On this page
Every vendor that creates, receives, stores, or transmits patient information on your behalf must sign a business associate agreement (BAA) before any PHI touches their systems: your EHR, email, video platform, fax service, AI scribe, cloud storage, and any staffing agency. Two groups are exempt. Your W-2 employees are workforce rather than business associates, so you train them instead of contracting with them, and pure payment processing is carved out of HIPAA by statute. The table below covers the twelve vendor categories a solo practice actually uses: whether each needs a BAA, whether the common vendors will sign one, and where the traps are.
This is practice-operations guidance rather than legal advice. Your vendor stack interacts with state privacy law too, so run anything load-bearing past your attorney.
Which vendors have to sign a BAA?
Every category below that stores or handles identifiable patient information needs a signed BAA before it sees the first patient name. Vendor postures verified August 2026.
| Vendor category | BAA needed? | Will they sign? | The fine print |
|---|---|---|---|
| EHR / practice platform | Yes, always | Yes, universally | This vendor holds the entire chart. Every legitimate EHR signs during onboarding, Eureka included. Hesitation here disqualifies the vendor. |
| Email and calendar | Yes | Paid tiers only | Google signs for paid Workspace editions, never for free Gmail; you accept the BAA yourself in the admin console. Microsoft includes its BAA by default in the standard Microsoft 365 terms. |
| Video visits | Yes | Paid tiers only | Zoom signs for selected paid plans and sells a healthcare edition; free accounts are never covered. Get the signature before the first visit, whichever platform you pick. |
| Fax | Yes | Qualifying accounts | eFax signs on qualifying accounts, and its own terms push PHI storage to the higher secure tiers, so read which product you are actually buying. Healthcare-first fax vendors keep the terms simpler. |
| Phone and texting | Depends | Varies | Your phone carrier is a conduit and signs nothing. Any platform that stores call recordings, voicemails, or message content is a business associate. Full comparison in the phone stack guide. |
| Scheduling | Yes, if it stores patient data | Varies | A booking tool holding names and appointment times for a psychiatry practice holds PHI. Your EHR's scheduler rides on the EHR BAA; many consumer schedulers offer no BAA at all. |
| AI scribes and transcription | Yes | Business tiers | A scribe that hears the visit is a business associate: no BAA, no recording. Consumer chatbot accounts carry no BAA, and the agreement should also bar training on your data. |
| Virtual assistants and staffing | Contractors, yes | Yes, make it a hiring condition | A W-2 employee is workforce: train them, no BAA. Agencies and individual contractors sign before first login. Setup details in the VA hiring guide. |
| Payment processors | No, for the charge itself | Mostly no | Payment processing is statutorily exempt, so processors decline BAAs; Stripe says it cannot sign one, and Square has offered BAA coverage only for some non-payment features. Keep treatment context out of payment fields. |
| Cloud storage and backup | Yes | Business tiers | Google Drive is on Google's covered-services list, OneDrive is in Microsoft's BAA scope, and Dropbox signs on Business plans. The uncovered version is the personal account of the same product. |
| Website and intake forms | Yes, if forms collect PHI | Wix now does | Wix reversed its years-long refusal and signs on qualifying premium plans once PHI protection is activated on the site. An uncovered form layer anywhere breaks the chain. |
| Labs and pharmacies | No | Not applicable | Labs and pharmacies are covered entities receiving PHI for treatment, which HIPAA permits without a BAA. No signature needed to send an order or a prescription. |
Who counts as a business associate in the first place?
Anyone outside your workforce who creates, receives, maintains, or transmits PHI to do a job for you, per HHS's definition. Three boundary cases decide most of the table:
- Employees are workforce. You supervise and train them under your policies instead of contracting with them. The moment the same role is filled by an outside agency or an individual contractor, that person is a business associate and the BAA requirement applies, regardless of country.
- Conduits are exempt. Entities that merely transport PHI without storing it, like the postal service, your internet provider, and your phone carrier, need no BAA. The exception is narrow: a service that holds your messages, recordings, or files on its servers is outside it.
- Other covered entities are already regulated. Quest, your patient's pharmacy, and the colleague covering your vacation receive PHI for treatment, and HIPAA permits treatment disclosures between covered entities without a BAA.
Job titles change nothing. A "software vendor," a "consultant," and a "friend helping with billing" are all business associates the moment PHI reaches them.
How do you get the Google Workspace BAA?
You accept it yourself in the admin console on any paid Workspace edition; Google never signs for free @gmail.com accounts. The path: Admin console, then Account settings, then Legal and compliance, then Security and Privacy Additional Terms, then review and accept the HIPAA Business Associate Amendment. Electronic acceptance is binding, and nothing gets mailed.
