ClearMax HIPAA Glossary

Business Associate Agreement (BAA): Dental Practice Guide + Free Vendor Checklist

Last reviewed: April 26, 2026  ·  Author: ClearMax Labs Compliance Team

Plain-English answer: A BAA is the written contract you sign with every vendor
that touches your patient data. It transfers HIPAA obligations downstream, defines what the vendor
can and can’t do with PHI, and locks in breach-notification windows. Required by HIPAA §164.504(e).
For a typical dental practice, you need 8-15 of them: PMS, imaging, billing, IT vendor, email,
eFax, payment processor, marketing platform, lab software, sterilization tracking, etc. Most
practices we audit have 3-5 missing or unsigned.

Who needs a BAA?

The HIPAA definition of a business associate is anyone who creates, receives, maintains, or
transmits
PHI on behalf of a covered entity in the course of providing a service. For a dental
practice, the typical BAA inventory includes:

  • Practice management system (Dentrix, Eaglesoft, Open Dental, Curve Dental, Carestream)
  • Imaging vendor (Dexis, Schick, Carestream Imaging, Romexis)
  • Billing & insurance verification (DentalXChange, Vyne Trellis, NEA Powered by Vyne)
  • IT vendor / MSP (every external technician with admin access)
  • Email / collaboration (Microsoft 365, Google Workspace — confirm the BAA is signed)
  • eFax (SRFax, Updox, eFax Corporate Healthcare)
  • Payment processor (only if they receive PHI alongside payment data)
  • Patient communication (Solutionreach, Weave, Lighthouse 360, Yapi, Modento, NexHealth)
  • Backup / DR vendor (Datto, Veeam Cloud Connect, Acronis Healthcare)
  • Marketing & review platforms if they touch patient names/contact info

The 11 required terms (per 45 CFR §164.504(e))

Every compliant BAA must include these 11 elements:

  1. Permitted uses and disclosures — what the BA is allowed to do with PHI.
  2. Prohibition on uses outside the contract — explicit no-go list.
  3. Safeguards — required administrative, physical, technical safeguards.
  4. Reporting unauthorized disclosures — to the covered entity, with timeline.
  5. Subcontractor flow-down — BA must require its subcontractors to sign equivalent BAAs.
  6. Access rights — providing access to PHI for individual access requests (§164.524).
  7. Amendment — supporting amendments to PHI per §164.526.
  8. Accounting of disclosures — providing the data needed for §164.528.
  9. HHS access — making books and records available to HHS for compliance investigations.
  10. Return or destruction at termination — what happens to PHI when the contract ends.
  11. Termination for breach — covered entity’s right to terminate if BA materially breaches.

If your BAA is missing any of these, it’s a §164.504(e) finding waiting to happen. The
HHS sample BAA provisions are the safest reference text.

Common BAA gaps in dental practices

  • Personal email accounts. Front desk uses Gmail Personal or Yahoo to email lab
    orders. No BAA possible. Switch to your practice Microsoft 365 (with BAA active) or Google
    Workspace (with BAA signed in admin console).
  • Outsourced billing without a BAA. The billing service has full PMS access but
    there’s no signed contract. Single most common finding in our audits.
  • Marketing agencies receiving patient contact lists. The agency runs your
    Facebook ads or your Google Ads conversion tracking and at some point you sent them a CSV of
    patient names. No BAA = breach. The fix: stop sending patient PII; use server-side conversion
    tracking with hashed identifiers if needed.
  • IT vendors with verbal arrangements. The local IT guy your practice has used
    for 8 years has admin domain credentials. There’s no BAA on file. This is the gap that explodes
    during a ransomware investigation.
  • Cloud backup without a BAA. You’re paying for cloud backup but the contract
    predates HIPAA awareness. Confirm the BAA is current and reflects the BA-subcontractor relationship.

Free 10-vendor BAA inventory checklist

Use the accordion below to walk every common dental vendor relationship and check BAA status.
For a populated, branded version with the full §164.504(e) language for each row, see the
$297 BAA Template + Vendor Inventory.

