BAA Agreement
Last updated: 10 October 2026
Before we access any patient information for your practice, MBCS signs a Business Associate Agreement (BAA) with you. This page explains what that agreement covers and how to get one. It is a summary. The signed BAA is the binding document.
What a BAA is
HIPAA requires a covered entity, such as your practice, to have a written agreement with any business associate that creates, receives, maintains or transmits protected health information (PHI) on its behalf. Billing, coding and revenue cycle work usually requires PHI, so the BAA is signed before onboarding begins.
When it is signed
- You request an assessment using practice-level details only. No PHI is needed.
- We send a proposal and services agreement.
- Both parties sign the BAA, together with or before the services agreement.
- Only then do we set up secure access and begin working with PHI.
What our BAA covers
Our standard BAA includes the terms HIPAA requires, including that we will:
- use and disclose PHI only to perform the contracted services or as required by law
- apply appropriate administrative, physical and technical safeguards and comply with the HIPAA Security Rule for electronic PHI
- report to you any use or disclosure not permitted by the BAA, any security incident, and any breach of unsecured PHI within 10 business days of discovery
- require any subcontractor that handles your PHI to agree to the same restrictions in writing
- help you respond to patients’ requests to access or amend their information and for an accounting of disclosures
- make our relevant records available to the U.S. Department of Health and Human Services when required
- return or destroy PHI when the relationship ends, or protect any PHI that cannot feasibly be returned or destroyed
- allow you to terminate the agreement if we materially breach it
Request a BAA
To request our BAA for review, contact us or call +1 (737) 332-2245. Please do not include any patient information in your request.
