Business Associate Agreement for Therapists: BAA Review
Outline
The vendor just emailed a 14-page PDF and a calendar hold labeled “BAA signature.” Your first client is in 20 minutes. A business associate agreement for therapists is not a race to the signature block. It is the document that should match how the product will actually touch notes, recordings, exports, and backups.
This guide is a clause-and-workflow review for US mental-health clinicians. It covers who counts as a business associate, what to verify before PHI moves, how to connect each clause to real vendor handling, and which questions belong with counsel. It is not a model contract and not legal advice.
For the wider cluster, start at the therapy compliance hub. For one-person HIPAA operating rhythm around vendors, use the HIPAA guide for solo therapists.
Free PDF: BAA Review Checklist for Therapists
A printable review sheet for matching BAA clauses to how a therapy-practice vendor handles PHI.
- Vendor, covered-entity, plan-tier, owner, and review-date fields
- Checks for permitted uses, safeguards, subcontractors, and incident notice
- Return, destruction, export, and backup-lifecycle prompts
- Clause-versus-product evidence fields and counsel escalation questions
Free. We'll email the PDF link right away. We may also send the occasional therapist toolkit. Unsubscribe any time.
Where should we send the link?
We'll email the PDF link right away. You'll also get the occasional therapist toolkit. Unsubscribe any time.
✓ Check your inbox
We've sent you the PDF
The download link is on its way to your inbox, usually within a minute or two. The email will come from Emosapien (hello@team.emosapien.com); check your spam folder if you don't see it.
You're also on the weekly therapist toolkit list. Unsubscribe any time from the email footer.
Educational resource for licensed US mental-health clinicians and practice leaders. HIPAA Privacy and Security Rule materials change. Verify current HHS OCR guidance, your plan terms, and qualified counsel before you rely on any checklist.
What a business associate agreement for therapists actually is
A business associate creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. HHS publishes both plain-language business associate guidance and sample business associate agreement provisions. Those materials define the floor. Your signed PDF still has to match your stack.
In a therapy practice, business associates often include:
- EHR and practice-management platforms
- Telehealth and e-fax vendors
- Cloud storage, email hosts, and backup tools that hold clinical content
- Billing, clearinghouse, and virtual receptionist services that see PHI
- Transcription, ambient capture, and AI documentation products that process session content
A business associate agreement for therapists is the written contract that sets permitted uses, required safeguards, subcontractor rules, incident notice, HHS access, and what happens to PHI when the relationship ends. Signing without reading is how “HIPAA-aligned” marketing becomes an unreviewed risk file.
What this review covers
Before PHI moves, verify the relationship, the plan tier that includes the BAA, permitted uses, safeguards, subcontractors, incident notice clocks, termination, and return or destruction of data. Match every clause to how the product stores, accesses, trains on, and exits clinical content. Keep the executed PDF, plan-tier proof, and a dated subprocessor list with a named owner so the next audit or incident is boring.
When the work shifts past clause review:
- Multi-clinician access control and incident ownership after you hire
- Custom contract language: qualified healthcare counsel or a vetted firm template, not a fill-in-the-blank marketing PDF
Confirm the relationship before you debate clauses
Not every software subscription is a business associate relationship. Ask three plain questions:
- Does the vendor create, receive, maintain, or transmit PHI for us?
- Is that work on our behalf as a covered entity (or on behalf of another business associate)?
- Would identifiable clinical content enter the system in normal use?
If the answers are yes, get the BAA on the plan tier you will actually buy before go-live. Capture plan-tier evidence in the same folder as the PDF: order confirmation, admin-console plan badge, or vendor email that names the tier with BAA eligibility. Some vendors advertise HIPAA posture on a marketing page and gate the BAA to a higher tier. If the answers are no, write a short memo that explains why PHI stays out of that tool. Do not rely on a silent assumption.
Also name the parties correctly:
- Legal practice entity (not only the clinician’s personal name when the entity is the covered entity)
- Vendor legal name and the product brand if they differ
- Effective date and the subscription plan tied to BAA eligibility
- Who signs for the practice, where the executed PDF is stored, and who owns that vendor inventory row
The review checklist: clauses that must connect to real handling
Work the BAA like a map of the product, not like a notary stamp. For each section below, write what the clause says and what you observed in the product, security page, admin console, or vendor answers.
