BAA & HIPAA Security Checklist: What to Require From a Billing Vendor

BAA & HIPAA Security Checklist: What to Require From a Billing Vendor — illustration

Any vendor that touches your protected health information (PHI) — including a billing company — is a business associate under HIPAA, and the relationship needs a business associate agreement (BAA) plus real safeguards behind it. This checklist covers what the BAA should address and the security controls worth verifying before you share data. It’s educational guidance, not legal advice: have your own counsel review any BAA before signing.

A note on us: MBSG handles client data under HIPAA safeguards and a business associate agreement. We don’t publish program specifics as marketing claims — the controls below are what we recommend you verify in any vendor, including us. For how we approach data protection generally, see HIPAA and security. To discuss our practices directly, contact us.

The BAA checklist

1. Parties and scope defined. The agreement identifies both parties and precisely what PHI the vendor will access, use, or disclose — and for what purposes. Vague scope (“all data as needed”) is a red flag.

2. Permitted uses and disclosures limited. The BAA restricts the vendor to using PHI only as necessary to perform the contracted services, plus HIPAA-permitted exceptions that are explicitly named. Marketing uses, sale of PHI, and unrelated analytics should be expressly off the table.

3. Safeguard obligations stated. The vendor commits to administrative, physical, and technical safeguards appropriate to the PHI involved — not just a generic promise to “comply with HIPAA.”

4. Subcontractor flow-down. If the vendor uses subcontractors that touch PHI, the BAA requires equivalent written agreements with each of them. Your PHI shouldn’t travel downstream without the same protections.

5. Breach notification terms. Clear obligations: the vendor notifies you of breaches and security incidents within defined timeframes, with the information you need to meet your own notification duties. Know the clock before you need it.

6. Individual-rights support. The vendor agrees to support your HIPAA obligations to individuals — access requests, amendment requests, and accounting of disclosures — for PHI it holds.

7. Return or destruction at termination. When the relationship ends, PHI is returned to you or destroyed (with certification), except where retention is legally required. Define what happens to backups and archives too.

8. Audit and oversight rights. You retain the right to verify compliance — through assessments, questionnaires, or audit provisions. A BAA with no verification mechanism is a promise without evidence.

9. Termination for violation. Material breach of the BAA’s privacy and security terms gives you termination rights. This is standard and should be present.

The safeguards checklist

Beyond the paper, verify the actual controls:

Access control. Role-based access — staff see only the PHI their job requires. Unique user accounts (no shared logins), strong authentication, and prompt deprovisioning when staff leave or change roles.

Encryption. PHI encrypted in transit and at rest. Ask specifically — “we use secure systems” is not an answer.

Workforce training. Regular HIPAA and security training for everyone who touches PHI, with records. Training should cover phishing and social engineering, not just policy recitation.

Minimum necessary discipline. Workflows designed so staff encounter the minimum PHI needed for the task — billing staff don’t need full clinical narratives to post a payment.

Incident response. A written incident response plan with named roles, tested periodically. Ask when it was last tested, not just whether it exists.

Physical safeguards. Controls on facilities and workstations where PHI is accessed — relevant even (especially) for remote workforces: screen locks, secure networks, device management.

Business continuity. Backup and recovery procedures that protect PHI availability — because a ransomware event that destroys billing data is both a security incident and a revenue catastrophe.

Marketing-data separation. PHI stays out of marketing systems: no patient data in email marketing tools, analytics, or general CRMs. Ask where the boundary is and how it’s enforced.

Red flags

  • Reluctance to sign a BAA, or pressure to use the vendor’s one-sided template without negotiation.
  • “We’re HIPAA certified” — there is no official HIPAA certification; look for actual controls instead.
  • No named security contact or incident process.
  • Shared logins, or inability to describe access controls specifically.
  • PHI in systems that don’t need it (marketing CRMs, unsecured email, personal devices).

FAQs

Does every billing vendor need a BAA?
If they create, receive, maintain, or transmit PHI on your behalf — yes. A billing company that only ever saw de-identified data wouldn’t, but real billing work involves PHI. Get the BAA signed before data flows, not after.

What should we do before sharing data with a new billing partner?
Sign the BAA, verify the safeguards above (at least via a security questionnaire and discussion), confirm the data-transfer method is encrypted, and define exactly what data the vendor needs — minimum necessary applies to onboarding too.

Can we use our own BAA template?
You can propose it; vendors often negotiate toward mutual language. What matters is that the final agreement covers the checklist items above. Have counsel review it either way.

How do we verify safeguards without an on-site audit?
Security questionnaires, evidence requests (training records, incident response test dates, encryption standards), and contractual audit rights. For higher-risk relationships, independent assessments exist — scope them to what matters.

What happens to our data if we leave the vendor?
That’s the return-or-destruction clause: PHI comes back to you or is destroyed with certification, on a defined timeline. Settle this in the BAA before signing, not during an exit.

Does a BAA cover our own HIPAA obligations?
No — the BAA governs the vendor relationship. Your practice retains its own HIPAA duties: risk analysis, policies, training, and patient-facing obligations. A vendor’s BAA doesn’t transfer your compliance.

Get a Free Billing Audit — revenue-focused, but we’re happy to walk through our data-handling practices on the same call. Or contact us at +1 (307) 396-4107 or contact@medicalbillingservicesgroup.com. MBSG works remotely with practices in all 50 states.

This page is general educational information, not legal advice. HIPAA obligations depend on your specific circumstances — consult qualified counsel. Last reviewed 2026-10-08.

Leave a Comment