Somewhere in your medical group’s business office, there’s a folder of Business Associate Agreements. Chances are, nobody remembers negotiating any of them. Somebody pulled the vendor’s template, somebody else redlined a definition or two, and the deal moved on to the “real” agreement, the part everyone actually cared about: price, terms, exclusivity, who gets to walk away and when.
The trap in that approach is that the document your organization treats as an afterthought is frequently the one that decides who absorbs the loss when something big goes wrong.
Think of the BAA the way you’d think of a prenuptial agreement. Nobody signs a prenup because they expect the marriage to fail. They sign it because if it does, they’d like the terms set in advance, by two people who still like each other, rather than later, by two who don’t. A BAA works the same way: signed while the vendor relationship is all promise and no incident, its value realized at the one moment nobody’s thinking about it, after something has already gone wrong.
Most medical group leaders never get that far in their thinking. They know HIPAA requires a BAA whenever a vendor touches protected health information, so they get one, almost any one, usually the vendor’s own template, because it’s “free.” Compliance box checked, deal done.
But HIPAA is clear about why a BAA has to exist and has almost nothing to say about what a good one looks like. It won’t tell you who pays when a vendor’s system gets breached, who’s in charge of the response, or who decides, at 4:45 on a Friday afternoon, whether what just happened is reportable. It won’t tell you whether the vendor can use data derived from your patients to train a product it then sells to your competitor down the street.
Those aren’t regulatory questions. They’re business questions, and the BAA, not the statute, is the only document positioned to answer them.
Every contract of consequence is, underneath the business terms, a risk allocation document. Your BAA is no exception, except the risk it allocates is one of the more expensive categories your organization will face: forensic investigation, patient notification, credit monitoring, regulatory scrutiny, the plaintiffs’ bar, and reputational damage. The BAA should say, item by item, who pays. Instead, most simply recite that the vendor will “comply with HIPAA” and stop there.
The next time someone says, “we just need to attach the BAA,” stop them. Read it twice: once as it is, once as though something has already gone wrong. It might be the most important contract your group signs all year.
Mark F. Weiss, JD, is an attorney specializing in the business and legal issues affecting physician groups and healthcare facilities on a national basis, practicing at The Mark F. Weiss Law Firm, with offices in Dallas, Texas and Los Angeles and Santa Barbara, California. He can be reached by email at markweiss@weisspc.com.


