A signed BAA is not the same as a compliant BAA. Most practices collect signatures and file the document without ever reading it carefully. When OCR investigates a breach, the BAA is one of the first things they request — and deficient agreements can shift liability in ways the practice never anticipated.
Here are the five problems that appear most frequently.
A privacy policy is not a BAA. Terms of service are not a BAA. A checkbox in an onboarding form is not a BAA. Under 45 CFR §164.504(e), a BAA must be a separately executed written contract with specific required elements. Any vendor who claims their privacy policy satisfies the BAA requirement is either uninformed or hoping you are.
A compliant BAA must describe permitted uses and disclosures of PHI with specificity. Vague language like "uses necessary to provide services" without enumeration gives the vendor room to use patient data in ways you never intended — including training AI models. If the permitted uses are not specific, the agreement doesn't meet the standard and your patients' data may be at risk in ways you haven't authorized.
The HIPAA Breach Notification Rule requires business associates to notify covered entities of discovered breaches "without unreasonable delay and in no case later than 60 days." Your BAA must include a breach reporting obligation. Many vendor-provided agreements omit this entirely or specify longer timelines that contradict the rule. An agreement that gives the vendor 90 days to notify you of a breach is non-compliant on its face.
If your business associate uses subcontractors who access PHI on their behalf — cloud storage vendors, third-party processors, AI platform providers — those subcontractors are also Business Associates under HIPAA. Your BAA must require your vendor to obtain compliant BAAs with their own subcontractors. Without this chain of accountability, a breach at a subcontractor level creates exposure all the way back to your practice.
When a vendor relationship ends, what happens to your patients' data? A compliant BAA must include a provision requiring the vendor to return or destroy PHI upon termination of the agreement — or document why return or destruction is infeasible. Without this clause, patient data may sit in a vendor's systems indefinitely after you've switched providers, with no obligation on their part to protect or delete it.
AI tool vendors present new BAA risks that traditional agreements weren't written to address: model training on client data, data residency in shared cloud infrastructure, retention policies tied to AI improvement programs. If your BAA was written before your practice started using AI tools, it almost certainly needs to be updated or replaced.
What to do next
Pull every BAA your practice has signed in the last three years. For each one, confirm: it's a separate signed agreement (not a policy reference), it specifies permitted uses, it includes breach notification timelines, it covers subcontractors, and it addresses termination.
Flag any that fail more than one of those checks. Those vendors need either a corrected agreement or a frank conversation about whether the relationship continues.
If you're adding any new vendor — especially an AI tool — the BAA review should happen before the contract is signed, not after data is flowing.