A Missing Signature Cost One Health System $4.3 Million

In 2016, Advocate Health Care Network agreed to pay $5.55 million to settle multiple HIPAA violations with the Office for Civil Rights. Among the findings: the organization had failed to obtain satisfactory business associate agreements from several entities handling protected health information on its behalf. No signed form. No documented safeguards. Just exposure — millions of patients' worth of it.

If you think a business associate agreement form is just a formality, I'd encourage you to reconsider. In my experience consulting with covered entities of all sizes, the BAA is the single most neglected document in HIPAA compliance programs. And it's one of the most dangerous gaps OCR looks for during an investigation.

This post breaks down exactly what your business associate agreement form must contain, the mistakes I see most often, and how to keep your organization out of OCR's enforcement crosshairs in 2026.

What Is a Business Associate Agreement Form?

A business associate agreement form is a legally required contract between a covered entity — like a hospital, health plan, or provider — and any business associate that creates, receives, maintains, or transmits PHI on the covered entity's behalf. Think billing companies, IT vendors, shredding services, cloud storage providers, even answering services.

The HIPAA Privacy Rule and the HIPAA Security Rule both require this agreement to be in place before any PHI changes hands. The 2013 Omnibus Rule expanded the scope dramatically, making business associates directly liable for compliance and extending requirements to subcontractors.

Without a signed BAA, even routine data sharing becomes a potential HIPAA violation.

The requirement for BAAs comes directly from 45 CFR § 164.502(e) and § 164.504(e). HHS has published guidance and even sample business associate agreement provisions to help organizations get started. If you haven't reviewed those provisions recently, bookmark that page today.

But here's the thing I tell every client: the HHS sample provisions are a floor, not a ceiling. Your actual agreement needs to reflect the specific relationship, the specific data flows, and the specific risks involved.

9 Elements Every Business Associate Agreement Form Must Include

Over the years I've reviewed hundreds of BAAs. The ones that hold up under scrutiny — and under OCR investigation — consistently include these elements:

  • Permitted uses and disclosures of PHI. Spell out exactly what the business associate can and cannot do with the data.
  • A prohibition on unauthorized use or disclosure. This must go beyond boilerplate. Be specific.
  • Safeguards requirement. The BA must implement administrative, physical, and technical safeguards to protect ePHI.
  • Breach notification obligations. The BA must report any breach of unsecured PHI to the covered entity within a defined timeframe — typically 60 days under HIPAA, though many agreements tighten this to 10 or 15 days.
  • Subcontractor flow-down provisions. If the BA uses subcontractors who access PHI, those subcontractors need their own BAAs.
  • Access to PHI for the individual. The agreement must ensure individuals can exercise their right to access their own records.
  • Amendment provisions. The BA must make PHI available for amendments when required.
  • Accounting of disclosures. The BA must make information available for the covered entity to fulfill its disclosure accounting obligations.
  • Termination clauses. What happens to the PHI when the contract ends? Return it, destroy it, or — if neither is feasible — extend protections indefinitely.

Miss even one of these, and your business associate agreement form has a gap that OCR can — and will — exploit.

The $2.3 Million Mistake: Raleigh Orthopaedic Clinic

In 2016, Raleigh Orthopaedic Clinic, P.A. paid $750,000 to settle with OCR after it handed over x-rays containing PHI to a third party that was not a business associate and did so without a BAA in place. The practice had essentially given a vendor access to patient data without any contractual protections.

I've seen this exact pattern repeat itself dozens of times in smaller practices. A new vendor starts handling appointment reminders or managing cloud backups, and nobody in the office thinks to ask: do we have a BAA with these people?

Your organization needs a process — not just a form — to catch every vendor relationship that touches PHI.

Common BAA Mistakes I See Every Month

1. Using a Generic Template Without Customization

I get it. You downloaded a business associate agreement form from the internet, had both parties sign it, and filed it away. The problem? Generic templates rarely account for your specific data flows, your specific subcontractor chains, or state-level privacy laws that may layer additional requirements on top of HIPAA.

