ShieldForce Colored Variance Logo
How to Negotiate a Better Business Associate Agreement With Your Home Health EHR Vendor
How-To Guide

How to Negotiate a Better Business Associate Agreement With Your Home Health EHR Vendor

The Business Associate Agreement is the contract through which an EHR vendor accepts HIPAA obligations for the patient data in their platform. Most home health agencies sign whatever BAA the...

The Business Associate Agreement is the contract through which an EHR vendor accepts HIPAA obligations for the patient data in their platform. Most home health agencies sign whatever BAA the vendor provides without review, on the assumption that the vendor's legal team has produced a compliant document. Some have. Many have produced a document that's HIPAA-compliant in the minimum required sense while containing provisions that are significantly unfavorable to the covered entity — particularly around breach notification timelines, liability limitations, and sub-contractor coverage. The gap between a standard vendor BAA and a negotiated BAA often means the difference between meaningful protection and an expensive surprise when a breach occurs.

What HIPAA Requires a BAA to Include — the Baseline

HIPAA specifies the minimum required provisions for a BAA at 45 CFR § 164.504(e). These include: permitted and required uses of PHI, prohibitions on unauthorized uses, requirements to use appropriate safeguards, reporting of security incidents and breaches, requirements to flow down obligations to sub-contractors (sub-business-associates), obligations at termination of the arrangement, and authorization for the covered entity to terminate the agreement if the BAA is breached. A BAA that contains all of these provisions is technically HIPAA compliant. It may still be a poor agreement for the agency — see HIPAA Security Officer Requirements for Home Health Agencies for how BAA review and negotiation fits into the Security Officer's broader vendor management responsibilities.

What Standard Vendor BAA Templates Commonly Omit or Underspecify

Breach Notification Timeline

HIPAA requires a BAA to include breach notification provisions, but doesn't specify an exact notification timeline for the business associate to notify the covered entity. Standard vendor BAAs often use language like "without unreasonable delay" or "within 60 days of discovery" — the latter being the maximum HIPAA permits for notification to patients, not the standard for business-to-business notification. This matters enormously: the agency's own 60-day notification clock to OCR and patients starts at the agency's discovery of the breach, not the vendor's. If an EHR vendor takes 45 days to notify the agency of a breach in their system, the agency has 15 days to identify affected patients, send letters, and notify HHS. Negotiate for a specific business-to-business notification timeline of 5–15 days maximum.

Sub-Contractor Coverage and Cloud Infrastructure

An EHR vendor doesn't operate in isolation. They use cloud infrastructure providers (AWS, Azure, Google Cloud), backup vendors, analytics platforms, and support services — all of which may process patient data. The BAA should require the vendor to flow down HIPAA obligations to all sub-contractors and to notify the agency if a sub-contractor breach affects its data. Standard templates often contain this requirement in general language without specifying that the vendor is responsible for the sub-contractor's compliance or for notifying the agency of sub-contractor incidents. This same sub-contractor logic applies to any vendor touching ePHI — see Home Health EHR Security Compared for how BAA boundaries specifically play out across the major home health EHR platforms.

Security Standards and Evidence

Standard BAAs state that the vendor will "use appropriate safeguards" to protect PHI. Negotiate for the vendor to specify the security standards they maintain — SOC 2 Type 2 certification, HITRUST, or equivalent — and to provide annual evidence of continued certification. A vendor that won't commit to documented security standards in the BAA is a vendor whose security posture can't be verified.

Liability and Indemnification

Many vendor BAAs contain liability limitations that cap the vendor's exposure to the fees paid under the contract — often meaning that a vendor breach affecting thousands of patients creates liability for the vendor capped at a few months of software subscription fees. Review these provisions with legal counsel. Some are negotiable, particularly for larger agencies or in competitive vendor selection situations.

How to Open the Negotiation Without Losing the Deal

Vendors present BAAs as non-negotiable to discourage review. The practical approach: request a redline of the BAA and identify the two or three provisions most important to negotiate — the breach notification timeline, sub-contractor coverage, and security evidence requirements are typically the highest-value targets. Frame the request as due diligence, not adversarial: "We have legal counsel who reviews all BAAs as part of our HIPAA compliance program — here are the specific provisions we need to discuss." Most established healthcare software vendors have handled this conversation before and will negotiate the high-priority items rather than lose the business.

This negotiation leverage matters even when the vendor relationship isn't a direct choice — for example, with state-managed EVV systems, where the agency may have less room to negotiate but should still push for clarity on the same core provisions wherever possible.

Frequently Asked Questions

Is a standard vendor BAA template legally sufficient under HIPAA?

It can technically satisfy the minimum required provisions under 45 CFR § 164.504(e) while still being a weak agreement for the covered entity — HIPAA sets a floor, not a standard of fairness, particularly around breach notification timelines and liability caps.

What's the single highest-priority provision to negotiate in a BAA?

The business-to-business breach notification timeline. A vendor's standard "60 days" language is the maximum HIPAA allows for notifying patients, not a reasonable timeline for notifying the covered entity — negotiating this down to 5–15 days preserves the time needed to meet the agency's own notification deadlines.

Will an EHR vendor actually negotiate BAA terms, or is it take-it-or-leave-it?

Most established healthcare software vendors have handled BAA negotiation requests before and will negotiate high-priority provisions rather than lose the business, especially when the request is framed as standard due diligence rather than an adversarial demand.

Does a BAA need to specifically require the vendor's security certifications?

It should. A BAA that only requires "appropriate safeguards" without naming a specific standard (SOC 2 Type 2, HITRUST, or equivalent) and requiring annual evidence leaves the agency with no way to verify the vendor's actual security posture.


Closing

If you're serious about protecting your home health agency — and about having documentation that holds up when it needs to — the next step is a free HIPAA Risk Assessment.

→ Schedule Your Free HIPAA Risk Assessment — https://shieldforce.io/hipaa-assessment

→ Explore Home Healthcare Cybersecurity — https://shieldforce.io/home-healthcare

→ View Transparent Pricing from $35/user/month — https://shieldforce.io/home-healthcare/checkout

Share this post

Topics

#How-To Guide#How-To-Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours - 24/7.