What a BAA is — and why billing vendors always need one

The HIPAA Privacy Rule requires covered entities to have satisfactory assurances that business associates will appropriately safeguard protected health information (PHI) before sharing it. HHS describes the mechanism directly: a covered entity may disclose PHI to a business associate and allow it to create or receive PHI on its behalf only after obtaining those assurances through a written contract — the Business Associate Agreement.

Medical billing companies are the textbook business associate. Claims contain names, dates of service, diagnoses, procedure codes, member numbers and often far more — and all of it is PHI the moment it identifies a patient. A billing vendor without a signed BAA is not a minor paperwork lapse; it is an unpermitted disclosure exposing both parties to enforcement.

“A covered entity may disclose protected health information to a business associate and may allow a business associate to create or receive protected health information on its behalf, if the covered entity obtains satisfactory assurances that the business associate will appropriately safeguard the information.”
— HHS.gov — Business Associates, 45 CFR § 164.502(e)

What a compliant BAA must cover

The specific required terms live in the HIPAA rules, but operationally a serious BAA answers six questions. Read yours against this list before signing:

  • Permitted uses: what the vendor may do with PHI (billing, coding, appeals, analytics) and the explicit prohibition on using it for anything else — including marketing or selling data.
  • Safeguards: the administrative, physical and technical protections the vendor will maintain (encryption, access controls, audit logging).
  • Breach notification: how and how fast the vendor must notify the practice of a breach or suspected breach — a defined clock, not "promptly."
  • Subcontractors: downstream vendors (clearinghouses, offshore staffing, software providers) must be bound by equivalent protections through their own agreements.
  • Individual rights support: the vendor must help the practice respond to patient access requests and amendments touching the records it holds.
  • Return or destruction: what happens to PHI at termination — returned or securely destroyed, with certification.

The questions to ask any billing vendor

Any vendor with a working compliance program will answer these without hesitation — and will produce the documents, not just assurances:

  1. Will you sign our BAA before your team accesses any patient data — not after onboarding?
  2. Is data encrypted in transit and at rest, and with which standards (e.g., TLS 1.3)?
  3. Who on your team will access our PHI, under what role-based permissions, and are those accesses logged?
  4. Do any subcontractors — including offshore staff — touch our data, and are they covered by equivalent agreements?
  5. What is your breach notification procedure, and what is the maximum notification window you commit to?
  6. How do you handle data at engagement termination — return, destruction, and written certification?
  7. Can you describe your minimum-necessary access policy in plain operational terms?

The BAA is the contract; the safeguards are the operations

A signed BAA is necessary but not sufficient. The document commits the vendor to safeguards; the practice should verify the safeguards exist. Role-based access inside the practice's own EHR, for example, means the billing team operates under the practice's permission structure with full audit trail — not through a shared superuser login that makes accountability impossible.

Encryption standards matter the same way: TLS in transit and encryption at rest are baseline expectations for any vendor handling claims, and access logs should be reviewable. These operational questions are where "we take security seriously" either becomes verifiable or doesn't.

Red flags when evaluating a billing vendor

The compliance posture of a billing vendor is visible in its first conversations. Watch for these patterns:

  • No BAA offered until you ask — or vaguely promised "when we get started"
  • Resistance to signing your BAA (using a compliant one is not a burden; refusing is a signal)
  • No subcontractor disclosure — every real billing operation has clearinghouses and sometimes offshore teams; silence means the agreements may not exist
  • Shared logins or "we'll use your front desk credentials" as the access model
  • No written breach procedure, or notification timelines measured in months
  • Data destruction handled by "we'll delete whatever we have" without certification

How EntireRCM handles HIPAA on day one

EntireRCM executes a federal Business Associate Agreement before any data access occurs — Day 1, before onboarding reviews a single claim. Data moves under TLS 1.3 encryption, access is role-based inside your own EHR with logging, subcontractor protections are maintained in writing, and termination procedures return or destroy PHI with certification.

Compliance is not the flashy part of revenue cycle management — it is the part that lets everything else exist. If you are evaluating billing partners (or re-evaluating yours), the questions above are a fast filter. You can also request our compliance documentation alongside the free billing audit; we will send both.

This article is informational and does not constitute legal advice. Final BAA review should involve your own counsel.