Data Security

Business Associate Agreements for Occupational Health Vendors: A Practical Guide

carefoundryESC Team · Occupational Health & Compliance · Jan 3, 2026 · 7 min read

Last reviewed Jan 3, 2026

A vendor's sales rep slides a "BAA" across the table and tells you to sign it before go-live. Do you actually need it — and is the one they handed you any good? This guide to the business associate agreement occupational health programs need answers both, because for an occupational health function the requirement is less obvious than it is for a hospital billing department.

You can't answer "do I need a BAA" until you answer "am I even the kind of entity HIPAA reaches." That gate gets skipped constantly.

This is general information, not legal advice. Confirm your covered-entity status and any specific agreement with counsel before you rely on it.

The two-part test

Before you chase paperwork, run these two questions in order.

1. Are you a covered entity or a business associate at all? HIPAA applies to health plans, health-care clearinghouses, and health-care providers who conduct HIPAA standard electronic transactions — chiefly electronic billing and claims. A purely in-house occupational-health clinic that never bills electronically may not be a covered provider under the Privacy Rule. If HIPAA doesn't reach you, its BAA requirement doesn't either. (Other rules still might — more on that below.)

2. Does the vendor create, receive, maintain, or transmit PHI on your behalf? If you are a covered entity and the vendor touches protected health information for you, you're into BAA territory.

Only when both answers are "yes" do you have a HIPAA obligation to get a signed agreement. Skipping question one is how employers end up signing (or demanding) BAAs they don't strictly need — or, worse, assuming they're exempt when they aren't.

Who counts as a business associate

HIPAA defines a business associate as a person or entity that, on behalf of a covered entity but not as a member of its workforce, creates, receives, maintains, or transmits protected health information to perform a function such as claims processing, data analysis, quality assurance, or billing — or that provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, or financial services involving PHI (45 CFR 160.103).

Read the verb "maintains" closely. A cloud or SaaS occupational-health platform that merely stores your records is a business associate even if no one at the vendor ever opens a file. There's no "we just hold the data, we don't look at it" exemption. If they house it, they're a business associate.

And it flows downstream. A business associate's subcontractors — the vendor's hosting provider, its offsite backup service — are themselves business associates and need their own written assurances.

When the agreement is legally required

Two rules require the contract, on two parallel bases.

A single, well-drafted BAA satisfies both. You don't need two documents; you need one that covers the ground below.

What the BAA must contain — a checklist

The mandatory terms come straight from 45 CFR 164.504(e)(2). Run a candidate agreement against this list; if a clause is missing, send it back.

If a vendor's template is silent on subcontractor flow-down or on return/destruction at termination, those are the two clauses I see missing most often. Don't wave them through.

The occupational-health carve-out most people miss

Not everything in an employee's occupational-health file is PHI.

The Privacy Rule's definition of protected health information expressly excludes "employment records held by a covered entity in its role as employer" (45 CFR 160.103, paragraph (2)(iii) of the PHI definition). Records you hold purely in your employer capacity may sit outside HIPAA's definition of PHI altogether. The line between "provider record" and "employment record" is genuinely fact-dependent and worth a conversation with counsel — but the takeaway is that "it's a medical record, therefore it's HIPAA PHI" is simply not a safe assumption in occ health.

That exclusion is also a trap for the opposite reason: it does not mean the data is unregulated.

HIPAA is not the only rule

OSHA governs employee medical and exposure records independently of HIPAA. Under 29 CFR 1910.1020, employee medical records must be preserved for at least the duration of employment plus 30 years (1910.1020(d)(1)(i)), and employee exposure records for at least 30 years (1910.1020(d)(1)(ii)). An "employee medical record" is one concerning an employee's health status made or maintained by a physician, nurse, or other health-care personnel (1910.1020(c)(6)(i)).

So a record can fall outside HIPAA's PHI definition and still carry a 30-plus-year OSHA retention mandate. When you evaluate a vendor, ask how they handle that retention window and end-of-contract data return — a BAA's "destroy at termination" clause and OSHA's decades-long retention duty have to be reconciled, not left to collide.

What happens without a BAA

Disclosing PHI to a vendor without the required assurances is itself a Privacy Rule violation — the missing agreement is a standalone finding, not just a technicality that surfaces after a breach.

Civil money penalties are tiered by culpability under 45 CFR 160.404. The statutory bases run from $100 per violation for "did not know" up to a minimum of $50,000 per violation for uncorrected willful neglect, with a regulation-text annual cap of $1,500,000 for all violations of an identical provision. One caveat that changes the exposure math: in 2019 HHS issued a Notification of Enforcement Discretion applying substantially lower annual caps to the three less-culpable tiers (roughly $25,000, $100,000, and $250,000, versus the $1.5M in the rule text) — confirm the current caps with HHS before relying on any single number.

All of these amounts are inflation-adjusted annually. The 2025 table at 45 CFR 102.3 ran from a $145 minimum per violation up to a $2,190,294 calendar-year cap. HHS updates that table each year through a Federal Register rule, so verify the current-year figures against the latest adjustment before you cite any specific dollar amount.

FAQ

Do I automatically need a BAA because I run an occupational-health clinic? No. First determine whether you're a HIPAA covered entity — generally, a provider that conducts standard electronic transactions like electronic billing. If you're not a covered entity, HIPAA's BAA requirement doesn't apply, though OSHA and state law still govern the records.

Does a cloud vendor that never looks at our data need a BAA? Yes, if you're a covered entity. Because the definition includes vendors that "maintain" PHI, a storage or SaaS provider is a business associate even if it never views the files (45 CFR 160.103).

Is one BAA enough for both the Privacy and Security Rules? Yes. One agreement covering the terms in 164.504(e)(2) satisfies both the Privacy Rule's contract requirement and the Security Rule's requirement for electronic PHI.


Sort out your covered-entity status first, then hold every vendor's agreement up against the checklist above. When you're evaluating an occupational-health platform — carefoundryESC included — ask to see the BAA early, and confirm it addresses subcontractor flow-down and long-horizon OSHA retention before you sign anything.

See carefoundryESC in action

Generate OSHA 300/300A/301 reports, track immunizations, and manage employee health from one HIPAA-aligned system.

Request a demo →
← Back to the blog