Start Free Assessment

Annual BAA Review: Vendor Compliance Audit Guide

HIPAA requires covered entities to have Business Associate Agreements with all vendors that access protected health information.

This comprehensive guide covers annual BAA reviews, vendor security assessment procedures, and how to maintain documented evidence of vendor compliance. Learn how to conduct thorough vendor audits and ensure your third-party relationships remain compliant.

What is a Business Associate Agreement?

A Business Associate Agreement (BAA) is a contract required by HIPAA between a covered entity and any vendor (business associate) that accesses, processes, creates, receives, or maintains protected health information (PHI). The BAA establishes each party's responsibilities for protecting PHI and meeting HIPAA requirements.

Who Needs a BAA: Any third party that has access to PHI, including cloud service providers, IT vendors, billing companies, transcriptionists, legal firms, consultants, and any other vendors that might see patient information.

Required Elements of a HIPAA-Compliant BAA

Permitted Uses of PHI

BAA must specify exactly what uses of PHI are permitted. Business associate may only use PHI for purposes specified by covered entity.

Safeguard Requirements

Business associate must implement safeguards to protect PHI, including administrative, physical, and technical safeguards required by HIPAA Security Rule.

Subcontractor Requirements

If business associate uses subcontractors to process PHI, BAA must require subcontractors to have BAAs meeting same requirements.

Breach Notification

BAA must require business associate to notify covered entity of any breaches of unsecured PHI without unreasonable delay.

Access and Amendment

Business associate must provide access to PHI and assist with patient requests for amendments and restrictions.

Audit and Inspection Rights

BAA must allow covered entity to audit and inspect business associate's facilities, systems, and records to verify compliance.

Return or Destruction

Upon termination, business associate must return or securely destroy all PHI, with documented proof of destruction.

Term and Termination

BAA must specify contract term, termination conditions, and required actions upon termination.

Annual BAA Audit Process

Step-by-Step BAA Review & Vendor Audit

1

Create Vendor Inventory

Compile complete list of all vendors and third parties with PHI access. Include vendor name, contact information, type of services provided, and PHI types accessed.

2

Verify BAAs Are Signed

Confirm executed (signed) BAAs exist for all vendors on list. Any vendor with PHI access without a signed BAA requires immediate attention.

3

Review BAA Content

Examine each BAA to verify all required HIPAA elements are included. Check if BAA reflects current business relationship and services provided.

4

Request Security Documentation

Request security assessments, certifications (SOC 2, ISO 27001), audit reports, and security questionnaire responses from vendors.

5

Conduct Security Assessment

Evaluate vendor security based on documentation provided. Assess encryption, access controls, disaster recovery, incident response, and compliance posture.

6

Document Findings

Create assessment report for each vendor noting compliance status, any gaps identified, and required remediation.

7

Address Deficiencies

For vendors with gaps or non-compliant BAAs, work with vendor to update agreements and address security deficiencies.

8

Document Compliance

Maintain file for each vendor with BAA, assessment results, and documented evidence of compliance. Keep for minimum 6 years.

Vendor Security Assessment Checklist

Annual Assessment Items

Data Encryption: Verify encryption is implemented for PHI in transit (TLS) and at rest (AES-256 or stronger)
Access Controls: Confirm role-based access control, multi-factor authentication, and least privilege principle
Audit Logging: Verify audit logs capture access to PHI and are retained for minimum 6 years
Vulnerability Management: Confirm vendor conducts regular vulnerability assessments and patches systems
Disaster Recovery: Verify backup procedures and disaster recovery testing with documented results
Incident Response: Confirm vendor has incident response plan and breach notification procedures
Staff Training: Verify vendor provides annual HIPAA and security training to staff with access to PHI
Business Continuity: Confirm vendor maintains business continuity plan and service level agreements
Subcontractors: Verify vendor has BAAs with any subcontractors handling PHI
Certifications: Review SOC 2, ISO 27001, or other relevant security certifications
Compliance History: Check for any reported security incidents or compliance violations
Regulatory Changes: Verify vendor is aware of and compliant with new HIPAA requirements

Vendor Risk Classification

Risk Levels & Assessment Frequency

HIGH RISK - Annual Assessment Required

Vendors with direct ePHI access (EHR systems, cloud storage, email), processing large volumes of PHI, or handling sensitive data types. Require detailed security assessments and onsite audits annually or semi-annually.

MEDIUM RISK - Annual Assessment Required

Vendors with indirect PHI access, limited volumes, or handling non-sensitive data. Require comprehensive security questionnaires and documentation review annually.

LOW RISK - Annual Assessment Recommended

Vendors with minimal PHI access or only accessing de-identified data. Simplified assessment annually with focus on BAA compliance and basic security controls.

BAA Amendment & Termination

When to Update or Terminate BAAs

Update BAA When:

  • Services provided by vendor change significantly
  • Vendor systems or security controls are updated
  • Types of PHI accessed change
  • Regulatory requirements change
  • Vendor adds subcontractors to handle PHI
  • BAA language no longer reflects HIPAA requirements

Terminating BAAs & PHI Return

Upon Vendor Termination:

  • Require vendor to return or securely destroy all PHI within specified timeframe (typically 30-60 days)
  • Request written certification that PHI has been destroyed or returned
  • Retain all audit records and assessment documentation
  • Verify no backup copies of PHI remain with vendor
  • Document vendor termination and PHI disposition in compliance file

Frequently Asked Questions

What is a Business Associate Agreement and who needs one?
A Business Associate Agreement (BAA) is a contract required by HIPAA between a covered entity and any vendor (business associate) that accesses, processes, or stores protected health information (PHI). All vendors handling PHI require a BAA, including cloud providers, IT vendors, billing services, and any third party that might access patient data.
What must be included in a HIPAA-compliant BAA?
Required elements include: permitted uses of PHI, safeguard requirements, subcontractor requirements, breach notification procedures, access and amendment rights, audit and inspection rights, term and termination, return/destruction of PHI, and penalties for violations. The BAA must align with HIPAA's requirements for protecting PHI.
How often should you conduct vendor security assessments?
Conduct formal vendor security assessments at least annually. High-risk vendors should be assessed more frequently (semi-annually or quarterly). Assess new vendors before granting PHI access and whenever significant changes occur to the vendor's systems or services.
What should we do if a vendor is not compliant with HIPAA requirements?
Document the specific non-compliance issues and work with the vendor to develop a remediation plan with target dates. Set a reasonable timeframe (typically 30-90 days) for remediation. Monitor progress toward compliance. If vendor cannot achieve compliance, consider finding an alternative vendor or restricting their PHI access.

Streamline Your Vendor Compliance Program

Get BAA templates, vendor assessment tools, and compliance tracking resources.

Get Vendor Compliance Tools