Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Compliance whitepaper | Dental

Business Associate Agreements: A Guide for Dental Practices

Know which vendors need a signed agreement and what it should cover

  • Published September 25, 2026
  • 4 min read

Your practice shares patient information with many outside companies. Billing services, cloud software vendors, IT providers, and shredding companies may all see protected health information. HIPAA requires business associate agreements with these vendors, and this guide explains how to find, review, and manage them.

What a business associate is

Under HIPAA, a business associate is a person or company that creates, receives, maintains, or transmits protected health information on your behalf. Your practice, by contrast, is the covered entity. The vendor handles data because it provides a service to you.

In short, the agreement is a contract that spells out how the vendor must protect that data. It also makes the vendor directly responsible for certain HIPAA requirements. So a signed agreement matters for you and for the vendor.

Common dental vendors that need one

Many practices undercount their business associates. That is because some vendors handle data quietly in the background. Review this list against your own vendors:

  • Practice management and imaging software vendors, especially cloud platforms.
  • Managed IT providers and anyone with remote access to your systems.
  • Billing, collections, and claims services.
  • Patient communication platforms for texting, reminders, and reviews.
  • Cloud phone systems that store voicemail or recordings.
  • Backup and cloud storage services.
  • Email and file sharing platforms.
  • Document shredding and hardware disposal companies.
  • Answering services and outside consultants who review charts.

However, not every relationship needs an agreement. For example, sharing records with another provider for treatment generally does not require one. When the answer is unclear, confirm with your compliance advisor or counsel.

What business associate agreements should include

HIPAA sets out required elements for these contracts. A solid agreement usually covers the following points.

Permitted uses

First, the agreement states what the vendor may do with patient data. Typically, the vendor may only use it to provide the contracted service.

Safeguards

Second, the vendor must protect electronic data with appropriate safeguards under the HIPAA Security Rule. That includes access controls, security measures, and workforce training.

Breach reporting

Next, the vendor must report security incidents and breaches to you. Look for clear reporting timelines, because you may have your own notification duties.

Subcontractors

If the vendor uses its own subcontractors that touch your data, it must sign agreements with them too. This keeps protections in place down the chain.

Return or destruction

When the contract ends, the vendor must return or destroy the data where feasible. Otherwise, the protections continue for as long as it keeps the data.

Red flags to watch for

Some vendors resist signing or offer weak terms. So pay attention when a vendor says it does not need an agreement even though it stores patient data. Also, be cautious when a vendor offers only a generic document that omits breach reporting.

Consumer versions of software can be another problem. A free file sharing or email account often comes with no agreement at all. Therefore, use business versions that the vendor will cover under a signed contract.

Tracking and managing your agreements

Signing is only the first step. After that, agreements need a home, an owner, and a review schedule. Many practices keep a simple vendor register for this purpose.

Use this checklist to build and maintain yours:

  1. List every vendor that may handle patient information.
  2. Record whether a signed agreement exists and where it is stored.
  3. Note the date signed and the vendor contact for security issues.
  4. Flag vendors with missing or outdated agreements for follow-up.
  5. Add a step to your purchasing process so no new vendor starts without review.
  6. Review the register during your annual HIPAA risk analysis.
  7. Update it when you end a vendor relationship and confirm data return or destruction.

An agreement is not a security guarantee

A contract sets expectations, but it does not prove the vendor is secure. So ask a few simple questions of your most important vendors. For example, how do they protect accounts, back up data, and respond to incidents?

In addition, remember that your own obligations continue. Your practice still needs its own risk analysis, safeguards, and policies. Business associate agreements share responsibility; they do not transfer it.

How WEBIT helps

WEBIT signs business associate agreements for our healthcare clients, including dental practices. We also help you identify which technology vendors in your office handle patient data and whether they are covered.

For practices that want more structure, our managed compliance add-on helps organize policies and evidence. Visit our dental practices page or contact us to review your vendor list.

Key takeaways

  • Any vendor that handles patient data on your behalf likely needs a signed agreement.
  • IT, cloud, phone, texting, and disposal vendors are easy to overlook.
  • Strong agreements cover permitted uses, safeguards, breach reporting, subcontractors, and data return.
  • Keep a vendor register and review it during your annual risk analysis.
  • A signed agreement shares responsibility but does not replace your own safeguards.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Dental IT services

See how WEBIT supports dental organizations across Chicagoland.

Explore Dental IT →

More Dental whitepapers

Browse the full library of guides for your industry.

All Dental whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.