Skip to main content
The PC is a HIPAA covered entity. The dental support organization (DSO) handles protected health information on the PC’s behalf, which makes it a business associate, and a written business associate agreement (BAA) is required before the DSO touches any PHI.

Prerequisites

  • Both entities formed
  • A privacy officer identified for the PC
  • An inventory of every vendor that will handle PHI

Who needs a BAA with whom

Banks are generally not business associates for ordinary payment processing. HIPAA excludes financial institutions’ payment activities from the business associate definition. That is why you don’t need a BAA to receive payer EFTs, and also why you must never put PHI in a bank memo field, because the exclusion covers processing payments, not receiving clinical data.

What the BAA must contain

The required elements are specified at 45 C.F.R. § 164.504(e).1 A compliant BAA must:

Steps

1

Execute the DSO–PC BAA before the first patient

Not after go-live. The DSO handles PHI from the moment it operates scheduling or billing.One BAA per PC. Each professional entity is a separate covered entity. A ten-PC group has ten BAAs with the DSO.
2

Inventory every vendor that touches PHI

Walk the data flow:
  • PMS (practice management system) vendor
  • Dental clearinghouse
  • Attachment service: radiographs, perio charts, and narratives pass through these vendors on their way to payers, and imaging is PHI
  • Billing service or RCM vendor
  • Cloud hosting and infrastructure, including cloud imaging storage
  • Patient statement, recall, and communication vendors
  • Answering service, transcription, interpretation
  • Analytics and data warehouse tooling
  • AI and LLM providers, and any model gateway or proxy
  • Document storage and shredding
  • Collections agency
  • IT support with system access
A denial analytics warehouse built from 835 data holds PHI. Teams building it as a finance project routinely miss the BAA, the encryption requirement, and its inclusion in the risk analysis. See HIPAA fundamentals.
3

Execute subcontractor BAAs

The DSO, as a business associate, must have BAAs with its own subcontractors. Those subcontractors are business associates in their own right and are directly liable under HIPAA.
4

Read the vendor's BAA rather than signing it unread

Most vendors present their own form. Check:
  • Breach notification timeline. Is it short enough for the PC to meet its own 60-day deadline?
  • Whether the vendor may use PHI for its own purposes such as product improvement, and whether that is acceptable
  • Indemnification and liability caps
  • Whether subcontractors are permitted and how they’re controlled
  • Return or destruction obligations at termination. For a PMS, ask specifically how you will export the clinical database and imaging.
  • Where data is stored, including offshore
5

Build the BAA inventory

A single register: vendor, what PHI they handle, BAA execution date, renewal or review date, breach notification window, and the internal owner.
6

Review annually and on every new vendor

Add to the compliance calendar. See Set up your compliance calendar.

Verify it worked

  • A BAA between the DSO and each PC, executed before PHI was handled
  • All nine required elements present
  • Every PHI-handling vendor identified, including the PMS, clearinghouse, and attachment service
  • Subcontractor BAAs executed
  • Breach notification windows short enough to meet the covered entity’s deadline
  • BAA inventory maintained with review dates
  • Analytics and data warehouse infrastructure included
  • No BAA sought with the bank for ordinary payment processing, and no PHI in bank fields

Common failure modes

Sources

  1. 45 C.F.R. § 164.504(e). eCFR. HHS OCR, Business Associate Contracts.
Last modified on August 21, 2026