2. Forgetting About Subcontractors

Since the Omnibus Rule, subcontractors of business associates are also considered business associates. That means your IT vendor's cloud hosting provider needs a BAA too. I've audited organizations that had a solid agreement with their primary vendor but zero documentation downstream. That's a violation waiting to happen.

3. No Process for Tracking and Renewing BAAs

BAAs aren't set-and-forget documents. Vendor relationships evolve. Services change. Data flows expand. If your BAA doesn't reflect the current reality of how PHI is being handled, it's functionally useless. I recommend reviewing every BAA annually — at minimum.

4. Failing to Train Your Workforce on What a BAA Means

Here's what happens in practice: a department manager signs up for a new SaaS tool that processes patient information. Nobody in compliance knows about it. No BAA is executed. The breach happens six months later.

Your workforce — from front-desk staff to community health workers to department heads — needs to understand that any vendor touching PHI requires a signed agreement. Programs like our HIPAA Training for Community Health Workers cover these concepts in practical, role-specific terms that actually stick.

Who Counts as a Business Associate in 2026?

The list keeps growing. Here are vendor types I routinely flag during compliance assessments:

  • EHR and health IT vendors
  • Medical billing and coding companies
  • Cloud storage and hosting providers
  • Answering and call center services
  • Shredding and document destruction companies
  • Consultants who access PHI (yes, even temporarily)
  • Health information exchanges
  • Revenue cycle management firms
  • Patient engagement platforms and telehealth vendors

If a vendor creates, receives, maintains, or transmits PHI on your behalf, they're a business associate. Period. HHS provides a detailed explanation of business associate relationships on its business associates guidance page.

How to Build a BAA Process That Actually Works

A signed business associate agreement form is necessary, but it's not sufficient. You need a system. Here's the framework I use with clients:

Step 1: Inventory Every Vendor Relationship

Start with accounts payable. Pull every vendor your organization has paid in the last 12 months. For each one, ask: does this vendor have any access to PHI or ePHI? If yes, they need a BAA.

Step 2: Standardize Your Agreement Template (Then Customize)

Build a base template that includes all nine required elements listed above. Then customize the permitted uses, breach notification timelines, and termination provisions for each vendor relationship.

Step 3: Assign Ownership

Someone in your organization — typically a privacy officer or compliance lead — must own the BAA tracker. They should know the status of every agreement: executed, pending, expired, or under review.

Step 4: Train Every Hiring Manager and Department Lead

Anyone who can engage a new vendor needs to understand the BAA requirement. This is where workforce training from HIPAACertify makes a measurable difference. When people understand the why, they're far more likely to follow the process.

Step 5: Audit Annually

Every year, compare your active vendor list against your BAA inventory. Look for gaps. I guarantee you'll find at least one.

What Happens If You Don't Have a Business Associate Agreement Form?

OCR doesn't need a breach to cite you for a missing BAA. During compliance reviews and complaint investigations, the absence of a signed business associate agreement is often one of the first findings. Penalties range from $100 to $50,000 per violation under the HIPAA penalty tiers, with calendar-year caps that can reach $2,067,813 per violation category.

But the financial penalty is only part of the damage. A corrective action plan from OCR typically requires two to three years of external monitoring. That's expensive, disruptive, and embarrassing.

And if a breach occurs involving a vendor with no BAA? You've lost any contractual leverage to compel the vendor's cooperation with the breach notification process. You're exposed legally, financially, and reputationally — all because of a missing piece of paper.

Your BAA Checklist for 2026

Before you close this tab, ask yourself these questions:

  • Do I have a signed BAA with every vendor that touches PHI?
  • Does each agreement include all nine required provisions?
  • Have I reviewed and updated these agreements in the last 12 months?
  • Does my workforce know not to engage new vendors without a BAA?
  • Do my business associates have BAAs with their subcontractors?

If you answered "no" or "I'm not sure" to any of these, you have work to do. The good news: this is fixable. The bad news: OCR won't give you credit for meaning to get around to it.

A business associate agreement form is one of HIPAA's most concrete, enforceable requirements. Get it right, and you've eliminated one of the most common sources of compliance failures. Get it wrong, and you've handed OCR exactly the evidence it needs.