Why One Size Doesn’t Fit All for BAAs

Business Associate Agreements (BAAs) are often treated as standard, “check-the-box” documents. In reality, the right BAA structure depends heavily on who your customers are. What works for a single clinician or small practice often falls short when dealing with enterprise healthcare organizations.

Small Clients & Individual Users

For individual clinicians and small healthcare practices, BAAs are typically straightforward. These agreements focus on baseline HIPAA compliance—safeguards, permitted uses of PHI, breach notification, and basic risk allocation. Because these clients usually operate in a single state and have limited compliance infrastructure, they rarely negotiate BAAs extensively. In many cases, a standardized, click-through BAA is both appropriate and sufficient.

Enterprise Clients Are Different

Enterprise healthcare clients—such as hospital systems, health plans, and multi-state provider groups—approach BAAs very differently. For them, a BAA is not just a compliance formality; it’s a core risk-management document. These organizations typically involve legal, compliance, and information security teams in vendor reviews. As a result, they expect BAAs to address more complex issues, including:

  • Offshore or overseas personnel access
  • Data residency and cross-border access
  • State-specific privacy laws
  • Audit and reporting rights
  • Subcontractor and flow-down obligations

Silence on these issues is often viewed as a red flag rather than a neutral position.

HIPAA Is the Floor, Not the Ceiling

While HIPAA permits the use of offshore personnel under appropriate safeguards, many states and healthcare organizations impose stricter requirements. Large enterprises commonly apply the most restrictive applicable rules across their entire organization to ensure compliance. This means that vendors serving enterprise clients are increasingly expected to disclose and limit offshore access to PHI directly within their BAAs, even if HIPAA alone would not require it.

Why Tailoring Matters

Using a single, generic BAA for all customers can slow down enterprise sales, force last-minute contract rewrites, or even derail deals late in procurement. A more effective approach is to align the BAA with the customer’s size, risk profile, and regulatory exposure.

  • For small clients, simplicity works.
  • For enterprise clients, transparency and specificity are essential.

The Bottom Line

One size doesn’t fit all when it comes to BAAs. Providers that recognize the difference—and structure their agreements accordingly—reduce friction, build trust with enterprise customers, and position themselves for scalable growth in healthcare markets.

Andrew Moskow

As a Legal Officer at Foundry Law Group, Andrew is a dedicated advocate ready to tackle new and complex endeavors with passion and expertise.