HIPAA Compliance

Dental Business Associate Agreements: 2026 Checklist

Use this 2026 dental BAA checklist to identify business associates, review HIPAA contract terms, manage subcontractors, cloud vendors, and renewals.

Dental IT Team August 15, 2026 11 min read
dental business associate agreement dental BAA checklist HIPAA business associate dental practice business associate agreement requirements
Dental practice leaders reviewing a vendor business associate agreement and HIPAA responsibilities on a computer
A BAA should match the vendor's real access to PHI, define required protections and reporting duties, and stay connected to ongoing vendor oversight.

A dental business associate agreement is not just a form to collect from vendors. It is the written framework that defines how a business associate may use protected health information, what safeguards and reporting duties apply, how subcontractors are handled, and what happens to PHI when the relationship ends. For a dental practice, the practical challenge is knowing which vendors actually qualify as business associates, making sure the agreement contains the required HIPAA elements, and then connecting that contract to real vendor-risk management instead of filing it away and forgetting it.

Key Takeaways

Start with the vendor's actual role: a BAA is generally required when an outside person or company creates, receives, maintains, or transmits PHI on behalf of the dental practice, but not every vendor relationship qualifies.

The agreement must cover permitted uses and disclosures, safeguards, incident and breach reporting, subcontractors, individual-rights support, HHS access, termination, and return or destruction of PHI.

A signed BAA does not replace security due diligence. Practices still need to understand vendor access, authentication, backups, incident handling, subcontractors, data location, termination procedures, and other operational risks.

What is a business associate agreement for a dental practice?

Under HIPAA, a business associate is generally a person or organization outside the covered entity's workforce that performs functions or provides services involving protected health information on behalf of the covered entity. HHS says covered entities must obtain satisfactory assurances in writing that the business associate will appropriately safeguard the PHI it receives or creates on the covered entity's behalf.

The BAA is the contract or other written arrangement that supplies those assurances. It defines the permitted and required uses and disclosures of PHI, requires appropriate safeguards, establishes reporting and cooperation duties, and addresses what happens when the relationship ends. Business associates also have direct liability under parts of the HIPAA Rules; the document is therefore more than a promise between two private companies.

Which dental vendors are likely to be business associates?

Common examples can include billing and claims services, outsourced IT providers, managed service providers, cloud storage or backup companies, patient-communication platforms, consultants, legal or accounting providers, record-storage or destruction services, and software companies when their services require them to create, receive, maintain, or transmit PHI on behalf of the practice. The key is the service and PHI relationship, not the vendor's marketing category.

HHS specifically notes that outside IT specialists can be business associates when their work involves PHI. For dental offices, remote support tools, server administration, backup portals, database troubleshooting, imaging support, cloud administration, and migration projects can all create access pathways to ePHI. If an IT provider can reach systems containing patient information as part of its service, the practice should evaluate the business associate relationship rather than assuming the vendor is merely a computer contractor.

Which relationships do not automatically require a BAA?

Not every company that sells something to a dental practice becomes a business associate. HHS says the mere sale or provision of software does not by itself create a business associate relationship when the vendor does not have access to the covered entity's PHI. A locally installed product with no vendor access may therefore present a different HIPAA relationship from a hosted service or support contract that allows the vendor to access patient data.

HIPAA also contains exceptions. Members of the practice's workforce are not business associates. Disclosures from one covered health care provider to another provider for treatment generally do not require a business associate contract. HHS also recognizes a narrow conduit exception for transmission-only services where access to PHI is transient rather than persistent.

What must a dental BAA contain?

HHS's sample business associate contract guidance gives practices a useful checklist. The agreement should establish the permitted and required uses and disclosures of PHI; prohibit other uses or disclosures except as permitted by the contract or required by law; and require appropriate safeguards, including applicable Security Rule protections for ePHI.

The contract should also require the business associate to report uses or disclosures that are not provided for by the agreement, including breaches of unsecured PHI; assist the covered entity with access, amendment, and accounting obligations where applicable; make relevant records available to HHS for compliance review; and comply with Privacy Rule requirements when the business associate is performing a covered entity obligation on its behalf.

