Rules
What does a HIPAA business associate agreement cover for a US healthcare marketing agency?
A HIPAA business associate agreement binds your marketing agency to specific clauses, breach timelines, and PHI safeguards. Here is what to check.
What to take away
- A HIPAA business associate agreement is required whenever a marketing agency creates, receives, maintains, or transmits protected health information on your behalf.
- The agreement must name permitted uses, ban the agency from reusing your PHI for its own purposes, and set breach notification deadlines.
- Your practice remains liable for the agency's mistakes, so the contract must include flow-down terms for subcontractors and Security Rule safeguards.
- Breach notice should arrive within days, not months, and the agency must handle notification if it caused the breach.
- Termination clauses must require return or destruction of PHI, with a certificate when destruction is chosen.
Who counts as a business associate under HHS rules
A marketing agency becomes a business associate when it handles protected health information to perform a service for your practice. That includes patient lists, call recordings, texting platforms, and analytics that touch identifiable data. The HHS Office for Civil Rights sets the standard in its Business Associates guidance.
The test is not the agency's label. A vendor that only receives de-identified data, or that works under a treatment, payment, or operations exception, may fall outside the definition. Most outreach vendors do not.
Your practice is a covered entity. The agency is a business associate. The BAA is the contract that makes the agency directly accountable to OCR for Privacy, Security, and Breach Notification rules.
A single campaign can create the relationship. If the agency sends appointment reminders, runs recall texts, or manages review requests using patient names, it needs a BAA before the first message goes out.
State law can add layers. California's Confidentiality of Medical Information Act, Washington's My Health My Data Act, and similar statutes in Texas, Florida, New York, and Illinois may impose stricter limits than HIPAA alone. A BAA does not override those rules.
Clauses a BAA must carry for a marketing agency
Required BAA clauses come from the HIPAA Privacy Rule and the HITECH Act. OCR expects the contract to describe what the agency may do with PHI, how it protects the data, and what happens when something goes wrong.
The table below lists the clauses a marketing agency BAA must include and what each one does for your practice.
| Required BAA clause | What it does for your practice |
|---|---|
| Permitted uses and disclosures | Limits the agency to the outreach work you hired it for |
| Prohibition on reuse | Stops the agency from using PHI for its own marketing, product, or AI training |
| Safeguards | Requires administrative, physical, and technical protections |
| Breach reporting | Sets the deadline and the contact for notice |
| Subcontractor flow-down | Passes the same duties to downstream vendors |
| Access and amendment support | Makes the agency help you answer patient requests |
| Return or destruction | Says what happens to PHI at the end of the contract |
| Accounting of disclosures | Lets you track where PHI went |
Each clause should name a responsible role, not just a department. A generic reference to "the agency" is hard to enforce when a campaign goes wrong.
Use a checklist before you sign. Our guide to casl healthcare email marketing compliance walks through the documents to collect, including the BAA, the security questionnaire, and the subcontractor list.
Permitted uses and disclosures and the prohibition on agency reuse
The BAA must state the exact purposes for which the agency may use PHI. For a marketing agency, that usually means patient outreach, appointment reminders, reputation management, and campaign measurement.
Anything outside that list is not permitted. The agency cannot use your patient list to build its own audience, enrich its database, or train a model. It cannot sell the data or share it with an ad platform without your written authorization.
OCR's HIPAA FAQs for Professionals explain that business associates may only use PHI as the contract allows. If the contract is silent, the use is not allowed.
Watch for broad language such as "and other business purposes." That phrase can swallow the prohibition on reuse. Ask for a closed list of purposes tied to your campaigns.
Patient communications need their own review. Texting and calling rules sit alongside HIPAA, and the consent and opt-out rules for patient texting are a common gap in vendor contracts.
If the agency wants to use aggregated or de-identified data for benchmarks, the BAA should say so and define the de-identification standard. Otherwise, assume the data stays identifiable and restricted.
Breach notification timelines practices should see in writing
The Breach Notification Rule lives in 45 CFR Subchapter C, alongside the Privacy and Security rules. The eCFR text is the source to cite when a vendor disputes a deadline.
A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach. That is the outer limit, not a target. Your BAA can and should require faster notice.
Practices should ask for notice within 24 to 72 hours for confirmed incidents. Early notice lets you start a risk assessment, involve counsel, and prepare patient communication before rumors spread.
The BAA should also say who calls whom. Name a security contact, a backup, and a method that works outside business hours. A breach discovered on a Friday night should not wait until Monday.
If the agency caused the breach, the contract should require the agency to handle notification to patients, OCR, and the media when thresholds are met. Your practice still carries the reporting duty, so the agency's work must be documented.
Include a duty to investigate and report root cause. A timeline without a cause analysis leaves you repeating the same incident with the same vendor.
Subcontractor and downstream vendor obligations
Marketing agencies rarely work alone. They use email platforms, texting gateways, call tracking tools, analytics providers, and freelance designers. Each one that touches PHI is a subcontractor.
