Skip to content
Hipsana

Articles / Records, patients, and staff

Does Your Dental Practice Need a BAA, and With Which Vendors? (2026)

A North Carolina clinic gave a vendor the X-ray films of 17,300 patients to recycle for the silver. No contract, just a phone call. That missing piece of paper cost it $750,000. The problem was not the recycling; it was handing patient records to a vendor without a business associate agreement (BAA), the contract HIPAA requires first. If a company creates, receives, stores, or transmits your patients' data on your behalf, you need a signed BAA. Here is which vendors qualify, how to get one, and what skipping it costs. Vendor agreements are one layer of the four federal rules a dental practice answers to.

This article explains when a dental practice needs a Business Associate Agreement, and with which vendors. It is general information, not legal advice for your specific situation. For that, consult a healthcare attorney or a qualified HIPAA compliance professional.

Before you go vendor by vendor, it helps to see where your practice actually stands. The free HIPAA Scorecard checks your BAAs and the other core Security Rule controls that line up with the issues OCR raises most, then scores your practice out of 100. A starting point, not a full audit. About three minutes. Check my practice →

What a BAA is, and what HIPAA actually requires

A business associate agreement, or BAA, is a written contract between your practice and any outside company that handles protected health information on your behalf. HIPAA calls that company a business associate (45 CFR § 160.103). The rule is blunt about the order of operations: you may disclose patient data to a business associate only after it gives you satisfactory assurances, in writing, that it will protect the data (45 CFR § 164.502(e)).

The Security Rule says the same thing for electronic records, in its own words. A covered practice may let a vendor create, receive, maintain, or transmit electronic patient information only after obtaining written assurances that the vendor will safeguard it (45 CFR § 164.308(b)). Those assurances have required contents: the vendor must agree to follow the Security Rule, to report security incidents and breaches back to you, and to bind its own subcontractors to the same terms (45 CFR § 164.314(a)).

Under HIPAA, you may hand patient data to an outside company only after it signs an agreement promising, in writing, to protect it. No agreement, no data.

That last line is not a slogan. It is the part Raleigh Orthopaedic missed, and it is the part a checklist alone will not catch.

Which of your vendors need a BAA?

Start with one question for each vendor: does this company create, receive, store, or transmit our patients' information to do its job? If the answer is yes, it is almost certainly a business associate, and it needs a BAA. That phrase covers far more than the companies that obviously look at patient charts.

A typical dental office works with more business-associate vendors than most owners expect. Here is how the common dental-office vendors usually fall. Treat it as a starting map, not a substitute for checking each contract.

Vendor or serviceNeeds a BAA?Why
Practice-management or imaging software (PMS, EHR)YesHolds your whole patient database
Billing service or claims clearinghouseYesTransmits patient data to payers
IT or managed-services provider (MSP)Almost alwaysCan reach the systems holding patient data, even just to fix them
Cloud storage and backupYesStores patient data, even encrypted and unread
Email, messaging, or file-sharingIt dependsYes if it stores patient data; not a pure conduit
Records, film, or drive disposalYesHandles media that still holds patient data
Answering service or virtual receptionYesCan see names, numbers, appointments
AI scribes, chatbots, imaging toolsYesSame terms as any data vendor
How common dental-office vendors fall under HIPAA's business-associate rule. A starting map; check each contract.

Four of these have their own deep-dives: emailing patient data to a specialist, disposing of records that still hold patient data, whether ChatGPT can ever be a compliant vendor, and the five-question BAA test for an AI scribe.

The one real exception is narrow. A vendor that only carries data from one point to another without storing it, a true conduit such as the postal service or an internet provider, is not a business associate. OCR draws the line at whether the company maintains or can access the data, not at whether anyone there looks. That is why cloud storage and most email services are business associates and the phone company is not. When in doubt, treat the vendor as one and ask for the agreement. The opposite case also comes up: a few vendors that receive patient data will not sign a BAA at all, the way website analytics and advertising pixels such as Google Analytics and the Meta Pixel do, which is why website tracking pixels are their own HIPAA problem.

A few relationships do not need a BAA, and they trip people up. You do not sign one with another healthcare provider you share records with for a patient's treatment. That is why a dental lab you send impressions or images to for a case does not need one: under HIPAA's treatment exception, HHS and the ADA treat the lab as another health care provider, not your business associate. You also do not sign one with your own staff, who are workforce members rather than vendors. The treatment exception is narrow, though: if that lab or another provider does a non-treatment job for you, such as billing or records review, the BAA requirement comes back.

