What a BAA Actually Protects You From
(And What It Doesn’t)
You finished the Security Risk Assessment. Maybe you used the free HHS tool, maybe you hired someone, maybe you’re on a compliance platform that walked you through it. Either way, there’s a report sitting in a folder somewhere, and it feels like the job is done.
It isn’t, and this is the part almost nobody writes about. Most HIPAA content — including our own pillar guide on the SRA — is built around the assessment itself: how to run it, what it covers, who needs one. Almost none of it addresses the other eleven months of the year, which is exactly when things actually go wrong. OCR doesn’t cite organizations for failing to complete a risk analysis three years ago. It cites them for having one that no longer reflects reality.
Here’s a cadence that doesn’t require a compliance department — just a recurring block on someone’s calendar and a habit of writing things down.
Monthly: the fifteen-minute check
This isn’t a mini risk assessment. It’s a pulse check, and it should take less time than a staff meeting.
- New vendors. Did anyone sign up for a new billing tool, scheduling app, fax-to-email service, or AI transcription tool this month? If it touches patient data and there’s no signed BAA on file, that’s this month’s action item — not next quarter’s.
- Departed staff. Confirm that anyone who left has been removed from the EHR, email, and any shared drives. This is the single most common gap auditors and consultants find in small practices — an account that should have been deactivated the day someone left, still active six months later.
- Devices. Any new laptops, tablets, or phones added to the practice? Are they encrypted and covered under your device policy before they touch PHI, not after?
Keep a simple running log — a shared doc is fine — with the date, what changed, and who handled it. That log becomes valuable documentation later, and building it monthly is far less painful than reconstructing it from memory during an audit.
Quarterly: the deeper look
Roughly every three months, spend an hour on:
- Access review. Pull a list of who has access to what, and confirm it still matches actual job roles. Practices grow and change roles informally — someone who covered billing for two weeks during a leave often keeps that access indefinitely.
- BAA inventory. Cross-check your vendor list against your signed BAAs. It’s common for a practice to add three or four new tools a year and only formally track BAAs for the big, obvious ones (the EHR, the billing company) while missing smaller ones (the answering service, the shredding company, the patient text-reminder app).
- Remediation follow-through. If your original SRA identified action items, where do things actually stand? “We’re aware of it” is not the same as “we fixed it,” and OCR’s stated posture in recent enforcement activity has moved specifically toward checking whether findings were acted on, not just identified.
Annually: the full reassessment
A complete SRA should happen at least once a year, and sooner if something material changed — a new EHR, a new location, a service line addition (behavioral health, telehealth, a new specialty), or a security incident, even a small one. Treat the annual reassessment as an update to a living document, not a from-scratch project. If your monthly and quarterly habits above are solid, the annual reassessment gets noticeably faster each year, because you’re not starting from zero.
The habit that matters most: writing it down
None of this protects you if it isn’t documented. If an incident happens and OCR asks what your risk management program looked like, “we’ve been keeping up with it” is a much weaker answer than a dated log showing monthly vendor checks, quarterly access reviews, and a remediation tracker with completion dates. The goal isn’t perfection — it’s being able to show, in writing, that this was an active, ongoing process rather than a folder that got opened once a year.
Related reading
- The HIPAA Security Risk Assessment: Everything a Small Healthcare Facility Needs to Know — the starting point for this series, covering what the SRA actually requires.
- The HIPAA Compliance Officer Job Nobody Applied For — for whoever ends up owning this cadence day to day.
- What a BAA Actually Protects You From (And What It Doesn’t) — more on the vendor side of the monthly check above.
This page is maintained by AffableONE and reviewed for accuracy against current HHS and OCR guidance. It is intended as educational content, not legal advice.