The BAA must require the agency to sign a downstream agreement with every subcontractor that creates, receives, maintains, or transmits PHI on its behalf. The terms must be at least as strict as your BAA.
Ask for a current subcontractor list at signing and after any material change. If the agency adds a new texting vendor without telling you, your risk changes without your consent.
Call tracking is a frequent weak point. The call tracking comparison on this site shows what to verify when recordings and caller data are involved.
Flow-down clauses should cover breach notice, safeguards, and the prohibition on reuse. A subcontractor that can repurpose call recordings for its own product is a problem even if the main agency behaves well.
Your practice should have the right to object to a new subcontractor that cannot meet the terms. Without that right, the agency can expand its vendor stack at will.
What happens when an agency uses patient data for its own purposes
Using PHI for its own purposes is a breach of the BAA and, in many cases, a violation of HIPAA. The agency becomes directly liable to OCR for the unauthorized use.
Common examples include building a lookalike audience from your patient list, selling appointment data to a lead broker, or training a marketing model on patient messages. Each one exceeds the permitted uses in the contract.
When you discover the misuse, document it. Preserve logs, campaign exports, and written instructions. Then notify the agency in writing and demand an accounting of what was shared and with whom.
You may need to notify affected patients if the misuse creates a risk of harm. OCR evaluates the nature and extent of the data, who received it, and whether the risk was mitigated.
Remedies belong in the BAA. Ask for indemnification, audit rights, and the ability to terminate immediately for cause. Some practices add liquidated damages, though state law may limit those terms.
Report serious misuse to OCR. The agency's own breach notice obligations do not replace your duty as a covered entity to report a breach that affects your patients.
Termination, return, and destruction of PHI
The BAA must say what happens to PHI when the contract ends. The agency should return or destroy all PHI it holds, including backups, campaign exports, and derived files.
If return or destruction is not feasible, the BAA must extend the protections to the retained data and limit further use. That exception should be narrow and time bound.
Ask for a written certificate of destruction when records are shredded or wiped. For cloud systems, confirm that deletion covers replicas and disaster recovery copies.
Set a deadline, such as 30 days after termination, and withhold final payment until the certificate arrives. That gives the clause teeth.
Termination for cause should be available for a material breach that is not cured within a short window, often 10 to 30 days. Termination for convenience should also be defined so you are not locked in.
Keep a copy of the BAA and the destruction certificate for at least six years. OCR can ask for them during an investigation.
Security Rule safeguards that back the BAA
The BAA is only as strong as the safeguards behind it. The Security Rule requires administrative, physical, and technical protections for electronic PHI, and the Security Rule Guidance Material explains what OCR expects.
Administrative safeguards include a risk analysis, a written security plan, workforce training, and incident response procedures. Ask for the agency's most recent risk analysis summary.
Physical safeguards cover offices, servers, and devices. If the agency is fully remote, ask how laptops and home networks are protected.
Technical safeguards include access controls, audit logs, encryption in transit and at rest, and automatic logoff. Encryption is not optional in practice; it is the main defense if a device is lost.
Outreach tools add their own risks. The ONC privacy and security guidance covers health IT privacy and security for tools that handle patient data.
Put the safeguards in the BAA as obligations, not marketing claims. A vague promise that the agency keeps data safe is not enforceable. Name the controls, the review cadence, and the evidence you will receive.
Build a routine for reviewing vendor security each year. Our guide to common healthcare marketing strategy questions covers contract renewals, training, and audit evidence in one cycle.
For a broader view of the rules that touch outreach, see the healthcare marketing compliance guide. It maps HIPAA, TCPA, FTC health products guidance, and state privacy laws to common campaigns.
Common questions
Does every marketing agency need a BAA? No. An agency needs one only when it handles PHI for your practice. If it works solely with de-identified data or public information, a BAA may not be required, but the data must truly be de-identified.
How fast must an agency report a breach? HIPAA allows up to 60 days after discovery, but your BAA can require 24 to 72 hours. Push for the shorter window so you can assess risk and notify patients on time.
Can an agency use our patient list for its own marketing? No. The BAA must prohibit use of PHI for the agency's own purposes, including audience building, product development, and model training. Any such use is a breach of the contract and HIPAA.
What happens if a subcontractor causes a breach? The agency remains responsible to you under the BAA. The subcontractor must have a downstream agreement with terms at least as strict, and the agency must coordinate notice and remediation.
Do we need a new BAA when the contract renews? Review it at each renewal. Campaigns, vendors, and state laws change. A BAA signed three years ago may not cover texting, AI tools, or Washington's My Health My Data Act.
Who reports the breach to OCR, us or the agency? Your practice reports as the covered entity. The agency reports to you. The BAA should require the agency to provide the facts, the affected population, and the mitigation steps you need for the OCR filing.