Your practice's facts can change the answer, so for your specific situation, consult a healthcare attorney or qualified compliance professional.

What one missing BAA can cost

The risk is not theoretical, and it is not only historical. In 2025, an attacker reached the records of roughly 1.2 million patients at Absolute Dental, a Nevada dental group, through a single compromised account belonging to its outside IT vendor. The practice agreed to a $3.3 million class-action settlement, entered without admitting wrongdoing and still pending a final approval hearing set for July 2026. A BAA would not have stopped that intrusion by itself, but the case is a plain lesson in why the contract matters: your vendor's access to your systems is your attack surface, and the BAA is where you pin down what that vendor must do to protect it.

Skipping the agreement is its own, separately punishable failure. Raleigh Orthopaedic Clinic reported a breach to the federal government in 2013, after it gave a vendor the X-ray films and records of 17,300 patients so the films could be digitized and the silver recovered. The arrangement was made over the phone, with no BAA. OCR's investigation did not turn on the recycling. It turned on the missing contract. The clinic paid $750,000 and accepted a corrective action plan that, among other things, required it to name one person responsible for getting a BAA from every vendor before any data is shared.

Excerpt from the HHS Office for Civil Rights resolution agreement with Raleigh Orthopaedic Clinic: the practice paid $750,000 for failing to execute a business associate agreement before giving a vendor the protected health information of 17,300 patients.
From the U.S. Department of Health and Human Services, Office for Civil Rights settlement with Raleigh Orthopaedic Clinic, P.A. (2016). Read the HHS announcement →

If a vendor breach does reach your patients, responding to a dental data breach is a separate process with its own deadlines. The cheaper path is to close the gap before anything goes wrong.

A missing or unsigned BAA is a common finding in HIPAA audits and breach investigations, and it is the kind of thing that is hard to spot from inside the office. The free HIPAA Scorecard checks for it, and for the other core controls that line up with the issues OCR raises most, in about three minutes. Check my practice →

How to get a BAA from a vendor

None of this needs a lawyer for the routine cases. It needs a list and a few emails.

List every vendor that touches patient data

Walk through your software and your service providers, plus anyone with access to your systems or records. The IT company, the billing service, the cloud backup, the imaging platform: write them all down. Many practices have never made this list.

Ask each vendor for its BAA

Established vendors keep one ready and will send it when you ask. If a vendor does not know what a BAA is, treat that as a warning sign about how it handles patient data.

Read the three things it must contain

The agreement must require the vendor to safeguard the data, to report breaches and security incidents to you, and to hold its own subcontractors to the same terms (45 CFR § 164.314(a)). A BAA that quietly disclaims all of that is not doing its job.

Sign it before any data flows

The agreement has to be in place before you share anything. Signing one after a disclosure does not cure the disclosure, which is the exact timing the Raleigh settlement turned on.

Keep the list current and owned

Store the signed agreements with the vendor list, and review it whenever you add or change a vendor. Naming one person to own this was literally part of the corrective action OCR ordered.

Keeping track of which vendors have a signed BAA is also part of a real HIPAA risk analysis, the document the same enforcement office checks first. The two go together: the risk analysis is where you notice the gap, and the BAA is how you close it.

Not sure which of your vendors are missing one? The Scorecard runs through ten core Security Rule controls that line up with the issues OCR raises most, including signed BAAs, and scores where your practice stands. It is a starting point, not a full audit. Check my practice →

When a vendor will not sign, and other edge cases

A few situations come up often enough to plan for.

  • The vendor refuses, or will only sign on a tier you cannot afford: Then you cannot use it for anything involving patient data. No privacy setting or paid add-on substitutes for the contract; find a vendor that will sign.
  • "We will send you our BAA": That is normal and fine. Read it anyway. The vendor's version still has to meet the required contents, and some are written to protect the vendor more than your patients.
  • Subcontractors behind your vendor: You do not sign with them directly. Your vendor is responsible for binding its own subcontractors, such as the data center behind your cloud software, to the same terms (45 CFR § 164.308(b)). The chain has to hold the whole way down.
  • Agencies you are required to report to: Sharing data because the law requires it, such as a report to a state board, is not a business-associate relationship and does not need a BAA.

