Skip to content

BAA Management — Business Associate Agreement Tracking and Renewal

Purpose: Procedure for identifying, executing, storing, and renewing Business Associate Agreements (BAAs) with PHI-handling vendors.

Owner: Adriana (BAA coordination, SharePoint storage) / Rory (technical determination, final approval) Audience: Rory, Adriana Review frequency: Annual (January) Last reviewed: May 2026


What Is a BAA and When Is One Required

A Business Associate Agreement is a HIPAA-required contract between a Covered Entity (Cirius Group) and any vendor that creates, receives, maintains, or transmits ePHI on Cirius's behalf. A BAA must be in place before sharing ePHI with the vendor.

A vendor is a Business Associate if they:

  • Host or process ePHI (cloud providers, SaaS tools with access to patient data)
  • Provide services that require them to access ePHI (MDR, security operations, backup)
  • Develop or maintain systems that store ePHI

A vendor is not a Business Associate if they handle only de-identified data, or if their service never touches ePHI (e.g., a domain registrar, a generic SaaS with no ePHI integration).


BAA Inventory

All active BAAs are tracked in compliance/vendor-phi-inventory.md. That doc is the authoritative list. This document covers the process.

Current key BAAs (as of 2026):

VendorBAA TypeLocationStatus
Microsoft Azure (PROD + DDE)Evergreen — accepted via EAAzure Portal → Support → Data protectionActive
Amazon Web ServicesEvergreen — accepted via consoleAWS Console → Account → AgreementsActive
Arctic WolfSigned agreementSharePoint → Legal/BAA FolderActive
Palo Alto Networks (Cortex XDR)Signed agreementSharePoint → Legal/BAA FolderActive
TwingateSigned agreementSharePoint → Legal/BAA FolderActive
Keeper SecuritySigned agreementSharePoint → Legal/BAA FolderActive
OneLoginSigned agreementSharePoint → Legal/BAA FolderActive

Full list with PHI types, expiry dates, and contacts: compliance/vendor-phi-inventory.md.


New Vendor Onboarding — BAA Procedure

Step 1 — Technical determination

Rory reviews whether the new vendor will touch ePHI:

  • Will the vendor have access to Azure or AWS resources that host ePHI?
  • Will Cirius send any data to the vendor that includes PHI?
  • Does the vendor's service require them to process, store, or transmit ePHI?

If yes to any: flag the vendor as BAA-required before any ePHI sharing begins.

Step 2 — BAA request

Adriana sends a BAA request to the vendor. Two options:

Option A — Vendor has their own BAA template: Adriana requests the vendor's HIPAA BAA. Rory reviews the vendor's BAA to confirm it covers:

  • A description of permitted uses and disclosures of ePHI
  • Vendor agreement to use appropriate safeguards
  • Vendor agreement to report breaches to Cirius within 60 days
  • Vendor agreement not to disclose ePHI other than as permitted
  • Vendor agreement to return or destroy ePHI upon contract termination

Option B — Cirius requests vendor execute Cirius's BAA template: Use the template in SharePoint → Legal/BAA Templates → Standard BAA Template.

Step 3 — Signature

Adriana coordinates signature. DocuSign is preferred. Rory signs on behalf of Cirius Group. Vendor countersigns.

Step 4 — Registration

  1. Adriana saves the signed BAA to SharePoint → Legal/BAA Folder → [VendorName]BAA[YYYY].pdf
  2. Adriana updates compliance/vendor-phi-inventory.md with:
    • BAA status: Active
    • Date signed
    • Expiry (if fixed term — some vendor BAAs have 3-year terms)
    • SharePoint storage path
  3. Rory confirms the vendor is now cleared to receive ePHI

Annual BAA Review

Every January, Rory and Adriana conduct the annual BAA review:

  1. Pull the full list from compliance/vendor-phi-inventory.md
  2. For each vendor:
    • Confirm the vendor relationship is still active
    • Confirm the BAA has not expired
    • Confirm the BAA covers the current scope of ePHI sharing (scope changes require a BAA amendment or new BAA)
  3. Any expired or missing BAAs: remediate within 30 days
  4. Any vendor no longer used: initiate offboarding (below)

Vendor Offboarding — PHI Return or Destruction

When a PHI vendor relationship ends:

  1. Adriana notifies the vendor in writing that the relationship is terminating and requests:
    • Confirmation that all Cirius ePHI has been returned (preferred) or destroyed
    • Written certification of destruction if applicable
  2. The BAA termination clause governs the timeline and method. Most BAAs require destruction certification within 30 days of termination
  3. Document the ePHI return/destruction confirmation in SharePoint → Legal/BAA Folder → [VendorName]Termination[YYYY].pdf
  4. Update compliance/vendor-phi-inventory.md — mark vendor as Terminated with the date
  5. Rory verifies at the technical layer: remove vendor's service principal or API credentials from Azure Key Vault and Entra. Confirm no remaining data pipelines to the vendor

Cloud Provider BAAs

Microsoft Azure and AWS BAAs are evergreen (no fixed term) and accepted electronically:

Azure BAA:

  • Accepted as part of the Microsoft Online Services Terms / Data Protection Addendum
  • Accessible in Azure Portal → (gear icon) → Help + support → Data protection → Microsoft privacy and compliance
  • Applies to all services in both PROD (d477c9f8) and DDE (ff1c5d68) tenants
  • Review annually to confirm the DPA is still accepted and covers current Azure services in use

AWS BAA:

  • Accepted in each account via AWS Console → My Account → AWS Agreements → Business Associate Addendum
  • Must be accepted in each account separately. Confirm acceptance in all 7 accounts annually
  • The BAA covers AWS HIPAA-eligible services (S3, RDS, EC2, etc.). Confirm that all ePHI-handling services are on the HIPAA-eligible services list

ePHI Shared Without a BAA

If ePHI is shared with a vendor that does not have an executed BAA:

  1. Treat as a potential HIPAA breach — initiate the 4-factor risk assessment per compliance/hipaa-breach-notification-procedure.md
  2. Immediately halt ePHI sharing with that vendor
  3. Execute a BAA as fast as possible (emergency BAA execution within 72 hours)
  4. Document the unauthorized sharing in SecOps
  5. If the risk assessment finds low probability of compromise: document and close. No external notification required
  6. If the risk assessment finds material risk: proceed with breach notification per the breach procedure

Audit Evidence

BAA management is an expected audit artifact for HIPAA, HITRUST, and SOC2:

  • HIPAA: Auditors will ask for a list of BAs and executed BAAs. Provide: vendor-phi-inventory.md + SharePoint BAA folder contents
  • SOC2: BA management is a CC control. Evidence: the vendor-phi-inventory.md, annual review documentation, BAA files
  • HITRUST: Control 09.ab requires BA agreements. Evidence: same as above

See compliance/soc2-pbc-guide.md for how BAAs appear in the evidence package.


  • compliance/vendor-phi-inventory.md — authoritative BAA and PHI vendor inventory
  • compliance/vendor-risk-inventory.md — broader vendor risk assessments
  • compliance/hipaa-breach-notification-procedure.md — if ePHI shared without a BAA
  • compliance/soc2-pbc-guide.md — audit evidence packaging
  • compliance/hipaa-administrative-procedures.md — BA management procedures under §164.308(b)

Internal use only — Cirius Group