HIPAA for marketing agencies and vendors: what your practice should require before, during and after
Before any marketing agency or software vendor touches patient data, your practice should have a signed Business Associate Agreement, a list of the vendor's subcontractors that will see your PHI (each with its own BAA), a simple map of where the data goes, a breach-notice window shorter than the 60-day legal maximum, the right to ask for security evidence, and exit terms that return or destroy your data and leave every account in your name. The same four stages apply to outside companies as to your own staff; the paperwork is different.
- A vendor that creates, receives, maintains or transmits PHI for you is a business associate and needs a BAA first (45 CFR 164.502(e), 164.504(e)).
- Your vendor must have BAAs with its subcontractors that handle your PHI (164.502(e)(1)(ii), 164.308(b)(2)).
- The law allows a vendor up to 60 days to report a breach to you (164.410). Negotiate a shorter window.
- HIPAA gives HHS access to the vendor's records; your own audit rights are contractual, so write them in.
- At the end, PHI must be returned or destroyed where feasible (164.504(e)(2)(ii)(J)), and ad, analytics and website accounts should already be yours.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Which outside companies are business associates
Short answer: any company that handles your patient information to do work for you. If they store it, receive it, send it or create it on your behalf, they are a business associate and need a BAA before data moves.
This page applies our four-stage HIPAA framework to outside companies. The usual list for a med spa, dental office or medical practice:
- Marketing agency handling forms, CRM, call tracking, booking data, patient emails or texts, or review requests.
- Software vendors: EHR and practice management, online booking, patient texting and email, call tracking and recording, CRM, review tools, chat widgets, intake forms, cloud storage.
- IT or managed service provider with admin access to systems, email or backups.
- Billing companies, transcription, shredding and records storage.
Not business associates: other providers receiving PHI for treatment (45 CFR 160.103), pure conduits that only transmit data, and contractors such as janitorial staff whose access to PHI is incidental, per HHS guidance. Workforce members under your direct control, including many locums, are covered by your workforce program instead.
Since the 2013 HIPAA Omnibus Rule, business associates are directly liable for complying with the Security Rule and parts of the Privacy Rule. That does not shift your duty to have the BAA in place before disclosure.
The four stages for agencies and vendors
Stage 1 · Onboard: the BAA and the questions behind it
HIPAA lists what a BAA must contain (164.504(e)(2)): permitted uses and disclosures; no other use; safeguards including Security Rule compliance; reporting of unauthorized uses, security incidents and breaches; flow-down to subcontractors; help with patient access, amendment and accounting requests; HHS access to books and records; return or destruction of PHI at termination; and your right to terminate for a material breach. HHS publishes sample provisions to compare against.
The BAA is necessary but not enough. Ask the questions that tell you how the vendor really works:
- Data-flow map. What PHI do you receive, from which of our systems, where is it stored, who can see it and where does it go next?
- Subcontractors. Which subcontractors touch our PHI (hosting, form tools, call tracking, texting, AI transcription)? Do you have a BAA with each (164.502(e)(1)(ii), 164.308(b)(2))?
- Training. Do the staff on our account hold HIPAA compliance training certificates, and how often is training refreshed?
- Risk analysis. When did you last complete a Security Rule risk analysis? Will you share a summary or an independent assessment report?
- Location. Where is our data stored and accessed from, including any offshore teams?
Stage 2 · Access: named users, your accounts
- The vendor's staff get named logins with MFA on your systems, never a shared practice login.
- Access is scoped to the work: an agency managing ads does not need the EHR.
- Ad accounts, analytics properties, Google Business Profile, domains, website hosting, call-tracking numbers and social pages are owned by the practice, with the vendor added as a user.
- API connections between your EHR or booking system and vendor tools are documented, with an owner and a review date.
Stage 3 · Operate: keep PHI where it belongs
- Ad platforms: no PHI. No patient list uploads, no pixels on booking, portal or intake pages, no form fields in tags. See our guides to HIPAA-safe Google Ads and HIPAA-safe Meta ads.
- Reporting: aggregate dashboards; patient-level reconciliation stays in BAA-covered systems.
- Incidents: the vendor must report breaches without unreasonable delay and within 60 days of discovery (164.410). Ask for 5 to 10 business days or less in the BAA, because your own notification clock can be affected by when the vendor knew.
- Changes: notice before the vendor adds a new subcontractor or moves your data.
Stage 4 · Offboard: data back, keys back
- Export your data first: lead history, call logs, review history, CRM records, creative assets.
- Written confirmation of return or destruction of PHI, including from subcontractors (164.504(e)(2)(ii)(J)). Where destruction is not feasible, the BAA's protections continue.
- Remove the vendor's users from every account and rotate shared credentials and API keys.
- Keep the BAA and exit records for six years (164.530(j)).