One change is on the horizon. A proposed overhaul of the HIPAA Security Rule, published in January 2025, would add a step to all of this: practices would have to obtain written verification from each vendor that it has actually deployed the required technical safeguards, refreshed every year. As of July 2026 it is still a proposal, not law. Build your vendor list against today's rules, date it, and expect the bar to rise.

This is general information, not legal advice. Whether a particular vendor counts as a business associate can depend on the specific facts of the arrangement. When a relationship is unclear, confirm it against current HHS guidance or with qualified counsel before you share patient data.

About the author

Dolev Arama is Hipsana's founder. He's the one behind the Scorecard and the short risk reviews it produces. He is not an attorney, and Hipsana is a publisher and referral service, not a law firm or a healthcare provider. The writing here starts where the rules actually live (HHS, OCR, NIST) and gets checked against their current text before it goes up. Regulatory claims trace back to those sources, and figures name where they come from; anything that can't be verified is labeled rather than asserted. More about Hipsana →

Sources

  • HHS Office for Civil Rights, "$750,000 settlement highlights the need for HIPAA business associate agreements," resolution agreement with Raleigh Orthopaedic Clinic, P.A. (2016).
  • HHS Office for Civil Rights, "Guidance on HIPAA & Cloud Computing" (a cloud or transmission vendor that maintains protected health information is a business associate, encrypted or not).
  • HHS Office for Civil Rights, sample business associate agreement provisions (accessed June 2026).
  • American Dental Association, FAQs on HIPAA business associates (a dental lab is a healthcare provider; no BAA is needed to share PHI for treatment).
  • Jordan v. Absolute Dental Group, LLC, No. 2:25-cv-00986 (D. Nev.); $3.3 million proposed class-action settlement over a 2025 vendor-account breach; final approval hearing July 30, 2026.
  • 45 CFR § 160.103; § 164.502(e); § 164.504(e); § 164.308(b); § 164.314(a) (eCFR, current).
  • Federal Register, HIPAA Security Rule NPRM, January 6, 2025 (RIN 0945-AA22).

Frequently asked questions

Does a solo dental practice really need BAAs, or is that just for large groups?

It applies to every covered practice, regardless of size. The rules make no exception for solo or small offices, and OCR has settled cases with single-doctor practices. If a vendor handles your patient data, you need a BAA with it whether you run one chair or ten.

Is my practice-management or imaging software vendor a business associate?

Almost always, yes. That software stores or processes your patients' records, which is the definition of a business associate. Cloud-based dental software vendors typically have a BAA ready and will provide it on request.

Do I need a BAA with my IT or computer-support company?

Usually yes. If the company can access the systems that hold patient data, even only to maintain or repair them, it is a business associate under HIPAA. This is one of the most commonly missed agreements in small practices.

Do I need a BAA with my dental lab?

Usually no. HHS and the ADA treat a dental lab as its own healthcare provider, and sharing patient information with it for a patient's treatment falls under HIPAA's treatment exception, which does not require a BAA. You would need one only if a lab or other provider does a non-treatment job for your practice, such as billing or records review.

We email x-rays to specialists. Does the email provider need a BAA?

If the provider stores or routes that patient data through its systems, yes. Most standard email and file-sharing services that hold the message are business associates. A pure conduit that only transmits without storing, like your phone or internet carrier, is not.

What happens if a vendor refuses to sign a BAA?

Then you cannot use that vendor for anything involving patient data. No privacy toggle or paid tier substitutes for the contract. The practical answer is to choose a vendor that will sign one.

Is having a BAA the same as being HIPAA compliant?

No. A signed BAA is one required piece. You still need a risk analysis and written policies, with the safeguards themselves actually in place. The Scorecard checks the BAA alongside the other core controls, so you can see whether the broader foundation is in place, not just one control.

Can a BAA be backdated to cover data we already shared?

A BAA cannot be backdated. The agreement has to be in place before you disclose patient data to the vendor. Signing one afterward does not undo the earlier disclosure, which is exactly the timing the Raleigh Orthopaedic settlement turned on.

Not sure where your practice stands?

The free HIPAA Scorecard checks ten core Security Rule controls and scores your practice out of 100. About three minutes, no cost. A starting point, not a full audit.

Check my practice →