CYBER DENTAL 2.0
(954) 639-7049

Business associate agreements for dental practices

If they can touch ePHI, they probably need a BAA. The MSP is one of those vendors. The PMS publisher may be another.

Journal · Legal, Plain English · F·02 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida

Short answer: A Business Associate Agreement (BAA) is a required HIPAA contract between a dental practice and any vendor that creates, receives, maintains or transmits PHI on its behalf. Your MSP, cloud backup provider, email platform, cloud PMS and shredding or billing vendors typically need one. The BAA sets permitted uses, required safeguards, breach reporting, subcontractor flow-down and what happens to PHI at termination.

At a glance

Required when A vendor handles PHI on the practice's behalf
Typical dental BAAs MSP, backup/cloud, email platform, cloud PMS, billing, shredding, answering service
Core terms Permitted uses, safeguards, breach reporting, subcontractors, return/destruction, termination
Practice's duty Obtain satisfactory assurances; remain responsible as covered entity
Vendor's duty Comply with Security Rule as a business associate; report incidents

General information, not legal advice.

What is a business associate?

A business associate is a person or entity that, on behalf of a covered entity, creates, receives, maintains or transmits PHI to perform a function or service, or that provides certain services involving PHI. Since the 2013 Omnibus Rule, business associates are directly liable for compliance with the HIPAA Security Rule and for certain Privacy and Breach Notification obligations.

Which dental vendors typically need a BAA?

Vendor type Why
Managed IT provider (MSP) Has access to systems holding ePHI
Cloud backup / hosting Stores ePHI
Email and productivity platform Transmits and stores ePHI
Cloud practice-management or imaging vendor Stores and processes ePHI
Billing / claims / revenue-cycle company Handles PHI to perform services
Shredding and records-disposal service Handles PHI media
Answering service, patient-communication tools Handle PHI in calls and messages
Dealer or installer technicians If they can access ePHI during the work

Exceptions exist (for example, certain disclosures between health care providers for treatment), so confirm edge cases with counsel.

What must a BAA contain?

Under 45 CFR 164.504(e) and 164.314(a), a BAA must at minimum:

  1. Establish the permitted and required uses and disclosures of PHI.
  2. Require the business associate to use appropriate safeguards and comply with the Security Rule for ePHI.
  3. Require reporting of unauthorized uses or disclosures, security incidents and breaches, ideally with a defined timeframe.
  4. Require subcontractors that handle PHI to agree to the same restrictions.
  5. Support the covered entity in meeting patient access, amendment and accounting obligations.
  6. Provide for return or destruction of PHI at the end of the relationship, where feasible.
  7. Allow the covered entity to terminate for a material violation.

HHS publishes sample BAA provisions as a reference.

What should a practice look for beyond the minimum?

  • A breach-reporting clock measured in days, not "without unreasonable delay" alone. The practice itself may face a short statutory clock. See Florida data-breach notification for dental practices.
  • Clear scope: which systems and data are covered.
  • Subcontractor list or notice when it changes.
  • Data return and exit terms: how you get your data back, in what format and when.
  • Insurance and indemnity appropriate to the risk.

Who is responsible if a vendor fails?

Both. The vendor is directly liable for its own HIPAA obligations; the practice remains responsible as the covered entity, including for choosing vendors who give satisfactory assurances. A BAA does not move the risk off the practice.

How does CyberDental handle BAAs?

CyberDental signs a BAA with every practice it serves, before it works on systems that contain ePHI. See How to become a CyberDental practice and What "HIPAA-compliant MSP" means.

What are common BAA mistakes?

  • None at all, because "it's a friend" or "it's just IT." See The nephew-does-the-IT myth.
  • A BAA signed once and never reviewed.
  • A vendor that touches PHI that nobody realized was a business associate.
  • No inventory of which vendors have BAAs.

Frequently asked questions

Does my IT company need to sign a BAA?

Yes, if it can create, receive, maintain or transmit PHI on your behalf, which a managed IT provider with access to your systems typically can.

Do I need a BAA with Microsoft or Google for email?

If PHI is stored or sent through the platform, you need a BAA that covers it, and your plan must be configured accordingly. Confirm current terms for your licensing.

Who is liable if my vendor causes a breach?

The vendor is directly liable for its own HIPAA obligations, and the practice remains responsible as the covered entity. A BAA does not eliminate the practice's responsibility.

Sources and further reading

Related in the Journal

About CyberDental

CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.

CALL TEXT