Do You Need a BAA With Your Marketing Agency? A Decision Checklist

Published: July 25, 2026

Written by: Chris Goodman

If your marketing agency's work touches protected health information in any way, HIPAA requires a signed Business Associate Agreement before that work starts, not after. Here's a straightforward way to tell whether you need one.

What a BAA actually is

A Business Associate Agreement is a contract required under HIPAA between a covered entity (like your medical practice) and any vendor, called a business associate, that creates, receives, maintains, or transmits protected health information on the practice's behalf. It obligates the vendor to specific safeguards and breach-notification responsibilities. A marketing agency counts as a business associate the moment its work involves PHI, regardless of how the engagement is described in a sales conversation.

The decision checklist

Walk through these questions about your marketing agency's actual day-to-day access:

  • Does the agency manage or view patient communications, such as appointment requests, intake forms, or a patient-facing chat widget?
  • Does the agency have access to your CRM or EHR-adjacent system where patient records or identifiable health information live?
  • Does the agency manage call tracking that records or transcribes calls where patients discuss their care?
  • Does the agency configure analytics or ad pixels on pages where a visitor's activity could reveal a specific health condition or treatment interest tied to identifiable information?
  • Does the agency handle review requests or responses in a way that could confirm a specific person was a patient?

If you answered yes to any of these, a BAA is very likely required before that specific piece of work begins. If the agency's work is limited to public-facing content, general SEO, or ad creative that never touches identifiable patient data, a BAA may not be required for that narrower scope, though many practices choose to put one in place anyway as a standing safeguard.

What the BAA should actually specify

  • Exactly what categories of PHI the agency may access, and for what purpose
  • The safeguards the agency commits to (encryption, access controls, staff training)
  • Breach notification timelines and responsibilities if something goes wrong
  • What happens to any PHI the agency holds when the engagement ends

A BAA is not a substitute for good technical setup

Signing a BAA doesn't retroactively fix a tracking setup that's already leaking PHI to ad platforms. It's a legal safeguard that should sit alongside, not instead of, an actual technical review of your forms, pixels, and analytics. A signed BAA with an agency that's still capturing identifiable health data in a Google Ads conversion event doesn't solve the underlying problem.

Where Tridigiam fits in

We sign BAAs when our work calls for one, and we build tracking, forms, and campaigns with PHI exposure in mind from the first conversation rather than as an afterthought. We're a marketing agency, not a law firm or a certified HIPAA compliance auditor, so the specific language of your BAA and your practice's broader HIPAA compliance program should be reviewed by your own counsel or compliance officer. What we can do is tell you plainly, before an engagement starts, whether the scope of work we're discussing would require one.

For the fuller HIPAA-and-marketing picture, see our Medical Practice Marketing: The Complete Guide or our BAA marketing services page.

Frequently asked questions

What happens if an agency touches PHI without a signed BAA?

It's a HIPAA violation exposure for the covered entity, not just the vendor, and can carry real regulatory and financial consequences. It's worth confirming BAA status before any work begins, not assuming it's been handled.

Does a BAA cover subcontractors the agency uses?

Only if the BAA specifically addresses subcontractors, and HIPAA generally requires those subcontractors to sign their own BAA as well if they'll touch PHI. Ask directly whether your agency uses subcontractors for any part of the work that touches patient data.

How often should a BAA be reviewed or updated?

Whenever the scope of work changes in a way that changes what data the agency can access, and periodically as a general practice, since tools and workflows tend to evolve over the life of an engagement.

Need marketing that actually moves the needle?

Tridigiam is a Las Vegas marketing and advertising agency built for regulated and growth-focused businesses. Call (702) 748-7005 or request a consultation.