Who needs a BAA?
Any vendor that creates, receives, maintains, or transmits PHI for your practice is a business associate (or subcontractor). Common examples: HIPAA email, cloud fax, patient forms, billing services, and some IT providers.
What a BAA should cover
- Permitted uses and disclosures of PHI
- Safeguards the vendor will maintain
- Breach notification timelines
- Subcontractor flow-down requirements
- Return or destruction of PHI at termination
Common mistakes
Signing a BAA but never training staff on the approved tool. Using a vendor’s “terms of service” instead of a HIPAA BAA. Letting BAAs expire when you renew SaaS contracts without re-execution.
Keep an audit-ready vendor file
Store executed BAAs with renewal dates, note which systems each vendor touches, and review annually when you add new apps. OCR will ask for this file early in an investigation.
How Easy MD Forms handles BAAs
When you evaluate Easy MD Forms, the Business Associate Agreement is not a separate negotiation or a paid add-on. Every subscription tier includes BAA execution before you send your first production message—so your vendor file is complete from day one, not assembled after a close call.
- Digital signing during onboarding — no weeks waiting on legal back-and-forth for a standard clinic rollout
- One BAA for the platform — email, fax, patient forms, secure files, and team chat under the same agreement
- Included on every plan — Starter, Practice, and Group; no surprise line item at contract time
- Documentation you can file — executed copy for your compliance binder and privacy officer reviews
What our agreement addresses
A proper BAA maps HIPAA obligations to the services you actually use. Ours covers the elements OCR expects to see when they review vendor relationships:
- Permitted uses and disclosures of PHI for Easy MD Forms services
- Safeguards we maintain (encryption, access controls, audit logging)
- Breach notification commitments and cooperation timelines
- Subcontractor flow-down where subprocessors handle PHI
- Return or destruction of PHI when the relationship ends
For technical safeguard detail—encryption, logging, MFA, and due-diligence packets—see our Security & BAA overview.