Two details matter after the click. First, the BAA applies only to Google's covered-services list (current version dated May 14, 2026): Gmail, Calendar, Drive with Docs, Sheets, and Forms, Meet, Chat, Keep, Sites, Tasks, Vault, Gemini in Workspace, and Google Voice for managed users, among others. A Google product missing from that list sits outside the BAA even on a paid account. Second, acceptance changes nothing about configuration. You still have to restrict sharing, control third-party app access, and document those choices.
Microsoft is the low-friction contrast: the HIPAA BAA is included by default in the Microsoft 365 Data Protection Addendum for every commercial customer, with its own in-scope services list covering Exchange Online, OneDrive for Business, Teams, and SharePoint. There is nothing to countersign, but the same fine print applies: check the list, then configure.
Does Stripe sign a BAA?
No. Stripe has stated it is unable to sign BAAs, and for the charge itself it does not need one: Section 1179 of HIPAA exempts financial institutions when they process payment transactions, which is why no processor, bank, or card network signs a BAA for moving money. Square has been the partial exception, offering BAA coverage for some non-payment features like messaging and marketing while taking the same exemption for processing; confirm the current terms with Square directly before relying on that (postures checked August 2026).
The working rule: the charge is exempt, everything around it is on you. A name and a card number moving through a payment rail is fine. A receipt line reading "99214 + 90833 psychotherapy add-on" ties that name to psychiatric treatment inside a system with no BAA. Keep diagnosis codes, medication names, and session details out of payment descriptions, memo fields, invoices, and customer-facing receipts; "professional services" does the job. Running card-on-file billing inside your EHR keeps the patient-facing payment layer under the EHR's BAA, which is how Eureka structures it, and the processor sees a charge without the chart.
Can your website collect patient information?
Only through a layer that is covered end to end. For years the specific answer for Wix was no: Wix would never sign a BAA, and the standard advice was to keep every patient-facing form off a Wix site. That has changed. As of 2026, Wix offers HIPAA support with a BAA on qualifying premium plans after you activate PHI protection, which restricts the site to approved apps. Verify plan eligibility at signup, because the forum advice you will find is stale in both directions: pre-2026 threads say Wix can never work, and a default Wix site with no PHI protection activated is still uncovered today.
Whatever Wix does next, a form is only as compliant as its weakest layer. A common small-practice setup routes an uncovered website form into BAA-covered Workspace email, and the destination being covered does nothing for the collection layer that gathered and transmitted the data. On a psychiatry site, an inquiry form links a name to the fact of seeking psychiatric care, the same category of linkage mapped in how patient data leaks to insurers. The clean pattern: let your marketing site stay a brochure with a phone number and a booking link, and run every real intake form through your EHR's patient-facing forms, which already sit under the EHR BAA.
What do you do when a vendor will not sign?
Change tiers, change vendors, or keep PHI out of the tool entirely. There is no fourth option, and "we're very secure" is not one of the three. OCR has fined practices for the missing signature alone: the Center for Children's Digestive Health, a small Chicago pediatric group, paid $31,000 in 2017 because its paper-records storage vendor had no BAA on file; Raleigh Orthopaedic Clinic paid $750,000 in 2016 for releasing X-ray films to a vendor without one; Advanced Care Hospitalists paid $500,000 in 2018 with the absent BAA leading the findings list.
David Cohen, CPA, JD, who reviews this handbook's legal content, draws the line this way: "A BAA costs a real vendor nothing; the standard ones are executed electronically in minutes. When a vendor stalls, or offers you a security white paper instead of a signature, they are telling you their product was never built to hold PHI. Believe them and move on."
The keep-PHI-out option is legitimate for tools doing genuinely patient-free work: bookkeeping by amounts, blog drafting, general email to colleagues. Its weakness is that it fails silently. The policy holds only until someone pastes a patient email into the uncovered tool, so write the boundary down, train anyone who works with you on it, and prefer covered tools for anything within arm's reach of clinical work.
Are signed BAAs enough to make you compliant?
No. A folder of signed BAAs satisfies one requirement, and the Security Rule separately requires a documented risk analysis of your own practice. This is the gap that shows up over and over when small practices get audited: compliant software everywhere, BAAs signed, and no written risk assessment, no security policy, and no device backup procedure. Using covered vendors was never the whole assignment.
For a solo telehealth practice the fix is an afternoon, and the table above is the starting inventory. List every system that touches PHI, note where each could fail (lost laptop, phished email account, departed contractor with live credentials), and document what you have done about each one. HHS publishes a free Security Risk Assessment tool built for small practices. Store the finished assessment with your BAAs, and re-run the inventory once a year, because the stack drifts: the AI scribe you trialed in March became a business associate whether or not the trial converted.