Agency BAA Obligations: What You Are Signing
What a marketing agency actually commits to when it signs a BAA with a healthcare client: scope, subcontractors, staff access, breach duties, and offboarding.
When a marketing agency signs a Business Associate Agreement it is accepting direct legal liability under HIPAA for the protected health information it handles on the client's behalf, and that obligation covers every subcontractor, freelancer, and tool the agency uses to do the work. Curve is the HIPAA-compliant tracking and attribution layer agencies use to keep the advertising side of that obligation manageable, with a signed BAA on every plan. A BAA is not a formality that unblocks CRM access. It is an operational commitment with a compliance program behind it.
You are a business associate whether you like the term or not
The status follows the data flow, not the job title. An agency becomes a business associate the moment it creates, receives, maintains, or transmits PHI on behalf of a covered entity. In practice that includes almost every real healthcare engagement:
- Login access to the client's CRM, EHR, or patient scheduling system.
- Lead notifications that pair a person's identity with a requested service or condition.
- Call tracking recordings or transcripts of patients describing symptoms.
- Form submissions routed to an agency inbox, automation tool, or spreadsheet.
- A patient list supplied for audience building.
- Building or operating the client's website intake and booking flows.
Running purely aggregate media with no lead-level access can keep an agency outside the definition. That arrangement is rarer than agencies assume, and it usually collapses the first time someone forwards a lead email to ask about quality.
What the agreement actually commits you to
Use and disclosure limited to what the agreement names
A BAA covers only the services described in it. Data received to run paid search cannot be repurposed for a case study, a benchmark report, an AI tool, or another client's lookalike audience, because none of those are the named service. Agencies get this wrong most often with aggregated insights. Building a cross-client benchmark from PHI you hold under several separate BAAs is a use nobody authorized.
Safeguards, in writing and in practice
The agreement requires appropriate administrative, physical, and technical safeguards. For an agency that means concrete things: access control with individual accounts rather than shared logins, multi-factor authentication, encryption in transit and at rest, a documented policy set, and workforce training that actually happened and can be evidenced with dates.
The gap between having safeguards and being able to prove you had them is where agencies lose. Keep the artifacts.
Flow-down to every subcontractor
This is the clause agencies underestimate. Any subcontractor who touches PHI on your behalf must be bound by terms at least as protective as the ones you signed. That covers the offshore reporting team, the freelance media buyer with CRM access, the contract developer building the intake form, the call center, and any software vendor storing lead data.
Two of those vendors will not sign. Meta and Google do not sign BAAs for their advertising products, which is not a loophole and not a subcontractor relationship you can paper over. It is the constraint that determines how conversion data has to be built: nothing that identifies a patient's clinical interest can reach them at all. Related reading: whether the Meta Pixel or Conversions API can be used safely.
Minimum necessary access
Staff get access to the PHI they need for their role, and no more. In an agency this is mostly a discipline problem rather than a technical one. Shared inboxes, an all-hands Slack channel where lead notifications land, and a client folder in a drive that everyone in the company can open are the three most common violations, and all three are cheap to fix before anyone asks about them.
Breach notification, on a clock
You must report breaches and security incidents to the covered entity, on the timeline the agreement specifies (frequently much tighter than the regulatory outer limit). Know that number before you need it. The practical requirement is an incident process with a named owner, a documented triage path, and the client contact who gets the call.
Note the exposure attached to getting this wrong. Since 2026-01-28, OCR civil monetary penalties run from $145 to $2,190,294 per violation category per year, and business associates can be penalized directly. Healthcare pixel litigation settlements have cumulatively crossed $100M, and plaintiffs' firms name vendors as well as providers.
Return or destruction at the end
When the engagement ends, PHI must be returned or destroyed, and if neither is feasible the protections continue indefinitely. Agencies routinely keep everything, on the theory that the client might come back. A shared drive full of a former client's lead exports is a live obligation with no revenue attached to it.
The operational program behind the signature
Signing the document is the easy part. Sustaining it is a small standing program.
Access reviews. Quarterly at minimum, and immediately whenever someone joins or leaves an account team. Offboarding a staff member from a healthcare client means revoking CRM, ad account, drive, and inbox access the same day.
A vendor register. One list of every tool touching client data, with BAA status and renewal date. New tools get added at procurement, not discovered during an incident.
Training with records. Annual, role-appropriate, with attendance logged. The account coordinator who forwards lead emails needs it more than the CTO does.
Incident runbook. Who declares an incident, who contacts the client, what gets written down, and when. Draft it while nothing is on fire.
Written policies. Short and real beats long and aspirational. A four-page policy set the team follows is worth more than forty pages nobody has read.
The three places agencies actually get caught
Enforcement and litigation rarely turn on an exotic failure. They turn on the same three habits.
