At the end of a full clinic day, a clinician still has unfinished notes. An AI scribe has recorded consultations, a billing service has received documentation, and a cloud platform has stored the resulting files. Each service may be useful, but each may also handle protected health information, or PHI, on the practice's behalf.
That is where HIPAA BAA requirements become practical. A Business Associate Agreement, or BAA, is the written contract that defines how a third party may handle PHI and what safeguards and operational duties apply. For clinicians in the US, the agreement is part of the legal foundation for using modern documentation, billing, storage, and transcription workflows. UK practices serving patients under UK GDPR face a separate data protection framework, but the same operational question remains important: which vendors can access patient information, and under what written terms?
The End-of-Day Charting Problem That Makes BAAs Real
A family physician finishes the last appointment and opens the day's documentation workflow. The consultation recording has gone to a cloud-based scribe. The structured note is copied into the EHR. A billing service later receives the note, while a cloud backup retains the working files. The clinician may see this as one charting process, but compliance depends on the separate vendors inside it.
The key question isn't whether each vendor describes itself as secure. It's whether the vendor creates, receives, maintains, or transmits electronic PHI for the practice. HHS states that a cloud service provider performing any of those functions for a covered entity or business associate requires a HIPAA-compliant BAA. Without one, the covered entity or business associate is violating the HIPAA Rules. HHS explains the cloud-provider BAA requirement.

The agreement follows the data
A BAA isn't bureaucratic decoration. It creates contractual controls for third-party PHI handling. The agreement should tell the vendor what it may do with the information, what it must do to protect it, and what happens when something goes wrong.
For a small practice, the vendor map often includes:
- Documentation services: Recording, transcription, note generation, task extraction, and clinical workflow support can all involve PHI.
- Billing services: Notes, diagnoses, procedure details, and patient identifiers may pass to a billing company.
- Storage and backup: A provider that stores ePHI may be a business associate even when it never displays the information to a human operator.
- Technical support: An IT contractor with access to systems containing PHI may need contractual controls appropriate to that access.
HHS says the BAA also supports the covered entity's own compliance duties. It doesn't transfer every HIPAA responsibility to the vendor. The practice still needs to decide whether a workflow is appropriate, limit access, train staff, and maintain oversight.
A practical review of HIPAA documentation workflows can help a practice identify each point where patient information enters, moves through, or leaves a documentation system. Practices that need a broader record of approvals, revisions, and compliance decisions may also benefit from document tracking compliance when managing their vendor files.
Understanding HIPAA BAA Requirements and Who Needs Them
A clinician records a visit with an ambient AI scribe, receives a draft note, and sends it into the practice's electronic record. The compliance question starts before the note reaches the chart: who handled the recording, transcript, and generated text, and did that organization act for the practice?
A business associate relationship usually exists when an outside organization performs a service for a covered entity and handles PHI in doing so. Covered entities include healthcare providers, health plans, and healthcare clearinghouses. The vendor's function matters more than its title or marketing. An AI scribe, billing company, data processor, cloud host, or technical support contractor may be a business associate if it handles PHI on the practice's behalf.
The Privacy Rule requires covered entities to establish written arrangements with business associates. The applicable standards appear in 45 CFR 164.502(e) and 45 CFR 164.504. HHS also describes the early compliance timeline. Covered entities with written contracts in place before October 15, 2002 could continue using those agreements until renewal or April 14, 2004, whichever came first. The general compliance date was April 14, 2003. These dates appear in HHS material on business associate arrangements.

Trace the patient-data path for each workflow. Record what the practice creates, where it sends the information, who can access it, and whether an outside party performs the service. Include consultation recordings, transcripts, generated notes, referrals, billing, backups, and technical support. Identify subcontractors that receive PHI, then classify the data as identifiable patient information or ePHI.
A privacy policy or security page does not replace a BAA. Request the written agreement and keep the executed copy with the service record, including the applicable version for each active workflow. A HIPAA documentation workflow guide can help clinicians map where recordings and notes enter, move through, and leave the documentation process. Practices that track approvals and contract revisions may also use document tracking compliance.
Employees of the practice are not business associates just because they work with PHI. The distinction is the external organization performing a covered function for the practice. HHS explains that the BAA must define the business associate's duties and require safeguards for PHI. See HHS answers common business associate questions.
Required BAA Clauses and Contractual Obligations
A compliant BAA should describe the actual workflow, not just repeat broad language about confidentiality. HHS sample provisions require the agreement to spell out permitted and required uses and disclosures of PHI, prohibit unauthorized use or disclosure beyond the agreement or law, and require appropriate safeguards.