1. Parties, definitions, and PHI in scope
- Covered entity and business associate are named without ambiguity
- PHI and electronic PHI are defined consistently with HIPAA usage
- Services covered by the BAA match the modules you will turn on
- Any “de-identified only” carve-outs match how staff will actually use the tool
If the contract covers “scheduling only” but your team will paste progress notes into a support chat, the scope is already wrong.
2. Permitted uses and disclosures
- Uses are limited to providing the contracted services
- Secondary uses (analytics, model improvement, marketing, benchmarking) are explicit or forbidden
- Disclosures to third parties require a HIPAA pathway, not informal sharing
- Minimum necessary language appears where the vendor can limit internal access
For AI documentation tools, permitted-use language is where “we improve the product” can quietly expand into training on client content. Get a written no-training position for identifiable client data when that is your requirement.
3. Safeguards
- Administrative, physical, and technical safeguards are required in writing
- Encryption in transit and at rest is addressed at a level you can verify
- Access controls, authentication, and workforce restrictions are described
- Audit logging or monitoring obligations are present enough to request evidence later
A safeguard clause without an operational counterpart is theater. Ask where audit logs live, how long they are kept, and how you request them after a suspected incident.
4. Subcontractors and subprocessors
- Flow-down: subcontractors that handle PHI must agree to equivalent restrictions
- You can obtain a current subprocessor list or equivalent disclosure
- Changes to material subprocessors have a notice path you can live with
- International transfers, if any, are visible before PHI lands abroad
Cloud AI stacks often have more subprocessors than the sales deck shows. Pull the current list the same week you sign, date the file (or keep the vendor URL plus a screenshot), and store it next to the executed BAA. Re-check when modules or AI features change.
5. Incident and breach notice
- Security incident and breach are defined or tied to HIPAA meanings
- Notice to the covered entity has a clock (many practices negotiate shorter than the federal outer limit)
- Required content of the notice is listed (what happened, data types, counts, mitigation)
- Cooperation duties cover investigation, client notice drafting, and regulator inquiries when assigned
After a vendor email lands, move into containment and the four-factor assessment with the HIPAA breach notification guide for therapists. The BAA still governs how fast the vendor must tell you and what facts they owe you.
6. Individual rights support
- Access, amendment, and accounting support exist when the vendor holds designated-record-set data
- Timelines align with how you meet client rights requests
- Export formats are usable, not locked in a proprietary dead end
If you cannot export a client’s data in a usable form, you will feel it during a records request or a platform migration.
7. HHS access, termination, return, and destruction
- Books and records relevant to HIPAA compliance can be made available to the Secretary of HHS as required
- Either party can terminate if the other commits a material breach and fails to cure when a cure period applies
- At termination, PHI is returned or destroyed when feasible, with a residual-retention explanation when destruction is not feasible
- Residual copies in backups have a stated lifecycle
“We delete on request” is incomplete if backups and offline replicas are never mentioned. Ask for the destruction method and the outside date when residual copies age out.
8. Plan tier, liability, and insurance questions for counsel
These often need a lawyer, not a clinician guess:
- Indemnity direction and caps
- Cyber insurance requirements
- Limitation of liability versus real incident cost
- Governing law and venue
- Whether the BAA controls over conflicting click-through terms
Build a counsel packet before the legal hour: the executed (or draft) PDF, plan-tier evidence, the product security page or whitepaper, a short admin-console walkthrough (access roles, retention defaults, export path), and the dated subprocessor list. Clause review without that packet wastes the hour.
Connect the paper to the product
A business associate agreement for therapists only works when the practice treats the contract as an operations document.
Run this walk-through before go-live:
- Data map. List every field that will enter the vendor: demographics, diagnoses, notes, audio, measures, payments, messages.
- Access map. Who inside your practice can see that data, and who inside the vendor can?
- Retention map. Defaults for active accounts, exports, trash, and backups.
