Business Associate Agreements: What Arizona Healthcare Providers Must Require from IT Vendors

Every IT vendor touching patient data needs a BAA

Under HIPAA, any organization that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity must sign a Business Associate Agreement. For Arizona medical practices, that includes your MSP, your cloud hosting provider, your EHR vendor, your billing service, your email provider, and potentially your shredding company.

If a vendor with access to PHI experiences a breach and there’s no BAA in place, your practice is liable under both HIPAA and Arizona’s ARS 18-552. The OCR has settled multiple cases specifically because practices failed to execute BAAs with their IT vendors.

What a BAA must include

  • Description of the permitted uses and disclosures of PHI
  • Requirement that the BA will not use or disclose PHI except as permitted
  • Requirement to implement appropriate safeguards
  • Requirement to report breaches of unsecured PHI
  • Requirement to ensure any subcontractors also sign BAAs
  • Requirement to make PHI available for patient access requests
  • Requirement to make records available to HHS for compliance investigations
  • Requirement to return or destroy PHI at contract termination

Red flags from IT vendors

Watch out for these warning signs:

  • “We don’t sign BAAs” means they either don’t understand HIPAA or aren’t confident in their security. Either way, don’t give them access to PHI.
  • Generic BAA templates that don’t reference your specific services are better than nothing but should be customized.
  • No SOC 2 or HIPAA compliance documentation to back up their BAA commitments.
  • Resistance to security questionnaires about how they protect your data.

Evaluating IT vendor compliance

Before signing a BAA with any IT vendor, ask:

  1. Do you have SOC 2 Type II certification?
  2. Can you provide documentation of your security controls?
  3. How do you encrypt PHI at rest and in transit?
  4. What is your breach notification timeline?
  5. Do your subcontractors also have BAAs in place?
  6. What happens to our data if we terminate the relationship?

A qualified HIPAA-compliant IT provider will answer all of these without hesitation and provide documentation to support their claims.

Getting your vendor agreements in order

Asteroid IT provides HIPAA-compliant IT support for Arizona medical practices, including BAA execution with all subcontractors. We serve practices across Chandler, Gilbert, and the East Valley.

Call us at 480-937-7021 or schedule a conversation.

Scroll to Top