← All posts
Filed in / hipaa · compliance · small-business

HIPAA Business Associate Agreements: Questions for Cloud Vendors

In this piece
  1. 01 When is a vendor a business associate?
  2. 02 Does encryption remove the need for a BAA?
  3. 03 What should the contract address?
  4. 04 Ask which services and organizations are covered
  5. 05 Scope the healthcare evaluation
  6. 06 Make incident reporting usable
  7. 07 Review access and exit before onboarding
  8. 08 Bring the agreement into the healthcare pilot

A business associate agreement should connect the cloud service handling ePHI to clear responsibilities for safeguards, incidents, and access. Before onboarding, establish which services and organizations the agreement covers.

Use the review to connect the contract to the work: which services will handle electronic protected health information (ePHI), which organizations participate, and who takes action when something goes wrong.

When is a vendor a business associate?

A business associate generally performs certain functions or services for a covered entity involving protected health information. Examples include billing, claims processing, and data analysis; a subcontractor handling PHI on behalf of a business associate can also be a business associate. HHS explains the definitions, examples, and exceptions in its business associate guidance.

The role depends on the relationship and information involved, not simply whether a company sells to healthcare customers. Identify what the vendor will do and whether PHI is involved before deciding what agreement is required.

Does encryption remove the need for a BAA?

No, HHS says that a cloud provider maintaining encrypted ePHI is still a business associate even if it cannot decrypt the data. A design that limits operator access can be valuable, but it does not remove the provider’s HIPAA obligations. See HHS guidance on encrypted ePHI and business associate status.

For a cloud service handling ePHI on your behalf, complete the required BAA before that use begins. HHS also makes clear that using a cloud service requires compliance with the applicable HIPAA rules beyond signing the agreement. See its cloud computing guidance.

What should the contract address?

HHS publishes business associate contract guidance and sample provisions. Topics include permitted uses and disclosures, safeguards, reporting obligations, subcontractors, support for individual rights, and return or destruction of PHI at termination where feasible.

Use those provisions with the people responsible for your contracts and compliance program. The operational questions below help expose gaps between a document and the service your staff expects to use.

Ask which services and organizations are covered

Bring a list of the features you plan to enable. Ask the vendor to identify the covered legal entity, product, account, and service scope in writing.

For a collaboration workspace, discuss email, attachments, files and docs, chat, meetings, recordings, backups, and support submissions. Ask whether optional integrations or automated transcription send information to another service. Treat a new connection as a change to the reviewed workflow.

Subcontractor handling is also part of the BAA requirements. HHS describes obligations to ensure that subcontractors handling PHI agree to appropriate restrictions and safeguards in its contract guidance. Ask how the vendor identifies relevant subcontractors and communicates service changes.

Scope the healthcare evaluation

Request a healthcare pilot to review BAA scope against your intended service list. IRONKEEP signs a BAA during onboarding when it creates, receives, maintains, or transmits ePHI for an organization. The healthcare workspace is in private beta.

Make incident reporting usable

A reporting clause needs an operating path. Establish a monitored contact, an escalation method, and who receives follow-up information. Ask what the first report can contain and how updates will be delivered while an investigation continues.

Assign people to recognize suspected incidents, preserve useful evidence, and coordinate the response with the vendor.

Try a fictional tabletop exercise in which a staff member shares a folder with the wrong organization. Identify who removes access, determines the affected files, and coordinates with the recipient. Use synthetic records throughout.

Review access and exit before onboarding

Test an export while evaluating the service. Confirm what is included, whether the format is useful, and how long a larger export might take. Ask about access during an outage or contract dispute and what happens to retained copies when the service ends.

HHS explains that business associates generally may not block a covered entity’s access to PHI they maintain on its behalf, including as a response to a payment dispute. See HHS guidance on access to PHI held by business associates.

Keep the signed agreement, approved service list, contacts, and configuration decisions together. Give the record an owner so a new administrator can tell what was approved and when it needs another review.

Bring the agreement into the healthcare pilot

Bring the intended service list, incident contacts, and export requirements to the pilot discussion. Use the email guide and file sharing guide to turn the contract review into practical acceptance tests.

Healthcare · Private beta

Scope your healthcare workspace.

Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.

Request a healthcare pilot