Annual BAA Review: Vendor Compliance Audit Guide
HIPAA requires covered entities to have Business Associate Agreements with all vendors that access protected health information.
This comprehensive guide covers annual BAA reviews, vendor security assessment procedures, and how to maintain documented evidence of vendor compliance. Learn how to conduct thorough vendor audits and ensure your third-party relationships remain compliant.
What is a Business Associate Agreement?
A Business Associate Agreement (BAA) is a contract required by HIPAA between a covered entity and any vendor (business associate) that accesses, processes, creates, receives, or maintains protected health information (PHI). The BAA establishes each party's responsibilities for protecting PHI and meeting HIPAA requirements.
Who Needs a BAA: Any third party that has access to PHI, including cloud service providers, IT vendors, billing companies, transcriptionists, legal firms, consultants, and any other vendors that might see patient information.
Required Elements of a HIPAA-Compliant BAA
Permitted Uses of PHI
BAA must specify exactly what uses of PHI are permitted. Business associate may only use PHI for purposes specified by covered entity.
Safeguard Requirements
Business associate must implement safeguards to protect PHI, including administrative, physical, and technical safeguards required by HIPAA Security Rule.
Subcontractor Requirements
If business associate uses subcontractors to process PHI, BAA must require subcontractors to have BAAs meeting same requirements.
Breach Notification
BAA must require business associate to notify covered entity of any breaches of unsecured PHI without unreasonable delay.
Access and Amendment
Business associate must provide access to PHI and assist with patient requests for amendments and restrictions.
Audit and Inspection Rights
BAA must allow covered entity to audit and inspect business associate's facilities, systems, and records to verify compliance.
Return or Destruction
Upon termination, business associate must return or securely destroy all PHI, with documented proof of destruction.
Term and Termination
BAA must specify contract term, termination conditions, and required actions upon termination.
Annual BAA Audit Process
Step-by-Step BAA Review & Vendor Audit
Create Vendor Inventory
Compile complete list of all vendors and third parties with PHI access. Include vendor name, contact information, type of services provided, and PHI types accessed.
Verify BAAs Are Signed
Confirm executed (signed) BAAs exist for all vendors on list. Any vendor with PHI access without a signed BAA requires immediate attention.
Review BAA Content
Examine each BAA to verify all required HIPAA elements are included. Check if BAA reflects current business relationship and services provided.
Request Security Documentation
Request security assessments, certifications (SOC 2, ISO 27001), audit reports, and security questionnaire responses from vendors.
Conduct Security Assessment
Evaluate vendor security based on documentation provided. Assess encryption, access controls, disaster recovery, incident response, and compliance posture.
Document Findings
Create assessment report for each vendor noting compliance status, any gaps identified, and required remediation.
Address Deficiencies
For vendors with gaps or non-compliant BAAs, work with vendor to update agreements and address security deficiencies.
Document Compliance
Maintain file for each vendor with BAA, assessment results, and documented evidence of compliance. Keep for minimum 6 years.
Vendor Security Assessment Checklist
Annual Assessment Items
Vendor Risk Classification
Risk Levels & Assessment Frequency
HIGH RISK - Annual Assessment Required
Vendors with direct ePHI access (EHR systems, cloud storage, email), processing large volumes of PHI, or handling sensitive data types. Require detailed security assessments and onsite audits annually or semi-annually.
MEDIUM RISK - Annual Assessment Required
Vendors with indirect PHI access, limited volumes, or handling non-sensitive data. Require comprehensive security questionnaires and documentation review annually.
LOW RISK - Annual Assessment Recommended
Vendors with minimal PHI access or only accessing de-identified data. Simplified assessment annually with focus on BAA compliance and basic security controls.
BAA Amendment & Termination
When to Update or Terminate BAAs
Update BAA When:
- Services provided by vendor change significantly
- Vendor systems or security controls are updated
- Types of PHI accessed change
- Regulatory requirements change
- Vendor adds subcontractors to handle PHI
- BAA language no longer reflects HIPAA requirements
Terminating BAAs & PHI Return
Upon Vendor Termination:
- Require vendor to return or securely destroy all PHI within specified timeframe (typically 30-60 days)
- Request written certification that PHI has been destroyed or returned
- Retain all audit records and assessment documentation
- Verify no backup copies of PHI remain with vendor
- Document vendor termination and PHI disposition in compliance file
Frequently Asked Questions
What is a Business Associate Agreement and who needs one?
What must be included in a HIPAA-compliant BAA?
How often should you conduct vendor security assessments?
What should we do if a vendor is not compliant with HIPAA requirements?
Streamline Your Vendor Compliance Program
Get BAA templates, vendor assessment tools, and compliance tracking resources.
Get Vendor Compliance Tools