1. Practice Management System (Dentrix, Eaglesoft, Open Dental, etc.)
BAA usually included with subscription — confirm by checking the contract page or asking your
account manager in writing. For self-hosted Open Dental, you don’t need a BAA with Open Dental Inc.
itself but you DO need one with whoever hosts the database (your IT vendor or cloud host).
2. Digital Imaging Software (Dexis, Schick, Romexis, Carestream Imaging)
Usually included with the maintenance contract. Common gap: cloud-sync feature was enabled on
the imaging server without anyone signing the cloud-sync provider’s BAA.
3. Insurance Verification & Claims (DentalXChange, Vyne Trellis, NEA)
BAA always required. These vendors handle PHI by definition (claims data is PHI).
4. IT Vendor / MSP (your IT support company)
Required, no exceptions. If the IT vendor refuses to sign or won’t provide one, replace them.
Every ClearMax engagement starts with a signed BAA before any access is granted.
5. Email / Collaboration (Microsoft 365, Google Workspace)
Microsoft: accept BAA terms in Service Trust Portal — covered SKUs only (Business Basic and up,
NOT Personal/Family). Google: accept BAA in Google Admin console — covered SKUs only (Business
Standard and up).
6. eFax Provider (SRFax, Updox, eFax Corporate Healthcare)
Required. eFax Personal/Plus consumer plans do NOT include a BAA. Must be on a Healthcare or
Corporate plan.
7. Patient Communication (Weave, Solutionreach, Yapi, NexHealth, Lighthouse 360)
Required. These platforms send appointment reminders containing PHI by definition. Always BAA
on signup.
8. Backup / Disaster Recovery (Datto, Veeam, Acronis)
Required for any vendor that physically stores ePHI offsite. Datto and Veeam Cloud Connect
have standard BAA programs.
9. Marketing Platforms (only if they touch patient PII)
Most marketing platforms (Mailchimp Standard, Constant Contact) do NOT offer a BAA. If you’re
emailing patients with treatment-specific content, you need Mailchimp Transactional (with HIPAA BAA)
or LuxSci Email Marketing.
10. Payment Processor (Square, Stripe, etc.)
Generally NOT required if the processor only handles payment data, not treatment data. Becomes
required if the processor handles itemized treatment line items tied to patient identifiers — most
dental processors do not, but verify in writing.

Need a defensible BAA template?

The $297 ClearMax BAA Template + Vendor Inventory is a legally-formatted BAA covering all 11 required terms in §164.504(e), plus a 2-page vendor-inventory tracker for your practice. Or get the BAA inventory done for you as part of the $1,100 HIPAA Audit.

Buy BAA Template ($297) →Get BAAs Inventoried ($1,100)

Frequently Asked Questions

Do I need a BAA with Microsoft 365?

Yes — but you need to activate it. Standard Microsoft 365 commercial subscriptions include a BAA at no extra cost if you accept Microsoft’s BAA terms in the Service Trust Portal and use a SKU that’s covered. Microsoft 365 Business Basic/Standard/Premium and Microsoft 365 E3/E5 are covered. Microsoft 365 Personal and Microsoft 365 Family are NOT covered — those are consumer SKUs and Microsoft will not sign a BAA for them. If your front desk is using a personal Microsoft account on a practice computer, you have a §164.504(e) gap. Microsoft’s HIPAA/HITECH offering page spells out which products are in scope.

Can a verbal BAA count?

No. 45 CFR §164.504(e)(1) requires a written contract or other written arrangement. Verbal assurances, click-through marketing-page checkboxes that aren’t tied to a contract, or a vendor’s general ‘we’re HIPAA-compliant’ web banner do not satisfy the rule. You need a signed document — wet signature, DocuSign, or click-through with audit trail — naming both parties and the 11 required terms.

What if my vendor refuses to sign a BAA?

Two real options. (1) Replace the vendor — if they touch ePHI and won’t sign a BAA, you can’t use them under HIPAA. Period. (2) Restructure the relationship so they don’t touch ePHI — e.g., if your marketing agency was getting patient lists by email, switch to send-only mail-merge through a tool that does have a BAA (Mailchimp Transactional with HIPAA BAA, or HIPAA-compliant SMS via TigerConnect). The ‘they won’t sign so I’ll just hope nothing happens’ approach is the single most common §164.504(e) finding in OCR investigations.

Sources:
45 CFR §164.504(e) (eCFR) ·
HHS Sample BAA Provisions ·
Microsoft HIPAA/HITECH Compliance Offering ·
HIPAA Journal — BAA Reference