What does a BAA actually commit your vendor to?
Short answer: three things. That they will safeguard your patients’ information and use it only for the work you hired them for, that they will tell you if they have a breach, and that they will hold their own subcontractors to the same obligations.
I am Scott Derby, I am an attorney. Most psychologists and mental health therapists have signed business associate agreements with their vendors, and most filed them without reading them. Here is what that document actually does.
A BAA is a promise, in writing, from a vendor who touches your patients’ information. When your email provider, your billing service or your notes software handles data that could identify a patient, HIPAA treats them as your business associate. The BAA is where they commit to protecting that data the way you have to.
What it promises comes down to three things worth knowing.
They will safeguard the information and use it only for the services you hired them for, and nothing else.
They will tell you if they have a breach, so that you are not the last person to find out about something that happened to your patients’ data.
They carry the same obligations down to their own subcontractors, which matters more than it sounds, because your vendor almost certainly uses vendors of their own.
One thing to check before you sign anyone’s version. Look for what happens to your data when the relationship ends. A good BAA says the vendor returns or destroys your information when you leave. If that language is missing, ask about it.
A BAA is not paperwork. It is your patients’ protection, in writing.
This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.