September 20, 2026

See Our Blogs

Explore insights on SEO, AI, and digital marketing strategies designed to help your business grow, stay visible, and adapt in a constantly evolving online landscape.

Beacon_Icon_resouse

A business associate agreement is a written contract between a HIPAA covered entity and a vendor that will create, receive, maintain, or transmit protected health information on its behalf. A behavioral health practice needs one with any vendor whose systems will touch patient information, and the agreement has to be in place before that information is shared rather than after.

Who counts as a business associate?

Any outside party handling protected health information as part of a service provided to the practice.

In behavioral health this commonly includes electronic health record vendors, CRM and marketing automation platforms, billing services, call answering and scheduling services, transcription tools, cloud storage providers, IT support with access to systems containing patient data, and marketing agencies with access to those systems.

The category is defined by function rather than by industry. A vendor that never intended to be in healthcare is still a business associate if the practice sends it protected health information.

What has to be in the agreement?

HIPAA regulations specify required provisions. The agreement must describe the permitted uses and disclosures of protected health information, require safeguards to prevent unauthorized use, require the business associate to report breaches and security incidents to the practice, require that subcontractors be bound by equivalent terms, and address the return or destruction of information when the relationship ends.

Most vendors that offer agreements provide a standard form containing these provisions. Practices should have counsel review it rather than assume a standard form covers their specific use.

When is one not required?

When no protected health information is involved, and when a vendor qualifies as a conduit.

The conduit exception is narrow. It covers entities that transmit information without accessing it other than incidentally, such as a postal service or a telecommunications carrier. Software vendors that store information generally do not qualify, because storage involves persistent access.

Practices sometimes assume that a vendor which technically could avoid seeing patient information does not need an agreement. The standard is whether the vendor’s systems can access the information, not whether anyone has looked at it.

What happens without one?

Sharing protected health information with a vendor that has not signed an agreement is an impermissible disclosure under the Privacy Rule, whether or not any information is ever exposed. The obligation and the liability sit with the practice, not with the vendor that was never asked.

What should a practice do first?

Inventory the vendors that currently touch patient information, then confirm which have signed agreements. Practices running this exercise for the first time usually find at least one vendor nobody thought of.

More on what a system should do once the agreement is in place is in What Should a Behavioral Health CRM Actually Do?

This article is general information and is not legal advice.