MSP BAA Obligations: What a Business Associate Agreement Commits You To

A Business Associate Agreement commits a managed service provider to five things: use protected health information only as the agreement permits, apply Security Rule safeguards to it, report security incidents and breaches to the client, bind its own subcontractors to the same terms, and return or destroy the data when the agreement ends. Those terms are set by 45 CFR 164.504(e). Signing is the easy part. Each clause has an operational cost the MSP absorbs.

The five clauses that carry real work

1. Permitted use and disclosure. The MSP may use protected health information only for the services in the contract. Using client data for its own analytics, benchmarking, or product development is outside the agreement unless the agreement says otherwise.

2. Safeguards. 45 CFR 164.504(e)(2)(ii)(B) requires appropriate safeguards. For a business associate this points back to the Security Rule directly, including the Security Risk Analysis at 45 CFR 164.308(a)(1)(ii)(A) covering the MSP’s own systems.

3. Incident and breach reporting. The MSP reports security incidents to the client, and reports breaches of unsecured protected health information under 45 CFR 164.410. Most agreements set a reporting window shorter than the regulation’s outer limit. Read the number in the contract, because that number is the one that binds.

4. Subcontractor flow-down. 45 CFR 164.308(b) and 164.502(e)(1)(ii) require the MSP to bind every subcontractor that touches protected health information to equivalent terms. A cloud backup provider, an offsite media vendor, or an outsourced night help desk each needs its own agreement.

5. Return or destruction at termination. When the agreement ends, protected health information is returned or destroyed if feasible. If it is not feasible, protections continue for as long as the MSP retains it. Backup retention is where this clause usually bites: data in a 90 day backup rotation is still in scope after the client leaves.

Clauses to read closely before signing

What to have in place before you sign the first one

MSP BAA obligations: quick answers

What does a BAA legally require an MSP to do?
Use protected health information only as permitted, apply Security Rule safeguards, report incidents and breaches, bind subcontractors to equivalent terms, and return or destroy the data at termination. The required terms are at 45 CFR 164.504(e).

Does an MSP need a BAA with each healthcare client separately?
Yes. The agreement is between the MSP and each covered entity or business associate it serves.

What happens to protected health information in backups when a client leaves?
It stays in scope. If return or destruction is not feasible, the agreement’s protections continue for as long as the MSP retains the data.

Is signing a BAA enough to be HIPAA compliant?
No. The agreement is the contract. The Security Rule obligations, including the Security Risk Analysis, apply to the business associate directly. See HIPAA compliance for MSPs.