from when the BA knew or should have known about the breach, not from when it decides to tell you. Some vendor agreements try to condition notification on the completion of the BA's internal investigation. That's not how the rule is intended to work, and those clauses will likely need to be removed.
Subcontractor flow-down. If your billing vendor uses a subcontracted clearinghouse that accesses your patients' data, HIPAA requires a BAA between those two parties. The proposed rule adds teeth: your agreement with the primary BA should confirm their subcontractor BAA obligations and require annual verification of subcontractor compliance. Many current agreements are silent on this entirely.
Data disposition on termination. The proposed rule's one-hour workforce access termination requirement, covering employee separations from covered entities, has implications for vendor relationships too. When you terminate a vendor relationship, the agreement should specify the timeline for return or destruction of ePHI and require written certification that it's been completed. Vague language ("vendor will make reasonable efforts to return or destroy data") may not protect you if the vendor's definition of "reasonable" diverges from yours.
The enforcement connection
The April 2026 ransomware settlements - four organizations, $1,165,000 in total penalties, involving Axia Women's Health, Assured Imaging, Consociate Health, and Star Group Health Benefits Plan, affecting over 427,000 individuals - all involved missing or inadequate security controls. OCR's investigation pattern in ransomware cases consistently surfaces BA failures: missing BAAs with vendors who had ePHI access, and BAAs that didn't include enforceable security obligations.
The OCR enforcement theory on BA liability is codified in the HIPAA regulations: covered entities can be held responsible for BA breaches when the covered entity "knew, or by exercising reasonable diligence, should have known" of a pattern of activity or practice by the BA that constituted a material breach of the BA's HIPAA obligations. A stale BAA, a missing BAA, or a BAA with no enforceable security requirements is evidence that reasonable diligence wasn't exercised. The result is shared liability for the BA's failure.
The corrective action plans from recent settlements are explicit: organizations must build formal BA monitoring programs and not just maintain agreements on file, but actively verify and document compliance. This is likely a new or additional duty to heap on stretched privacy programs.
The vendor stack problem
An organization that has been operating for ten years accumulates vendor relationships. A new EHR in 2018. A telehealth platform in 2020. A cloud backup service added as a minor IT decision in 2019. An answering service brought on when call volume increased. Some of these came with BAAs that were signed and filed. Some were added without anyone noting that a BAA was required.
The first step is a complete inventory of every vendor, contractor, and service provider with any access to ePHI. Not just the obvious ones, but all of them.
In practice, this inventory almost always surfaces relationships that either have no BAA or have agreements that are significantly outdated. The billing vendor with a 2015 agreement. The IT support firm that signed something in 2013. The cloud storage provider whose platform terms include a data processing addendum but not a HIPAA-compliant BAA.
Reviewing vendor-drafted BAAs
When you request updated agreements, many vendors will provide their own BAA template rather than accepting yours. Larger vendors such as EHR platforms, cloud providers, and clearinghouses have counsel who have drafted BAAs that favor the vendor's interests. Vendor-drafted doesn't mean non-compliant, but it does mean the agreement warrants careful review.
A few specific provisions to scrutinize:
Security obligation language. The proposed rule requires specific controls: MFA and encryption, not just general "appropriate safeguards" language. If the vendor's template uses general language, ask for specific commitments or add them by amendment.
Breach notification timelines. 45 CFR § 164.410 sets a 60-day maximum for BA-to-covered-entity notification. Some vendor agreements extend this window or condition notification on the BA completing its own investigation. HHS holds that your patients' breach notification clock runs from discovery, not from when your vendor decides it's ready to tell you. Don't negotiate away notification speed.
Limitation of liability. Mirroring service agreements, vendor-drafted BAAs often cap the vendor's financial liability for security incidents, sometimes to the value of the preceding month's fees. If a vendor breach exposes ten thousand patient records and the liability cap is $500, that's your problem, not theirs. These clauses are negotiable, especially with smaller vendors. If you can’t agree, maybe go silent and argue the amount later…just don’t sell yourself short by agreeing to a low number.
Data disposition on termination. The agreement should specify that ePHI will be returned or destroyed within a defined timeframe after the relationship ends, and that the vendor will provide written certification. Vague language ("vendor will make reasonable efforts") doesn't protect you if the vendor's definition of those efforts diverges from yours after the relationship sours.
Annual verification: the most onerous new standard most organizations aren't ready for
The most operationally significant change in the proposed rule's BA requirements is annual verification. Having a signed BAA has always been the starting point. Under the proposed rule, it's no longer enough.
Covered entities are expected to verify annually that their business associates have actually deployed required controls: MFA, encryption, documented risk analysis. The verification should be documented and specific: not "vendor attested to compliance" but "vendor provided SOC 2 Type II report dated X confirming MFA and encryption deployment across systems accessing our ePHI."
For smaller entities with a manageable vendor list, this is a defined annual project. For larger organizations with hundreds of BA relationships, it's a substantial ongoing function comparable in structure to how financial services firms manage vendor risk and it will require dedicated resources to execute correctly.
The mechanisms for verification are still developing as the rule finalizes, but the expected standard is something like a current SOC 2 Type II report, a completed security questionnaire with supporting documentation, or audit evidence of specific control deployment. Document what verification was obtained from whom and when.
Getting through the project
Build the vendor inventory first. Every vendor with ePHI access goes on the list: cloud backup, answering service, fax platform, IT support, billing company, transcription service, all of them.
Map existing agreements to vendors. For each vendor, identify whether a BAA exists, when it was signed, and what it says about security obligations. This is your gap analysis.
Prioritize by risk. Vendors with broad ePHI access like EHR vendors, billing companies, IT support firms, move to the top. Smaller vendors with limited access can follow.
Send update requests. For most vendors, a BAA update is a straightforward exchange: you send a revised agreement or amendment, they sign it. Some vendors have intake processes so start those early.
Build the verification workflow now. Decide how you'll obtain and store annual verification evidence before the compliance deadline arrives, not after.
This project isn't technically complex, but it is administratively large. Starting now means finishing before the deadline. Starting in the fall means a sprint that increases the risk of missed agreements and inadequate documentation.
That's the series. Four requirements, one compliance clock, and OCR already enforcing the underlying standards before the final rule has even published. The companies that treat this as an operational project will get there. Start now, work systematically, document everything and you’ll succeed. The organizations waiting for the final text before beginning will be under pressure when it arrives. Don’t do that.
If you want a structured compliance review of your BA agreements and vendor stack, schedule a consult @ https://jharrisadvisory.com/contact.
For the full picture — proposed changes, readiness plan, and toolkit — see our HIPAA Security Rule NPRM guide