MSP BAA Obligations: What a Business Associate Agreement Commits You To
A Business Associate Agreement commits a managed service provider to five things: use protected health information only as the agreement permits, apply Security Rule safeguards to it, report security incidents and breaches to the client, bind its own subcontractors to the same terms, and return or destroy the data when the agreement ends. Those terms are set by 45 CFR 164.504(e). Signing is the easy part. Each clause has an operational cost the MSP absorbs.
The five clauses that carry real work
1. Permitted use and disclosure. The MSP may use protected health information only for the services in the contract. Using client data for its own analytics, benchmarking, or product development is outside the agreement unless the agreement says otherwise.
2. Safeguards. 45 CFR 164.504(e)(2)(ii)(B) requires appropriate safeguards. For a business associate this points back to the Security Rule directly, including the Security Risk Analysis at 45 CFR 164.308(a)(1)(ii)(A) covering the MSP’s own systems.
3. Incident and breach reporting. The MSP reports security incidents to the client, and reports breaches of unsecured protected health information under 45 CFR 164.410. Most agreements set a reporting window shorter than the regulation’s outer limit. Read the number in the contract, because that number is the one that binds.
4. Subcontractor flow-down. 45 CFR 164.308(b) and 164.502(e)(1)(ii) require the MSP to bind every subcontractor that touches protected health information to equivalent terms. A cloud backup provider, an offsite media vendor, or an outsourced night help desk each needs its own agreement.
5. Return or destruction at termination. When the agreement ends, protected health information is returned or destroyed if feasible. If it is not feasible, protections continue for as long as the MSP retains it. Backup retention is where this clause usually bites: data in a 90 day backup rotation is still in scope after the client leaves.
Clauses to read closely before signing
- Indemnification and breach cost allocation. Not required by HIPAA and frequently added. It decides who pays for notification and credit monitoring.
- Audit rights. How much access the client gets to the MSP’s environment and on what notice.
- Reporting windows. Often tighter than the regulation. A 24 hour incident reporting clause is an operational commitment on nights and weekends.
- Cyber liability insurance minimums. A cost that scales with the client roster.
What to have in place before you sign the first one
- A current Security Risk Analysis of the MSP’s own environment.
- Written policies and procedures, retained six years under 45 CFR 164.316(b)(2)(i).
- Workforce training records for technicians with client access.
- Executed agreements with every subcontractor that touches protected health information.
- An incident response process that can meet the reporting window you agreed to.
MSP BAA obligations: quick answers
What does a BAA legally require an MSP to do?
Use protected health information only as permitted, apply Security Rule safeguards, report incidents and breaches, bind subcontractors to equivalent terms, and return or destroy the data at termination. The required terms are at 45 CFR 164.504(e).
Does an MSP need a BAA with each healthcare client separately?
Yes. The agreement is between the MSP and each covered entity or business associate it serves.
What happens to protected health information in backups when a client leaves?
It stays in scope. If return or destruction is not feasible, the agreement’s protections continue for as long as the MSP retains the data.
Is signing a BAA enough to be HIPAA compliant?
No. The agreement is the contract. The Security Rule obligations, including the Security Risk Analysis, apply to the business associate directly. See HIPAA compliance for MSPs.