← Back to Resources

BAA Tracker: What to Collect, When to Renew, and What Happens If You Don't

Missing or expired Business Associate Agreements are one of the top causes of HIPAA enforcement actions. This guide covers exactly who needs a BAA, what it must contain, and how to build a renewal programme that holds up under audit.

BAA RENEWAL TRACKERMTWTFSS12345678910111213141516171819202122232425262728293031

What is a Business Associate Agreement?

A Business Associate Agreement (BAA) is a legally binding contract required by HIPAA whenever a covered entity — a healthcare provider, health plan, or healthcare clearinghouse — shares Protected Health Information (PHI) with an external party that performs services on its behalf.

The BAA establishes that the receiving party (the "business associate") understands its obligations under HIPAA, will implement appropriate safeguards, and will report any security incidents or breaches. Without a valid BAA, sharing ePHI with any third party is a HIPAA violation — regardless of whether a breach occurs.

Which vendors require a BAA?

EHR / Clinical Software Vendors
Axxess, Epic, Cerner, PointClickCare
Cloud Storage and Backup Providers
AWS, Azure, Google Cloud (when storing ePHI)
Medical Billing and Coding Companies
Any third-party billing service with ePHI access
IT Service Providers
Managed service providers with access to your systems
Transcription Services
Clinical documentation vendors processing visit notes
Data Analytics Firms
Any vendor running analytics on patient-identifiable data
Legal and Accounting Firms
Only when ePHI access is required for the engagement

Seven provisions every BAA must include under 45 CFR §164.504(e).

  • 01Permitted uses and disclosures of ePHI are clearly defined
  • 02Business associate will not use or disclose ePHI beyond what is permitted
  • 03Appropriate safeguards will be implemented to prevent unauthorized use or disclosure
  • 04Any subcontractors who receive ePHI will be bound by the same obligations
  • 05ePHI will be available for amendment if required by the individual
  • 06Breaches and security incidents will be reported to the covered entity
  • 07On termination, ePHI will be returned, destroyed, or continued safeguards documented

What happens when a BAA is missing or expired.

Tiered Civil Penalty
$100 – $50,000 per violation

OCR can assess up to $1.9M per violation category per calendar year under the Penalty Tiers.

Criminal Liability
Up to 10 years imprisonment

Knowingly obtaining or disclosing ePHI without authorisation — including through a non-executed BAA — can result in criminal charges.

Breach Notification
Required within 60 days

If a BA discloses ePHI without a valid BAA, it may constitute a breach requiring notification to individuals, HHS, and potentially media.

State Penalties
Varies by state

Many states have added their own healthcare privacy laws with separate penalty structures that run concurrently with HIPAA enforcement.

Protexa BAA Management

Protexa's AI engine continuously monitors your BAA inventory for upcoming expirations, flags vendors where an agreement is missing, and surfaces anomalies between your approved vendor list and your active ePHI flows — each with a direct remediation action. No more renewal tracking in spreadsheets.

Track every BAA.
Automatically.

Protexa monitors your entire vendor inventory for BAA status, expiry dates, and coverage gaps — so your compliance posture never depends on a spreadsheet.

See BAA Tracking in Action← Back to Resources