The contract should also require the business associate to report non-permitted uses and disclosures, including breaches of unsecured PHI. For a cloud or SaaS service that creates, receives, maintains, or transmits ePHI, the BAA must contractually require compliance with the Security Rule. That makes the vendor's operational safeguards part of the contractual model.
| Clause Category | AI Scribe/Voice | Billing Service | Cloud Storage |
|---|---|---|---|
| Permitted uses | Recording, transcription, note generation, task extraction, and other defined documentation functions | Claims preparation, coding support, patient-account work, and other agreed billing functions | Storage, retrieval, backup, and defined technical administration |
| Safeguards | Controls for recordings, transcripts, generated notes, access, and output | Controls for clinical and billing records handled by staff and systems | Controls for stored and transmitted ePHI, including access management |
| Incident reporting | Reporting of unauthorized access, disclosure, or loss involving recordings or generated content | Reporting of incidents involving claims, notes, or patient-account information | Reporting of incidents involving stored or transmitted ePHI |
| Subcontractor flow-down | Applies to transcription, processing, hosting, or support subcontractors | Applies to downstream billing or technology providers | Applies to infrastructure, support, and storage subcontractors |
| Patient-data duties | Support for access, copies, corrections, and other assigned duties | Support for records or information the vendor holds for the practice | Ability to provide or return stored ePHI as assigned |
| End of service | Return or destruction of recordings, transcripts, notes, and related PHI where required | Return or destruction of billing records and PHI | Return or destruction of stored data, with continuing protections where required |
Privacy limits and operational duties
The privacy clauses answer, “What may the vendor do?” They should be specific enough to prevent the vendor from repurposing PHI outside the contracted service. For an AI documentation workflow, the practice should understand whether the agreement covers the recording, transcript, generated note, extracted tasks, and any billing suggestions.
The operational clauses answer, “What must the vendor do when the practice needs something?” HHS guidance gives the example of providing ePHI copies to the covered entity or the individual when the BAA assigns that duty. This shows that BAAs allocate work, not just privacy promises. HHS guidance on online tracking and business associate duties explains these obligations.
Practical rule: A BAA should describe the service the vendor actually performs. A generic promise to “protect information” leaves too much of the workflow undefined.
Cloud-Based AI Tools and the BAA Question
At the end of a clinic day, a clinician dictates an encounter while an ambient AI tool captures the conversation, sends audio to cloud processing, produces a transcript, and returns a draft note. The note may also include follow-up tasks or suggested billing codes. Whether the platform keeps a permanent copy is only one part of the review. If it receives, transmits, stores, transforms, or displays PHI at any stage, the practice must understand that workflow and the related BAA obligations.

Paper-based scribing and ambient recording can support the same documentation goal, but the controls are different. A paper arrangement may rely on physical access restrictions, confidentiality terms, and secure chart handling. An ambient workflow requires the written BAA to address recording, transmission, processing, transcription, generated notes, retention, access, and any subcontractors involved in those steps.
A compliance statement does not answer the BAA question
A vendor's claim that a product is HIPAA compliant can help with initial screening. It does not replace reviewing the agreement or checking how staff will use the tool. The BAA should assign responsibilities for the actual clinical workflow, while the practice remains responsible for its own HIPAA duties.
Review the agreement against the way documentation happens in the exam room:
- Does it cover audio, transcripts, generated notes, extracted tasks, and billing suggestions?
- Does it limit use of that information to the contracted service?
- Does it identify hosting or processing subcontractors and require appropriate obligations to flow to them?
- Does it set expectations for incident and breach reporting?
- Does it explain how the practice can receive or recover ePHI?
- Does the configured product match the services described in the agreement?
An offline recording mode may reduce reliance on a live connection during a consultation. It does not end the data review. Determine what happens when the device synchronizes, when audio is uploaded, and when the transcript or note is stored. Web and mobile access can fit clinical routines, but convenience does not remove the need to map each data transfer.
The same point appears in the guidance on whether Teams is HIPAA compliant. A product name or security label cannot, by itself, establish that the BAA covers the practice's documentation workflow.
Practical BAA Compliance Checklist for Clinicians
Small practices rarely need a large compliance department to manage BAAs well. They do need a repeatable process that connects contracts to real workflows. The following checklist is designed for a practice owner, clinical lead, or administrator evaluating an AI scribe, EHR connection, billing service, or storage provider.

Six checks before patient data moves
Identify the vendor's PHI role. Ask whether the service creates, receives, maintains, or transmits PHI. An AI scribe may handle PHI even if the clinician only sees the final note.
A practice can keep executed BAAs in one controlled folder with the vendor name, service description, signing date, responsible person, and review notes. An evidence system can also help streamline HIPAA audit evidence automation, especially when a practice needs to show how it approved vendors and followed up on open questions.