How should cloud and software vendors be reviewed?

Cloud services deserve special attention because storing data is enough to create a business associate relationship in many cases. HHS says a covered entity may use a cloud service to store or process ePHI when it enters into a HIPAA-compliant BAA with the cloud service provider and otherwise complies with the HIPAA Rules. Encryption does not remove that relationship when the provider maintains the ePHI.

The contract review should be paired with technical questions. Determine what data is stored, where the authoritative copy resides, whether the vendor can access the data, how administrators authenticate, how backups work, how data is restored, what logs are available, how security incidents are communicated, and how data will be returned or destroyed after termination. For a dental practice, also confirm how the cloud service interacts with practice-management, imaging, scanners, workstations, mobile devices, and third-party integrations.

What should the practice know about subcontractors?

Dental practices rarely receive services from a single isolated company. A patient-communication vendor may use cloud hosting, messaging infrastructure, analytics, or support subcontractors. An MSP may use remote-management, endpoint-security, ticketing, backup, and cloud platforms. The primary vendor's subcontractor chain can therefore determine where PHI is maintained or transmitted even when the practice has no direct contract with each downstream provider.

HIPAA requires business associates to obtain appropriate written assurances from subcontractors that create, receive, maintain, or transmit PHI on their behalf. The dental practice does not need to negotiate a separate BAA with every subcontractor in the chain, but it should understand whether subcontractors exist and whether the primary vendor contract properly flows down the required restrictions and conditions.

How should incident and breach reporting be handled?

The BAA should require the business associate to report impermissible uses or disclosures and breaches as required by the HIPAA Rules. Do not stop at a generic promise to notify the practice 'promptly.' Operationally, the practice should know the vendor's incident contact, escalation path, after-hours process, information the vendor will provide, and how the parties will coordinate investigation and notification decisions.

Contract language and incident-response procedures should work together. A vendor may discover suspicious access, ransomware, credential theft, accidental disclosure, or data loss before the dental practice sees any sign of the event. The practice needs enough information to evaluate scope, affected systems, PHI involved, containment, restoration, and its own notification obligations without waiting for an ordinary support-ticket cycle.

What should happen when a vendor relationship ends?

Termination is where weak agreements become expensive. Before signing, determine how the practice will retrieve records, images, exports, logs, configurations, and other information needed to continue patient care and business operations. Confirm the export format, timing, costs that are already contractually defined, and whether the practice can obtain the data without relying on the same account or administrator that is being terminated.

The BAA should require return or destruction of PHI when feasible. The practice should also remove vendor accounts, remote agents, VPN access, API credentials, shared passwords, forwarding rules, delegated cloud permissions, and physical access. Preserve records needed for legal, contractual, operational, or security purposes while avoiding indefinite retention of unnecessary access pathways.

How often should dental practices review BAAs?

HIPAA does not create a universal rule that every BAA must be re-signed annually. A better process is to maintain a current vendor and BAA register and review agreements when services, data access, ownership, subcontractors, products, locations, or regulatory obligations materially change. Practices can also use a periodic annual review as an administrative checkpoint even when a new signature is not required.

Track the vendor name, service owner, BAA status, effective date, contract renewal date, PHI involved, systems accessed, administrative accounts, subcontractor status, incident contact, termination requirements, and most recent risk review. This turns the BAA file from a folder of PDFs into a working control that can support audits, risk assessments, incident response, and vendor changes.

What BAA mistakes create avoidable risk?

The first mistake is collecting a BAA without confirming that it matches the service. A generic template may not reflect cloud storage, remote IT administration, patient messaging, data analytics, AI features, subcontractors, or the way the vendor actually handles PHI. The agreement should describe a real relationship, not simply contain the acronym HIPAA.

