Skip to content

HIPAA subcontractor BAAs

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

Your obligations flow downhill. Every subcontractor that touches your customers' PHI needs its own BAA with you — and many vendors miss this.

Obligations flow downhill

When you are a business associate, the subcontractors you use to deliver your service — cloud infrastructure, email, support tooling — that touch PHI become your business associates, and HIPAA requires a BAA with each. The Omnibus Rule made this explicit: the chain of obligation extends all the way down.

Which vendors need one

Not every vendor needs a BAA — only those that create, receive, maintain, or transmit PHI on your behalf. Your cloud provider hosting ePHI does; an analytics tool that never sees PHI does not. The task is mapping which vendors actually touch PHI, which is where an accurate vendor inventory pays off.

Where vendors get caught

The common failure is using a subprocessor that touches PHI without a BAA in place — often a tool adopted by a team without compliance review (shadow IT). That gap is your liability, not the subcontractor's problem alone. Major cloud providers offer BAAs; you must actually execute them and configure services to be in-scope.

Manage the chain

Keep a current inventory of subprocessors that touch PHI, with a signed BAA on file for each, reviewed as vendors change. SentinelPanda tracks the vendor/subprocessor inventory and BAA status so a PHI-touching vendor without a BAA surfaces before a regulator finds it.

HIPAA business associate agreements Tiering third-party vendors by risk Shadow IT: the compliance blind spot

Run your compliance program in one workspace.