Questions for each vendor type
For an AI scribe, ask whether the BAA covers audio, transcripts, generated notes, tasks, code suggestions, retention, and processing subcontractors. For an EHR integration, ask which information moves in each direction and whether the agreement covers the integration service as configured.
For a billing service, ask whether the agreement assigns responsibility for responding to patient or practice requests for information. For cloud storage, ask whether the BAA covers backup copies, support access, restoration, and deletion at the end of the relationship.
A BAA doesn't absolve the practice of oversight. It makes the vendor's obligations clearer and more enforceable while the covered entity remains responsible for its own HIPAA program.
Evaluating AI Scribe Vendors for BAA Compliance
A clinician finishes a visit, reviews the draft note, and sends it to the EHR. That simple sequence may involve audio, transcription, speaker separation, note generation, task extraction, coding suggestions, patient instructions, storage, and export. Vendor review should map that complete workflow before any patient information is uploaded. The BAA belongs in the product evaluation, not in a folder opened after implementation.
A useful comparison starts with the service's actual data handling. Can the practice review the BAA in advance? Does it cover recordings, transcripts, generated notes, retained session archives, and downstream processors? Are audit logs available for relevant account activity? Can staff transfer documentation into the EHR without creating an unapproved copy or data path? These questions connect contract language to daily charting.
For clinicians assessing HIPAA-compliant note-taking apps, PatientNotes provides one example. It offers a BAA at no extra cost, states that it is HIPAA compliant, and provides encryption in transit and at rest with audit logs. Its workflow includes web recording and a native iOS app with offline recording. It supports notes and tasks in the clinician's own language, templates across 37 specialties, and an AI template builder, as described on its specialty template page. ICD-10, CPT, and CDT suggestions apply to US billing only.
A short vendor review should also test operational fit:
- Can the practice see and assess the BAA before uploading patient data?
- Does the agreement match the configured service, including retention and processing?
- Does the vendor address subcontractors and their access to PHI?
- Can the practice obtain account activity records when investigating an issue?
- Does the subscription include the BAA, or is a separate charge introduced?
PatientNotes connects directly with one EHR. Other EHR workflows use copy and paste, and the service is not designed for health systems that require advanced enterprise integration. Pricing is $70 per user per month when billed monthly or $50 per user per month when billed annually, with a 7-day free trial, no credit card required, and a 14-day money-back guarantee, according to the PatientNotes pricing page. There is no enterprise tier and no sales call.
Those terms help a small practice understand the purchase before changing its documentation workflow. They do not replace legal review. They give the practice enough visibility to compare the BAA with the service clinicians will use.
Common Misconceptions About BAA Requirements
A practice manager may keep a vendor's privacy policy in a compliance folder and assume the requirement is covered. Another may accept a vendor's HIPAA compliance statement without asking for a signed agreement. Both approaches leave a gap because a privacy notice isn't a BAA.
A BAA is more than a privacy memo
A BAA is a written contract with defined limits and duties. It should explain permitted and required PHI uses, prohibit unauthorized reuse or disclosure, require safeguards, and address reporting when the vendor uses or discloses PHI improperly.
The agreement also has operational force. If it assigns the vendor responsibility for providing ePHI copies, the vendor must be able to perform that duty. If it requires subcontractor protections, the vendor needs a process for extending those obligations down the service chain.
A signed agreement is evidence of an arrangement. It isn't evidence that the workflow is configured correctly.
A compliance claim doesn't replace the agreement
A vendor can have strong security controls and still need a BAA when it handles PHI for a covered entity. The BAA and the safeguards serve different purposes. The contract defines obligations between the parties, while the technical and administrative controls help the parties carry them out.
A small practice should also avoid assuming that a vendor's standard contract covers every product. The BAA should match the service being used, including mobile recording, cloud processing, integrations, retention, and support access. If the vendor refuses to sign a BAA for a service that handles PHI, the practice should keep PHI out of that service.
A UK-based vendor can still need a US agreement
A UK-based company serving US clinicians doesn't become exempt from HIPAA because it operates in the UK. If it handles PHI for a US covered entity, the BAA analysis still applies. UK GDPR considerations may exist alongside HIPAA, but they don't replace the US contractual requirement.
The practical answer is manageable. Map the data, ask for the BAA before launch, read the permitted-use and incident clauses, confirm subcontractor coverage, and keep the signed agreement with the vendor record. Clinicians who want to compare documentation workflows can review the PatientNotes note-taking resources and then check whether the service fits the practice's actual EHR and recording process.
PatientNotes provides a HIPAA-compliant AI scribe with a BAA included at no extra cost, offline recording through its native iOS app, specialty templates, and copy-and-paste support for EHRs other than Semble. Visit PatientNotes to review the workflow, pricing, and free trial before patient data is introduced.



