What a BAA Means When You Hire an IT Provider for a Medical, Dental or Therapy Office

If you run a medical, dental or therapy office in the Portland area, an IT provider will eventually put a Business Associate Agreement in front of you, or you will realize you should be asking for one. This guide explains the BAA for IT providers in plain English: what the agreement is, why your IT company is usually covered by it, what it should say and what it cannot do for you. It is general information, not legal advice. Your attorney or compliance advisor answers the legal questions.

What a Business Associate Agreement Actually Is

HIPAA applies directly to covered entities, which include most health care providers that bill electronically, such as medical practices, dental practices and many therapy offices. When a covered entity hires an outside company to do work that involves protected health information (PHI), that company is a business associate. HIPAA requires the two sides to sign a written contract, the Business Associate Agreement or BAA, before the vendor handles PHI. The agreement sets out what the vendor may do with PHI and which protections it must keep in place.

Why Your IT Provider Is Usually a Business Associate

A business associate is a vendor that creates, receives, maintains or transmits PHI for a covered entity. An IT provider that manages your workstations, servers, backups, email or remote access can reach the systems where patient records live. Even when a technician never opens a chart, maintaining or having access to systems that store electronic PHI generally puts the vendor in business associate territory. The same goes for other vendors in the chain, such as a backup service or a cloud host.

The practical rule is simple: if a vendor will be near patient data, ask for a BAA before the work starts, not after. Accounting and legal offices are usually not covered entities themselves, but they can be business associates when they handle PHI on behalf of a practice.

What a BAA With an IT Provider Should Cover

A BAA is a contract, and the details matter. In general it should address:

  • Permitted uses. The vendor may use PHI only to perform the services and as the agreement allows.
  • Safeguards. The vendor must use appropriate administrative, physical and technical safeguards for electronic PHI. For an IT provider that usually means access controls such as multi-factor authentication (MFA), encryption of devices and backups, and logging of who accessed what.
  • Reporting. The vendor must tell the practice about security incidents and breaches involving PHI. HIPAA sets an outer limit of 60 days after discovery for a business associate to notify the covered entity, and an agreement can require faster notice.
  • Subcontractors. Any subcontractor that handles PHI for the vendor must agree in writing to the same restrictions.
  • Return or destruction. When the relationship ends, PHI is returned or destroyed where feasible.
  • Termination. The practice can end the contract if the vendor materially breaches it.

The practice generally remains responsible for deciding whether an incident requires notice to patients, which is why the reporting clause matters.

What a BAA Does Not Do

Signing a BAA does not make your practice HIPAA compliant, and it does not make the vendor secure. It is a required agreement, not a safeguard. Your practice still needs its own risk analysis, written policies, staff training and technical controls that actually work. Our HIPAA security risk analysis guide walks through the risk analysis step by step. A BAA also does not replace legal advice. If an agreement raises questions, ask your attorney.

Questions to Ask an IT Provider Before You Sign

  1. Will you sign a BAA before you touch any system that holds patient data?
  2. Which tools and subcontractors will touch PHI, such as remote access, backup and email security, and will each one sign a BAA?
  3. How do you control and review administrator access? Look for MFA, separate admin accounts and logging.
  4. How are laptops, servers and backups encrypted, and how often are backups tested?
  5. How will you tell us about a security incident, and who is our contact?
  6. What happens to our data and our passwords if we leave?

A provider who hesitates on the first question is telling you something.

How PDX IT Handles BAAs

PDX Information Technology Services (PDX IT) is a managed-services-only IT provider in Portland. We will sign a Business Associate Agreement (BAA) when your practice asks for one. Steve Shaff, the owner, is your direct point of contact, with a team of backup technicians behind him. We work on a monthly per-user plan and do not offer hourly or break-fix support. We are an IT provider, not a law firm, and nothing here is legal advice.

For the day-to-day work, see our page on managed IT for healthcare in Portland. For the HIPAA-focused safeguards, see HIPAA IT services in Portland, and for broader requirements such as PCI DSS and the Oregon Consumer Privacy Act, see our IT compliance services.

On-site support runs from Hillsboro to Gresham to Wilsonville to Vancouver, WA, including Portland, Beaverton and Clackamas, with no trip fee. Remote support is available anywhere in the U.S.

BAA Questions and Answers

Does my practice need a BAA with its IT provider?

Generally yes, if the provider creates, receives, maintains or transmits protected health information for your practice. An IT company that manages systems holding patient records usually falls into that group. Ask your attorney or compliance advisor about your specific situation.

Does signing a BAA make my practice HIPAA compliant?

No. A BAA is one required agreement. Your practice still needs its own risk analysis, written policies, staff training and working technical safeguards such as multi-factor authentication, encryption and tested backups.

Will PDX IT sign a BAA?

Yes. We will sign a Business Associate Agreement (BAA) when your practice asks for one. We are a managed-services-only provider, so the agreement goes with an ongoing monthly plan, not hourly or break-fix work.

Do accounting and legal offices need a BAA?

Usually they are not covered entities themselves. They can become business associates if they handle protected health information on behalf of a practice. If that applies to your office, ask your attorney.

Talk to Steve About Your BAA Questions

Call 971-331-4871 or email sales@pdxittech.com to talk it through, or book a free IT assessment. Steve Shaff is your direct point of contact.

Get In Touch

Share On Social Media

Other Recent Blog Articles

AI for Construction Companies in 2026: Jobsite Productivity Without Leaking Bids or Plans

October 1, 2026

Practical AI for construction companies in the Portland metro: where AI helps (estimating drafts, RFIs, scheduling), what never leaves the job trailer (bids, plans, owner data), and how managed IT keeps field phones from becoming shadow AI.

AI Acceptable Use Policy for Small Business: A Practical Template for 2026

September 29, 2026

A practical AI acceptable use policy for Portland metro SMBs: what to approve and ban, never-paste rules, shadow AI, human review, rollout and training, plus a one-page template your team will actually follow.

What to Look for in Managed IT Services: A Portland Buyer’s Checklist

September 28, 2026

2026 buyer’s checklist for managed IT services in Portland: monitoring, help desk, on-site coverage, security, backups, pricing clarity, and exit terms.