Business associate agreements for dental practices
If they can touch ePHI, they probably need a BAA. The MSP is one of those vendors. The PMS publisher may be another.
Journal · Legal, Plain English · F·02 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: A Business Associate Agreement (BAA) is a required HIPAA contract between a dental practice and any vendor that creates, receives, maintains or transmits PHI on its behalf. Your MSP, cloud backup provider, email platform, cloud PMS and shredding or billing vendors typically need one. The BAA sets permitted uses, required safeguards, breach reporting, subcontractor flow-down and what happens to PHI at termination.
At a glance
| Required when | A vendor handles PHI on the practice's behalf |
| Typical dental BAAs | MSP, backup/cloud, email platform, cloud PMS, billing, shredding, answering service |
| Core terms | Permitted uses, safeguards, breach reporting, subcontractors, return/destruction, termination |
| Practice's duty | Obtain satisfactory assurances; remain responsible as covered entity |
| Vendor's duty | Comply with Security Rule as a business associate; report incidents |
General information, not legal advice.
What is a business associate?
A business associate is a person or entity that, on behalf of a covered entity, creates, receives, maintains or transmits PHI to perform a function or service, or that provides certain services involving PHI. Since the 2013 Omnibus Rule, business associates are directly liable for compliance with the HIPAA Security Rule and for certain Privacy and Breach Notification obligations.
Which dental vendors typically need a BAA?
| Vendor type | Why |
|---|---|
| Managed IT provider (MSP) | Has access to systems holding ePHI |
| Cloud backup / hosting | Stores ePHI |
| Email and productivity platform | Transmits and stores ePHI |
| Cloud practice-management or imaging vendor | Stores and processes ePHI |
| Billing / claims / revenue-cycle company | Handles PHI to perform services |
| Shredding and records-disposal service | Handles PHI media |
| Answering service, patient-communication tools | Handle PHI in calls and messages |
| Dealer or installer technicians | If they can access ePHI during the work |
Exceptions exist (for example, certain disclosures between health care providers for treatment), so confirm edge cases with counsel.
What must a BAA contain?
Under 45 CFR 164.504(e) and 164.314(a), a BAA must at minimum:
- Establish the permitted and required uses and disclosures of PHI.
- Require the business associate to use appropriate safeguards and comply with the Security Rule for ePHI.
- Require reporting of unauthorized uses or disclosures, security incidents and breaches, ideally with a defined timeframe.
- Require subcontractors that handle PHI to agree to the same restrictions.
- Support the covered entity in meeting patient access, amendment and accounting obligations.
- Provide for return or destruction of PHI at the end of the relationship, where feasible.
- Allow the covered entity to terminate for a material violation.
HHS publishes sample BAA provisions as a reference.
What should a practice look for beyond the minimum?
- A breach-reporting clock measured in days, not "without unreasonable delay" alone. The practice itself may face a short statutory clock. See Florida data-breach notification for dental practices.
- Clear scope: which systems and data are covered.
- Subcontractor list or notice when it changes.
- Data return and exit terms: how you get your data back, in what format and when.
- Insurance and indemnity appropriate to the risk.
Who is responsible if a vendor fails?
Both. The vendor is directly liable for its own HIPAA obligations; the practice remains responsible as the covered entity, including for choosing vendors who give satisfactory assurances. A BAA does not move the risk off the practice.
How does CyberDental handle BAAs?
CyberDental signs a BAA with every practice it serves, before it works on systems that contain ePHI. See How to become a CyberDental practice and What "HIPAA-compliant MSP" means.
What are common BAA mistakes?
- None at all, because "it's a friend" or "it's just IT." See The nephew-does-the-IT myth.
- A BAA signed once and never reviewed.
- A vendor that touches PHI that nobody realized was a business associate.
- No inventory of which vendors have BAAs.
Frequently asked questions
Does my IT company need to sign a BAA?
Yes, if it can create, receive, maintain or transmit PHI on your behalf, which a managed IT provider with access to your systems typically can.
Do I need a BAA with Microsoft or Google for email?
If PHI is stored or sent through the platform, you need a BAA that covers it, and your plan must be configured accordingly. Confirm current terms for your licensing.
Who is liable if my vendor causes a breach?
The vendor is directly liable for its own HIPAA obligations, and the practice remains responsible as the covered entity. A BAA does not eliminate the practice's responsibility.
Sources and further reading
Related in the Journal
- What "HIPAA-compliant MSP" means (and does not)
- HIPAA for dental offices, in plain English
- Florida data-breach notification for dental practices
- CyberDental vs dealer IT (Patterson, Schein, and the truck)
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com