Another mistake is assuming a vendor's refusal to sign a BAA settles the legal analysis. If the vendor is creating, receiving, maintaining, or transmitting PHI on behalf of the practice, the practice should not route PHI through that service merely because the vendor's standard plan excludes a BAA. HHS states that using a cloud service to maintain ePHI without an appropriate BAA can violate the HIPAA Rules.

Did the proposed HIPAA Security Rule change BAA requirements in 2026?

As of August 2026, HHS continues to describe the major Security Rule cybersecurity modernization as a proposed rule and states that the current Security Rule remains in effect. Dental practices should not rewrite vendor contracts as though every proposal is already final law or claim a compliance deadline that HHS has not established through a final rule.

The proposal does reinforce the importance of understanding business associate security because it would make cybersecurity requirements more prescriptive for covered entities and business associates. Practices can use the rulemaking period to improve vendor inventories, authentication, encryption, incident response, network documentation, risk analysis, and contract alignment without mislabeling proposed provisions as current mandates.

What does a practical dental BAA checklist look like?

Start by exporting the vendor list from accounting, IT documentation, software subscriptions, contracts, and department records. For each vendor, identify the service, owner, systems involved, PHI exposure, hosting model, support access, and subcontractors. Classify the relationship as likely business associate, likely non-business associate, or needs legal/compliance review instead of guessing from the vendor name.

For likely business associates, confirm that a signed agreement exists and review it against the HHS required elements. Then connect the contract to a vendor-risk record: authentication, privileged access, encryption, backup and recovery, security contacts, breach reporting, subcontractors, data return, termination, and evidence reviewed. Resolve missing agreements and unsupported PHI workflows before expanding the service.

Sources and References

Primary sources used for this article

Regulations, product support information, and incident details can change. Review the linked primary sources for the latest status.

HHS — Business Associate Contracts

Primary HHS guidance listing required business associate contract elements and sample provisions.

HHS — Business Associates Guidance

Definitions, examples, exceptions, and business associate contract requirements.

HHS — Guidance on HIPAA and Cloud Computing

Official guidance on cloud service providers, encrypted ePHI, BAAs, SLAs, risk analysis, and the conduit exception.

HHS — Software Vendor Business Associate FAQ

Explains why software sales alone do not automatically create a business associate relationship when the vendor has no PHI access.

HHS OCR — MMG Fusion Settlement

March 2026 enforcement example involving a software company that OCR describes as a HIPAA business associate.

HHS — HIPAA Security Rule NPRM

Current HHS rulemaking status; HHS states the current Security Rule remains in effect while the cybersecurity update is proposed.

Common Questions

Frequently asked questions

Does every dental software company need to sign a BAA?

No. HHS says merely selling or providing software does not automatically create a business associate relationship when the vendor has no access to PHI. A BAA is generally required when the vendor creates, receives, maintains, or transmits PHI on behalf of the practice.

Does a cloud vendor need a BAA if the data is encrypted?

Generally yes when the cloud provider maintains ePHI on behalf of the practice. HHS states that a cloud provider can still be a business associate even if it stores only encrypted ePHI and does not possess the decryption key.

Does an IT company that supports a dental office need a BAA?

It depends on the services and access. Outside IT specialists are common examples of business associates when their work involves PHI. Remote administration, server support, backups, migrations, or access to systems containing patient information should be evaluated carefully.

Do dental practices need a new BAA every year?

HIPAA does not impose a blanket annual re-signing rule for every BAA. Practices should keep agreements current and review them when services, data access, parties, subcontractors, or applicable requirements change; a periodic annual inventory is still a useful governance practice.

Can a BAA replace vendor security due diligence?

No. A BAA establishes required contractual assurances, but the practice still needs risk-based information about access, authentication, safeguards, backups, incident response, subcontractors, data return, and other operational security issues.

Is the 2024-2026 HIPAA Security Rule cybersecurity proposal final?

No. As of August 2026, HHS continues to identify the Security Rule cybersecurity modernization as a proposed rule and states that the current Security Rule remains in effect while rulemaking continues.

Keep Reading

Related dental technology articles.

View All Articles