Does Your IT Company Need a BAA? (Almost Certainly Yes)
Does an IT provider count as a business associate?
Yes, in almost all cases. HIPAA defines a business associate as anyone who creates, receives, maintains or transmits protected health information on your behalf. An IT provider who administers your server, holds your backups, or has remote access to a workstation running your EHR maintains PHI — even if they never open a chart.
It comes up when a practice is switching IT providers, or when someone finally reads the paperwork: does the IT company need a Business Associate Agreement?
Almost always, yes. And the reason is narrower than most people assume.
The test isn’t whether they look at records
A business associate is anyone who creates, receives, maintains or transmits protected health information on your behalf. The word doing the work there is maintains.
Your IT provider may never open a chart. But if they administer the server the charts sit on, back it up, hold the encryption keys, or have a remote-access tool that can reach a workstation with your EHR open on it — they maintain PHI. That is enough.
People sometimes reach for the conduit exception, which covers services that merely transport data without storing it, like the postal service or a telecoms carrier. It is deliberately narrow. HHS has been explicit that it does not cover a vendor with persistent access to data, and a managed IT provider is not a conduit by any reading.
What “we’re HIPAA compliant” means when a vendor says it
By itself, nothing. There is no HIPAA certification, no registry, and no body that issues a compliance badge. Any provider claiming to be “HIPAA certified” is describing a training course they took, not a status they hold.
What you actually want to establish is narrower and more answerable:
- Will they sign a BAA? If a provider hesitates, that tells you something. It is a normal document and they should have one ready.
- Who else can reach your data? Their remote-access tool, their documentation platform, their ticketing system. If your PHI can end up in a support ticket, whoever hosts that ticketing system is in scope too.
- What happens when they have an incident? Not you — them. If their systems are breached and yours are reachable from them, you need to know within days, not months.
That last one stopped being hypothetical this year. Ernst & Young disclosed that an unauthorised party accessed a third-party support ticket platform used by its IT help desk and downloaded documents attached to those tickets — including tax and financial records. Access ran for two weeks before anyone noticed, and the disclosure came nearly three months after that.
The BAA is not the protection
This is the part worth being blunt about. A signed BAA does not secure anything. It allocates responsibility and it obliges your vendor to safeguard PHI and report breaches. It is a contract, not a control.
If your provider signs the BAA and then keeps your admin passwords in a shared spreadsheet, you have a document and a problem. The agreement matters at the point something goes wrong; the safeguards matter every day before that.
What we would actually check
- Is a BAA on file, signed by both parties, and can you find it in under a minute? An unsigned draft in someone’s email is not a BAA.
- Does it name the actual entity you deal with? Providers restructure. An agreement with a company that no longer exists protects nobody.
- Do you have BAAs with the others too? The EHR vendor, the backup provider, the document shredding company, the answering service, the transcription service. The IT company is rarely the only one.
- Does anyone review them? Most practices sign once and never look again. Vendors change subprocessors; the risk changes with them.
None of this requires buying anything. If you want a second pair of eyes on where your practice actually stands before something forces the question, that is a conversation we are happy to have — and we will tell you if the answer is that you are fine.
This is general information about a regulation, not legal advice. For a specific situation, talk to a healthcare attorney.



