What is a BAA?

BAA
A BAA, or business associate agreement, is the contract under HIPAA between a healthcare provider and a vendor handling protected health information on its behalf, setting out how that information may be used and safeguarded.

What BAA means in practice

Without one, passing PHI to a vendor is not permitted. The agreement is the mechanism, not a formality on top of one.

It has to run down the chain. Your vendor's subcontractors touch the same data, and each of those relationships needs its own agreement.

For a phone assistant that chain is longer than people expect: the telephony carrier, the speech recognition engine, the language model, the voice synthesis, and wherever recordings are stored.

What people get wrong

Counting the agreements behind one phone call

Say a physical therapy clinic is evaluating an AI phone vendor, and the salesperson says, "Yes, we'll sign a BAA." The practice manager asks a follow-up: which other companies touch the call?

An honest answer has five names in it. A telephony carrier delivers the audio. Speech recognition from a second company turns it into text. Next, a language model provider reads that text and writes the reply. Company four is the voice provider, which turns the reply into sound. And a cloud host stores the transcripts and recordings. The clinic's BAA covers only the vendor in front of it. For the chain to hold, that vendor needs its own signed agreement with each of the five, so one phone call rests on six contracts. The practice manager asks to see the subprocessor list and which entries have agreements in place. A vendor that has done the work can answer in one email, and a vague reply tells her just as much.

Four clauses to read before you sign

BAAs look like boilerplate, and the differences between them sit in a handful of clauses. Read the permitted uses first. It should limit the vendor to what's needed to provide the service. Watch for broad language about using your data to improve their products, and ask what it covers.

Then find the breach notification timing. HIPAA lets a business associate take up to 60 days after discovering a breach to tell you, and many practices negotiate that down to something far shorter, since your own notification clock depends on theirs.

Look at termination as well. The agreement should say your data is returned or destroyed when the contract ends, and how you'll get confirmation. Last comes the subcontractor clause, which should require the vendor to hold every subprocessor to the same terms. Have your attorney or compliance adviser read it too. We're describing what's commonly in these agreements, not giving legal advice, and GreetKeeper makes no BAA claim.

How GreetKeeper handles it

GreetKeeper makes no HIPAA claim and we are not going to put a badge on a page to close a sale.

If your practice needs a signed BAA covering every layer today, ask us directly about the current position before you buy rather than after.

The questions worth asking any vendor are the same four: will you sign, who are your subprocessors, do you hold agreements with each, and can we see them.

BAA questions

Who needs to sign a BAA?

The covered entity and each business associate that handles PHI on its behalf, and then each of those with its own subcontractors. The chain is the part people miss.

Does a BAA make a vendor secure?

It makes them contractually responsible, which is not the same thing. It allocates liability rather than proving any particular control exists.

Can I use a vendor with no BAA if I avoid PHI?

Only if you genuinely can keep PHI out, which is harder on a phone line than it sounds. Callers volunteer clinical detail without being asked.

Hear it take one of your calls

Two minutes, your own scenario, no card.