Business Associate Agreement (BAA): Dental Practice Guide + Free Vendor Checklist
Last reviewed: April 26, 2026 · Author: ClearMax Labs Compliance Team
Plain-English answer: A BAA is the written contract you sign with every vendor
that touches your patient data. It transfers HIPAA obligations downstream, defines what the vendor
can and can’t do with PHI, and locks in breach-notification windows. Required by HIPAA §164.504(e).
For a typical dental practice, you need 8-15 of them: PMS, imaging, billing, IT vendor, email,
eFax, payment processor, marketing platform, lab software, sterilization tracking, etc. Most
practices we audit have 3-5 missing or unsigned.
Who needs a BAA?
The HIPAA definition of a business associate is anyone who creates, receives, maintains, or
transmits PHI on behalf of a covered entity in the course of providing a service. For a dental
practice, the typical BAA inventory includes:
- Practice management system (Dentrix, Eaglesoft, Open Dental, Curve Dental, Carestream)
- Imaging vendor (Dexis, Schick, Carestream Imaging, Romexis)
- Billing & insurance verification (DentalXChange, Vyne Trellis, NEA Powered by Vyne)
- IT vendor / MSP (every external technician with admin access)
- Email / collaboration (Microsoft 365, Google Workspace — confirm the BAA is signed)
- eFax (SRFax, Updox, eFax Corporate Healthcare)
- Payment processor (only if they receive PHI alongside payment data)
- Patient communication (Solutionreach, Weave, Lighthouse 360, Yapi, Modento, NexHealth)
- Backup / DR vendor (Datto, Veeam Cloud Connect, Acronis Healthcare)
- Marketing & review platforms if they touch patient names/contact info
The 11 required terms (per 45 CFR §164.504(e))
Every compliant BAA must include these 11 elements:
- Permitted uses and disclosures — what the BA is allowed to do with PHI.
- Prohibition on uses outside the contract — explicit no-go list.
- Safeguards — required administrative, physical, technical safeguards.
- Reporting unauthorized disclosures — to the covered entity, with timeline.
- Subcontractor flow-down — BA must require its subcontractors to sign equivalent BAAs.
- Access rights — providing access to PHI for individual access requests (§164.524).
- Amendment — supporting amendments to PHI per §164.526.
- Accounting of disclosures — providing the data needed for §164.528.
- HHS access — making books and records available to HHS for compliance investigations.
- Return or destruction at termination — what happens to PHI when the contract ends.
- Termination for breach — covered entity’s right to terminate if BA materially breaches.
If your BAA is missing any of these, it’s a §164.504(e) finding waiting to happen. The
HHS sample BAA provisions are the safest reference text.
Common BAA gaps in dental practices
- Personal email accounts. Front desk uses Gmail Personal or Yahoo to email lab
orders. No BAA possible. Switch to your practice Microsoft 365 (with BAA active) or Google
Workspace (with BAA signed in admin console). - Outsourced billing without a BAA. The billing service has full PMS access but
there’s no signed contract. Single most common finding in our audits. - Marketing agencies receiving patient contact lists. The agency runs your
Facebook ads or your Google Ads conversion tracking and at some point you sent them a CSV of
patient names. No BAA = breach. The fix: stop sending patient PII; use server-side conversion
tracking with hashed identifiers if needed. - IT vendors with verbal arrangements. The local IT guy your practice has used
for 8 years has admin domain credentials. There’s no BAA on file. This is the gap that explodes
during a ransomware investigation. - Cloud backup without a BAA. You’re paying for cloud backup but the contract
predates HIPAA awareness. Confirm the BAA is current and reflects the BA-subcontractor relationship.
Free 10-vendor BAA inventory checklist
Use the accordion below to walk every common dental vendor relationship and check BAA status.
For a populated, branded version with the full §164.504(e) language for each row, see the
$297 BAA Template + Vendor Inventory.
1. Practice Management System (Dentrix, Eaglesoft, Open Dental, etc.)
account manager in writing. For self-hosted Open Dental, you don’t need a BAA with Open Dental Inc.
itself but you DO need one with whoever hosts the database (your IT vendor or cloud host).
2. Digital Imaging Software (Dexis, Schick, Romexis, Carestream Imaging)
the imaging server without anyone signing the cloud-sync provider’s BAA.
3. Insurance Verification & Claims (DentalXChange, Vyne Trellis, NEA)
4. IT Vendor / MSP (your IT support company)
Every ClearMax engagement starts with a signed BAA before any access is granted.
5. Email / Collaboration (Microsoft 365, Google Workspace)
NOT Personal/Family). Google: accept BAA in Google Admin console — covered SKUs only (Business
Standard and up).
6. eFax Provider (SRFax, Updox, eFax Corporate Healthcare)
Corporate plan.
7. Patient Communication (Weave, Solutionreach, Yapi, NexHealth, Lighthouse 360)
on signup.
8. Backup / Disaster Recovery (Datto, Veeam, Acronis)
have standard BAA programs.
9. Marketing Platforms (only if they touch patient PII)
emailing patients with treatment-specific content, you need Mailchimp Transactional (with HIPAA BAA)
or LuxSci Email Marketing.
10. Payment Processor (Square, Stripe, etc.)
required if the processor handles itemized treatment line items tied to patient identifiers — most
dental processors do not, but verify in writing.
Need a defensible BAA template?
The $297 ClearMax BAA Template + Vendor Inventory is a legally-formatted BAA covering all 11 required terms in §164.504(e), plus a 2-page vendor-inventory tracker for your practice. Or get the BAA inventory done for you as part of the $1,100 HIPAA Audit.
Frequently Asked Questions
Do I need a BAA with Microsoft 365?
Yes — but you need to activate it. Standard Microsoft 365 commercial subscriptions include a BAA at no extra cost if you accept Microsoft’s BAA terms in the Service Trust Portal and use a SKU that’s covered. Microsoft 365 Business Basic/Standard/Premium and Microsoft 365 E3/E5 are covered. Microsoft 365 Personal and Microsoft 365 Family are NOT covered — those are consumer SKUs and Microsoft will not sign a BAA for them. If your front desk is using a personal Microsoft account on a practice computer, you have a §164.504(e) gap. Microsoft’s HIPAA/HITECH offering page spells out which products are in scope.
Can a verbal BAA count?
No. 45 CFR §164.504(e)(1) requires a written contract or other written arrangement. Verbal assurances, click-through marketing-page checkboxes that aren’t tied to a contract, or a vendor’s general ‘we’re HIPAA-compliant’ web banner do not satisfy the rule. You need a signed document — wet signature, DocuSign, or click-through with audit trail — naming both parties and the 11 required terms.
What if my vendor refuses to sign a BAA?
Two real options. (1) Replace the vendor — if they touch ePHI and won’t sign a BAA, you can’t use them under HIPAA. Period. (2) Restructure the relationship so they don’t touch ePHI — e.g., if your marketing agency was getting patient lists by email, switch to send-only mail-merge through a tool that does have a BAA (Mailchimp Transactional with HIPAA BAA, or HIPAA-compliant SMS via TigerConnect). The ‘they won’t sign so I’ll just hope nothing happens’ approach is the single most common §164.504(e) finding in OCR investigations.
Related ClearMax glossary entries
Sources:
45 CFR §164.504(e) (eCFR) ·
HHS Sample BAA Provisions ·
Microsoft HIPAA/HITECH Compliance Offering ·
HIPAA Journal — BAA Reference