MedSpaForms

ANSWER

Do I need a business associate agreement with my software?

Updated 2026-08-25 · MedSpaForms

The short answer

Yes, if the vendor creates, receives, maintains or transmits protected health information on your behalf. Under HIPAA, that covers practice management systems, online booking and intake, EHRs, cloud hosting, e-signature tools, texting and email marketing platforms, billing services and IT support — even when data is encrypted and the vendor holds no key. The agreement must be signed before any patient data reaches the platform.

Which vendors are business associates?

The HIPAA Privacy Rule defines a business associate as a person or entity that creates, receives, maintains or transmits protected health information on behalf of a covered entity, and it requires satisfactory assurances in the form of a written contract at 45 CFR 164.502(e), with the required contract terms set out at 45 CFR 164.504(e). The Security Rule imposes a parallel requirement for electronic PHI at 45 CFR 164.308(b).

In a typical med spa, that sweeps in more vendors than owners expect: the practice management or EHR platform, online booking and digital intake forms, the e-signature tool used for consents, cloud storage where before-and-after photographs live, the SMS reminder service, email marketing if the list is built from patient records, billing and coding services, transcription, shredding and document destruction, outsourced IT and managed service providers, answering services, and any AI scribe or note-generation tool.

HHS guidance is explicit that a cloud service provider is a business associate even when it stores only encrypted ePHI and never holds the decryption key, because it maintains the data on your behalf. Encryption reduces breach risk; it does not remove the contract requirement.

What about the conduit exception?

The conduit exception is real but narrow. It covers entities that merely transport information without accessing it other than randomly or incidentally — the classic examples HHS gives are the postal service, private couriers and their electronic equivalents such as internet service providers acting purely as transmission channels.

Storage is the dividing line. HHS has stated that an entity maintaining PHI on behalf of a covered entity is a business associate even if it never actually views the data, because persistence of custody is different from transient transmission. A messaging platform that retains message history, a booking tool that stores appointment records, or a form service that keeps submissions is storing, not conduiting.

Vendor typeBAA required?Reason
EHR / practice managementYesCreates and maintains PHI
Online intake and bookingYesReceives and stores PHI
Cloud storage for clinical photosYesMaintains PHI, encrypted or not
E-signature platform for consentsYesReceives and retains PHI
SMS / email reminder platformYesTransmits and typically stores PHI
Outsourced IT with system accessYesCan access PHI incidental to service
Internet service providerGenerally noPure transmission conduit
Janitorial or landscapingGenerally noNo PHI access beyond incidental

What must the agreement actually say?

45 CFR 164.504(e) sets required elements: permitted and required uses and disclosures of PHI; a prohibition on further use or disclosure except as permitted or required by law; appropriate safeguards including Security Rule compliance for ePHI; reporting of unauthorized use or disclosure, security incidents and breaches; flow-down obligations binding subcontractors to the same terms; support for individual rights of access, amendment and accounting of disclosures; making internal practices and records available to HHS; return or destruction of PHI at termination where feasible; and termination for material breach.

Clicking "I agree" on a vendor's standard terms of service is not a BAA. Many platforms offer a BAA only on specific plan tiers, or only on request through a compliance portal, and using the consumer tier with patient data is a common and expensive mistake.

What this means for your paperwork

Build a vendor inventory listing every system that touches patient data, the PHI elements involved, whether a BAA is executed, the signature date, the renewal date and where the signed copy is stored. Review it at least annually and whenever you switch tools, because BAAs expire, vendors get acquired, and free-tier migrations silently drop the agreement.

Pair it with the rest of the HIPAA file a regulator asks for: a current Security Risk Analysis, written privacy and security policies, workforce training records, a breach response procedure, your Notice of Privacy Practices with acknowledgements, and separate authorizations for marketing uses of photographs. A signed BAA does not transfer your liability — under the enforcement rules, a covered entity that knew of a pattern of breach by a business associate and failed to act remains exposed.

Related questions

This answer is educational and is not legal or medical advice. Requirements vary by state and change over time — verify with your own legal and clinical advisors before applying anything here in practice.