HIPAA subcontractor BAAs
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
Your obligations flow downhill. Every subcontractor that touches your customers' PHI needs its own BAA with you — and many vendors miss this.
Obligations flow downhill
When you are a business associate, the subcontractors you use to deliver your service — cloud infrastructure, email, support tooling — that touch PHI become your business associates, and HIPAA requires a BAA with each. The Omnibus Rule made this explicit: the chain of obligation extends all the way down.
Which vendors need one
Not every vendor needs a BAA — only those that create, receive, maintain, or transmit PHI on your behalf. Your cloud provider hosting ePHI does; an analytics tool that never sees PHI does not. The task is mapping which vendors actually touch PHI, which is where an accurate vendor inventory pays off.
Where vendors get caught
The common failure is using a subprocessor that touches PHI without a BAA in place — often a tool adopted by a team without compliance review (shadow IT). That gap is your liability, not the subcontractor's problem alone. Major cloud providers offer BAAs; you must actually execute them and configure services to be in-scope.
Manage the chain
Keep a current inventory of subprocessors that touch PHI, with a signed BAA on file for each, reviewed as vendors change. SentinelPanda tracks the vendor/subprocessor inventory and BAA status so a PHI-touching vendor without a BAA surfaces before a regulator finds it.