Audit rights: what HIPAA gives you and what you should add
Short answer: HIPAA requires the vendor to open its books to HHS, not to you. If you want to check the vendor's practices, the contract has to say so.
| Term | Required by HIPAA? | What to ask for |
|---|---|---|
| HHS access to records | Yes (164.504(e)(2)(ii)(I)) | Standard in every BAA. |
| Breach reporting | Yes, within 60 days (164.410) | A shorter window and named contacts on both sides. |
| Subcontractor flow-down | Yes (164.504(e)(2)(ii)(D)) | A current list of subcontractors and notice of changes. |
| Practice audit or security evidence | No, contractual | Annual security questionnaire, risk analysis summary or independent assessment report, and the right to ask after an incident. |
| Training evidence | No, contractual | Training records or certificates for staff on your account. |
| Account ownership | No, contractual | All ad, analytics, web and phone assets in the practice's name. |
| Return or destruction at exit | Yes (164.504(e)(2)(ii)(J)) | Written certificate within a set number of days. |
Printable vendor and agency HIPAA checklist
Stage 1 · Onboard
- BAA signed before any PHI is shared, with all required elements
- Data-flow map received and reviewed
- Subcontractor list received; vendor confirms a BAA with each
- Training evidence for staff on the account
- Risk analysis date or independent assessment reviewed
- Data storage and access locations confirmed
Stage 2 · Access
- Named vendor users with MFA; no shared logins
- Access limited to systems the work requires
- All marketing and web assets owned by the practice
- Integrations and API keys documented
Stage 3 · Operate
- No PHI sent to ad platforms or analytics tags
- Breach-notice window in the BAA shorter than 60 days, with named contacts
- Notice required before new subcontractors or data moves
- Annual vendor review on the calendar
Stage 4 · Offboard
- Data exported before access ends
- Written return-or-destruction confirmation, including subcontractors
- Vendor users removed; credentials and keys rotated
- BAA and exit records filed for six years
How Ichelon Consulting US answers these questions
We are a healthcare-only marketing agency, so we expect these questions. A BAA is signed with every US client before work starts. Our client-facing and delivery teams hold HIPAA compliance training certificates. We build campaigns so PHI stays out of ad platforms, ask for named-user access rather than shared logins, and keep ad, analytics and web accounts in the client's name so an exit is clean. Contracts and invoices are in USD from our Dallas, Texas LLC, and our production team in Gurugram, India is part of the same company. Read more on how we work, or book a call and ask us for the data-flow map.
Related reading: BAA vendor selection for marketing agencies, HIPAA for in-house marketing teams, med spa marketing, med spa marketing statistics, the med spa Google presence report, the state medical board advertising guide and all US guides.
Sources
- 45 CFR 160.103 (business associate definition and exclusions): law.cornell.edu/cfr/text/45/160.103
- 45 CFR 164.502(e) (disclosures to business associates and subcontractors): law.cornell.edu/cfr/text/45/164.502
- 45 CFR 164.504(e) (required BAA contents): law.cornell.edu/cfr/text/45/164.504
- 45 CFR 164.308(b) (business associate contracts under the Security Rule): law.cornell.edu/cfr/text/45/164.308
- 45 CFR 164.410 (business associate breach notification): law.cornell.edu/cfr/text/45/164.410
- HHS, Business Associates guidance: hhs.gov
- HHS, Sample Business Associate Agreement Provisions: hhs.gov
- HHS FAQ, "Are we required to certify our organization's compliance with the standards?" (HHS does not recognize private compliance certificates): hhs.gov
- HHS, What You Should Know About OCR HIPAA Privacy Rule Guidance Materials (OCR does not certify persons or products as HIPAA compliant): hhs.gov
- HHS FAQ 243, janitorial services: hhs.gov
- OCR, Pagosa Springs Medical Center: hhs.gov
- OCR, Raleigh Orthopaedic Clinic: hhs.gov
- OCR, dental software business associate settlement (April 2026): hhs.gov press room
Related pages from the US team
HIPAA compliance by role
The full four-stage framework and the roles-by-stages matrix.
BAA vendor selection for marketing agencies
How to compare agencies on BAA terms and data handling.
HIPAA for practice managers
Running the vendor register and the breach decision.
HIPAA offboarding checklist
The vendor exit steps, including account ownership.
HIPAA-safe website tracking
Keeping PHI away from tags and pixels.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Does our marketing agency need to sign a BAA?
Yes, if it creates, receives, maintains or transmits PHI on your behalf. That includes handling lead forms, call tracking or recordings, CRM records, booking data, patient email or text lists, and review-request lists. If the agency only ever sees aggregate or de-identified data, a BAA may not be legally required, but ask how they keep it that way.
What should a BAA with a marketing agency include?
At minimum the elements HIPAA requires: permitted uses and disclosures, safeguards including Security Rule compliance, reporting of unauthorized uses and breaches, flow-down to subcontractors, support for patient access and amendment requests, HHS access to records, and return or destruction of PHI at termination. Many practices add a shorter breach-notice window, audit or security-evidence rights, and a list of approved subcontractors.
Will ad platforms sign a BAA?
Many mainstream advertising and analytics platforms will not sign a BAA. That is why campaigns should be designed so PHI never reaches them: no patient list uploads, no pixels on booking, portal or intake pages, and no form contents passed into ad or analytics tags.
Can a vendor be officially certified as HIPAA compliant?
No. HHS does not certify any person or product as HIPAA compliant and does not recognize private certificates as proof of compliance. What a vendor can show you is trained staff, independent security assessments and a signed BAA. Ask for that evidence rather than relying on a badge.
Can a vendor use offshore staff on our account?
HIPAA does not ban offshore access, but the vendor remains responsible for safeguarding your PHI wherever its staff are, and some payer contracts or state rules add conditions. Ask where your data is stored and accessed from, and put any restrictions you need into the contract.
What happens to our data when we leave a vendor?
The BAA must require the vendor to return or destroy the PHI it still holds and keep no copies, or, where that is not feasible, extend the BAA's protections and limit further use. Ask for written confirmation, including from subcontractors, and export what you need before access ends.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Looking for an agency that signs a BAA before it starts?
Ichelon Consulting US signs a BAA with every US client. Book a 30-minute call and we will walk you through our data flows, subcontractors and exit terms.