The shared inbox. Lead notifications containing a name and a requested service arrive in an address the whole account team can read, then get forwarded to a freelancer, then sit in a mailbox for four years. Every step is a disclosure, and the volume makes it hard to characterize as an isolated slip.
The convenience upload. Someone exports patient records to build a lookalike audience, or drops a lead list into a spreadsheet tool to clean it up. Intent is irrelevant; the data left the covered chain.
The tag added later. A carefully compliant setup at launch, then a heat map trial, a chat widget, or a new analytics tool added by whoever had container access. The agency signed a BAA and then stopped checking whether the architecture it promised still exists. A standing monthly check turns that into a thirty-day exposure instead of a multi-year one.
How Curve reduces what your BAA has to cover
Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare, and agencies are one of its target segments. It does not remove an agency's business associate status, and no vendor can. What it does is shrink the surface where PHI can travel and give you evidence of the controls.
- Signed BAA on every plan, which satisfies your flow-down obligation for the measurement vendor rather than leaving a gap in the chain.
- Per-destination field mapping. Only explicitly mapped fields forward to a given destination, and the default is that nothing goes. The answer to "what does Meta receive" becomes a configuration you can show a client's counsel.
- Neutral event aliases. The ad platform sees a neutral event name rather than the service line, so nothing disclosing clinical interest reaches the vendors who will not sign.
- Identifier hashing. SHA-256 per each platform's conversion API requirements.
- PHI-pattern detection. A monitoring layer flagging PHI-shaped values (SSNs, MRN-style IDs, dates, long numeric sequences) so a misconfigured form surfaces as an alert.
- Audit logs covering data processing and platform forwarding, which is the evidence half of "we had safeguards."
- Bridge tokens, incoming webhooks, and offline conversion uploads, so outcomes return from the client's CRM or practice management system without lead-level data living in agency spreadsheets.
Curve's tracking script installs in place of the Meta Pixel and Google tag, with events flowing to US-hosted infrastructure before anything is forwarded server-side to Meta CAPI, Google Ads Enhanced Conversions, TikTok, Microsoft, LinkedIn, or GA4. For the mechanics, see the conversion API architecture overview and compliant lead routing from ad click to CRM.
Reading a client's BAA before you sign it
Client-drafted BAAs vary, and some contain terms well beyond the regulatory baseline. Look at five things.
- Scope of services. Does it describe what you actually do? A narrow description creates problems later; an unbounded one creates them now.
- Breach notification window. Some demand notice within 24 hours of discovery. Confirm you can meet it operationally.
- Indemnification and liability caps. Frequently uncapped for privacy claims. This is a business decision, not a compliance one, and it belongs in front of whoever signs contracts.
- Audit rights. Some allow on-site inspection with short notice. Know what an auditor would find.
- Subcontractor consent. Some require written approval for every subcontractor. Line that up against your actual vendor list before signing.
Frequently asked questions
Does a BAA make our agency HIPAA compliant?
No. It creates the obligation; compliance is what you do afterwards. Signing without the access controls, training, vendor register, and incident process behind it puts the agency in a worse position than not signing, because now the duty is documented.
Can one BAA cover multiple clients or services?
A BAA covers only the parties and the services it names. Each covered entity client needs its own, and expanding the services you provide can require amending it.
What if the client will not sign a BAA but wants us to run their ads?
If PHI will reach you, running the account without one exposes both parties. Either restructure the engagement so no PHI reaches the agency, which is possible but genuinely constraining, or resolve the paperwork. Document the conversation either way.
Do we need a BAA with Meta or Google?
You cannot get one for their advertising products; they do not sign them. The architecture has to assume those platforms are outside the covered chain, which is why conversion data going to them must be neutral and hashed rather than descriptive.
Are we liable if a subcontractor causes the breach?
You remain responsible to the client for the work, and your flow-down obligation means the subcontractor's failure is also evidence about your own program. A signed subcontractor agreement helps your position; it does not remove your exposure.
How long do our obligations last after the contract ends?
Return or destroy the PHI at termination. Where that is infeasible, the protections continue for as long as you hold the data, which is a good reason to make disposal feasible by not accumulating it in the first place.
Where to start
Inventory where PHI currently sits inside your agency: inboxes, drives, CRMs, automation tools, spreadsheets, chat threads. Most agencies find more than they expected, and most of it is not needed to do the work. Reducing that footprint is the single highest-leverage action available, because every obligation in the agreement scales with it.
Then close the tracking gap, which is the piece the client cannot audit for you. Curve gives agencies a measurement layer with per-destination field mapping, neutral event aliases, hashed identifiers, audit logs, and a signed BAA on every plan. Run the free compliance scanner against a client site to see what is firing today, or visit curvecompliance.com to work through your healthcare book.
Reviewed August 2026. This is general information, not legal advice. Ad platform conversion APIs and healthcare advertising policies change frequently. Verify current requirements with counsel before implementation.
Related articles
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit