A healthcare BAA (Business Associate Agreement) is one of the few contracts where you actually get a say in a vendor’s security posture before you’ve handed over any data. And it’s also the one that most often gets signed at the bare legal minimum, filed away, and never looked at again.
For a SaaS vendor that touches Protected Health Information (PHI), the BAA is supposed to enforce some real security discipline. In practice, it usually just means that the vendor has promised to be careful.
That gap matters more than it should. In 2025, 35.8% of healthcare data breaches happened with the business associates.
A signed BAA healthcare organizations rely on doesn’t configure a firewall or run a test. It obligates the vendor to do those things. Whether they actually happen is a separate question, and it’s the one you’re left holding when OCR comes asking.
The five questions below are built to close that gap before you sign, doubling as a working framework for healthcare third party vendor risk management. They’re not legal advice, but diligent questions aimed at the operational reality behind a vendor’s promises.
Ask them during procurement, get the answers in writing, and make sure the BAA itself reflects them. A vendor’s willingness, or refusal, to answer will plainly tell you what you need to know.
1. Where Does Our PHI Actually Go and How Is It Stored?
Before anything else, you have to map the data.
A vendor’s marketing page rarely tells you where PHI physically lands, who else can touch it, or how it’s protected at rest. You need specifics about which cloud holds the data, whether it’s encrypted in transit and at rest and to what standard, whether your records are logically isolated, and exactly which staff and systems can decrypt them.
Most SaaS platforms are built on subcontractors, from cloud hosting and analytics to email and logging. Under HIPAA, every subcontractor that creates, receives, maintains, or transmits PHI on the vendor’s behalf has to be bound by the same protections as underlined in the agreement.
Ask for the current sub-processor list, what category of PHI each one receives, and how you’ll be notified when that list changes. If a vendor can’t produce this on request, they don’t have control of their own data flows, which means neither do you. This is the core of healthcare third party vendor risk management: the BAA names the obligation, but the sub-processor map is where the actual risk lives.
And know your boundary. HHS guidance on cloud computing is clear that a cloud provider becomes a business associate the moment it stores or processes PHI.
But a cloud provider’s BAA only covers the infrastructure layer. It doesn’t cover how the application running on top of that infrastructure handles PHI. That layer belongs to the SaaS vendor, and verifying it is on you.
2. Will you use our PHI to train your AI?
This is the question that’s changed the most in the last two years, and it’s the one most likely to be buried in a vendor’s terms of service rather than its BAA.
More SaaS platforms are running machine-learning features now, and the data fueling them has to come from somewhere. You need ask your vendor directly whether they will be using your patients’ PHI to train, fine-tune, or improve models?
Under HIPAA, a business associate can only use PHI for purposes the BAA permits. Product improvement and model training aren’t default permitted uses. A vendor can lawfully create de-identified data for its own purposes, but only if the BAA expressly allows it and the data actually meets HIPAA’s de-identification standard (either Safe Harbor removal of the 18 identifiers or a documented Expert Determination, per HHS’s de-identification guidance).
“We anonymize it” is not the same as meeting that standard.
A permissive AI or “service improvement” clause in a vendor’s general terms can quietly contradict the narrower BAA healthcare entities actually signed. If a vendor genuinely wants to train on your data, make them name it explicitly, define how de-identification is performed and verified, and give you the right to opt out.
3. What Happens to Our PHI When the Contract Ends?
The more revealing question is what happens when it ends.
HHS’s sample BAA provisions, drawn from 45 CFR 164.504(e), require that on termination the business associate return or destroy all PHI it holds. And where return or destruction is genuinely infeasible, extend the agreement’s protections to that data and limit any further use.
“Delete” in a SaaS environment is rarely as simple as it sounds. You need to ask your vendor how deletion happens across primary stores, replicas, and backups. Ask how long backup copies persist before they cycle out.
Ask whether sub-processors have to delete their copies too, and whether you’ll get a certificate of destruction confirming it was done. Set a defined timeline, so data doesn’t linger indefinitely in a dormant account. And confirm the format your records come back in, so you’re never locked out of your own data.
Termination is also the moment a vendor’s incentives shift. The customer is gone, but the data is still sitting there. A vendor that has thought carefully about end-of-life data handling is usually one that takes the rest of the agreement, and the rest of the healthcare third party vendor risk management, seriously too.
4. How Do You Prove Your Security Controls Actually Work?
A healthcare BAA requires appropriate safeguards, but that phrase is doing a lot of unspoken work. Two vendors can sign identical language and run completely different security programs underneath it.
Your is to replace assumption with evidence. Ask what independent testing the vendor undergoes, how often, and whether you can see the results.
This is, in effect, a healthcare risk assessment performed on a vendor’s environment with the same evidence-based scrutiny you’d want applied to your own organization.
The strongest signal is an independent penetration test: a manual, expert-led engagement that simulates a real attacker, not an automated vulnerability scan relabeled as a pentest. Ask who performs it, how recently, and whether you can review the report or at least an attestation letter.
In the same context, a SOC 2 Type II report is also useful, but you also have to understand what it actually is. It’s not a certification, not a pass/fail license, and not proof of HIPAA compliance. It tells you the controls were tested, it doesn’t close the HIPAA-specific gaps the BAA exists to cover.
HHS’s proposed update to the HIPAA Security Rule, published in January 2025, would make several long “addressable” controls mandatory, including MFA, encryption, vulnerability scanning at least every six months, and penetration testing at least once every 12 months.
As of mid-2026 the rule is still proposed rather than final, but it signals exactly where regulator expectations are heading. A vendor already operating to that standard won’t be scrambling when it lands.
5. What’s Your Incident Response Process?
When a SaaS vendor is breached, your patients’ data is exposed. But much of the notification burden, and the reputational damage, lands on you.
So, the final question is about speed and process: what does the vendor’s incident response actually look like, and how quickly will you hear about it?
Under the HIPAA Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery.
Your vendor should, however, not treat 60 days as a target. It’s far too long to wait before starting your own response and notification clock. Negotiate a tighter window into the healthcare BAA; many well-run programs require notice within a small number of days for confirmed incidents.
And the clock should run from the vendor’s discovery of the breach, not from some later internal confirmation.
The timeline is not everything. Ask your vendor whether they have a documented and tested incident response plan, who your named contact is during an incident, what information you’ll receive and when, and whether the vendor will cooperate with forensic investigation and give you the detail you need for your own OCR reporting.
The proposed Security Rule update would also require business associates to notify covered entities within 24 hours of activating a contingency plan. One more sign that “we’ll let you know eventually” is no longer an acceptable answer.
A healthcare BAA is only ever as strong as the diligence behind it. The signature proves that a vendor has accepted the obligations. These five questions test whether it can actually meet them. Asked early during procurement can prevent you from a costly breach. Asked late, they cost a great deal more.
How Can KLEAP Help?
Most BAA reviews stop at the contract. KLEAP starts there and keeps going, because a signature doesn’t tell you whether a vendor’s controls actually hold up.
KLEAP works with healthcare and healthtech organizations to turn BAAs from filed paperwork into something that’s actually enforced. We review the agreements you already have, identifying where the language is vague or silent on things like AI training, sub-processor flow-down, and breach notification timelines, and flagging the gaps before a regulator finds them for you.
Where we go further than most reviews is on verification. Rather than taking a vendor’s security claims at face value, our team builds a healthcare third party vendor risk management and runs independent, manual penetration testing to pressure-test what they’re actually promising. Not an automated scan with a report slapped on top, but a real, hands-on healthcare risk assessment designed to surface what a vendor’s own assurances might be glossing over.
All of this runs through KLEAP’s concierge model. A dedicated security expert assigned to your engagement from start to finish, not a rotating support queue or a dashboard generating a readiness score and calling it done. You get a named point of contact who understands your vendor landscape, your compliance obligations, and your risk tolerance, and who stays accountable for the outcome.
If you’re evaluating a new SaaS vendor, renegotiating a healthcare BAA, or just not sure whether your current agreements reflect reality, talk to your KLEAP concierge.