- Training map. Does any client content train public or shared models?
- Exit map. How you export, revoke access, and confirm destruction.
- Incident map. Who the vendor notifies, how you open an internal incident file, and which BAA clock starts.
Then lock custody so the paper stays findable:
- Store the executed PDF in a controlled location (practice drive folder or policy binder) with the vendor inventory row: product name, plan tier, sign date, next review date, incident notice email, and named owner.
- Keep plan-tier proof beside the PDF so a renewal or audit does not depend on memory.
- File the dated subprocessor list (or screenshot plus URL) in the same row; refresh when the vendor sends a change notice.
- Solo practices still need that single row. Group practices put the owner on the role matrix used for multi-clinician access and incidents.
Special notes for AI documentation and ambient tools
AI note tools raise the same BAA duties plus a few therapy-specific checks:
- BAA on the paid tier you will use, not a future enterprise promise
- No public-model training on identifiable session content, in writing
- Clinician review before sign-off so drafts do not become the record unattended
- Psychotherapy-notes handling if process notes must stay outside the designated record set
- Retention of audio and transcripts separate from the final note when those artifacts exist
- Subprocessor transparency for speech-to-text, storage, and model hosts
Emosapien is built for mental-health clinicians rather than generic medical scribing. Session content is not used to train public models. A Business Associate Agreement is available on Professional and Enterprise plans, with controls described on the therapy practice security page. Software still does not replace your vendor inventory, counsel packet, or sign-off discipline. If you want to test documentation support inside a review-first workflow, start a free trial.
Download the BAA review checklist
The printable checklist puts parties, permitted uses, safeguards, subcontractors, incident notice, termination, data return or destruction, and counsel questions on one working sheet. Use it for every new PHI vendor and at annual renewal. It is an educational worksheet, not a certification and not a substitute for a signed contract reviewed by counsel when stakes are high.
Free PDF: BAA Review Checklist for Therapists
A printable review sheet for matching BAA clauses to how a therapy-practice vendor handles PHI.
- Vendor, covered-entity, plan-tier, owner, and review-date fields
- Checks for permitted uses, safeguards, subcontractors, and incident notice
- Return, destruction, export, and backup-lifecycle prompts
- Clause-versus-product evidence fields and counsel escalation questions
Free. We'll email the PDF link right away. We may also send the occasional therapist toolkit. Unsubscribe any time.
Where should we send the link?
We'll email the PDF link right away. You'll also get the occasional therapist toolkit. Unsubscribe any time.
✓ Check your inbox
We've sent you the PDF
The download link is on its way to your inbox, usually within a minute or two. The email will come from Emosapien (hello@team.emosapien.com); check your spam folder if you don't see it.
You're also on the weekly therapist toolkit list. Unsubscribe any time from the email footer.
Closing checklist
- Decide whether the vendor is a business associate before PHI moves.
- Collect the BAA on the plan tier you will buy, and file plan-tier evidence with the PDF.
- Read permitted uses, safeguards, subcontractors, and notice clocks against the live product.
- Confirm training, retention, export, and destruction paths in writing.
- Store the signed PDF with named owner, review date, incident contact, and dated subprocessor list.
- Send counsel the packet (PDF, security materials, admin-console notes, subprocessors) for indemnity, liability, and ambiguous secondary-use language.
- Re-check the BAA, plan tier, and subprocessor file when modules or AI features change.
A business associate agreement for therapists earns its keep when the next vendor incident is boring: you already know the clock, the contact, the data map, and where the signed file lives. That is the standard this checklist is built to support.
References
- U.S. Department of Health and Human Services. Business Associates (who is a business associate; covered-entity responsibilities).
- U.S. Department of Health and Human Services. Sample Business Associate Agreement Provisions.
- Electronic Code of Federal Regulations. 45 CFR § 164.502 (uses and disclosures of PHI; business associate relationships).
- Electronic Code of Federal Regulations. 45 CFR § 164.504(e) (business associate contract requirements).
- U.S. Department of Health and Human Services. Breach Notification Rule (notice context when a business associate reports an incident).