HIPAA Business Associate Agreement for VPN vendors

If your practice, clinic, or healthcare-adjacent business is looking at VPN vendors, the very first question you should be asking is not "what encryption does it use?" — it is "will you sign a Business Associate Agreement?"

Everything else — AES-256, no-logs, kill switches, split tunneling — is table stakes that a dozen consumer VPNs can check. The BAA question is the one that separates vendors who can legally carry your PHI from vendors who cannot, regardless of how strong their crypto is.

And most consumer VPN providers cannot. Not because their technology is weak, but because their business model refuses the legal obligations that come with signing.

What a Business Associate Agreement Actually Is

The Business Associate Agreement (BAA) is defined in the HIPAA regulations at 45 CFR § 164.504(e). It is a written contract between a HIPAA-covered entity — a healthcare provider, health plan, or healthcare clearinghouse — and a "business associate," which is any vendor that creates, receives, maintains, or transmits Protected Health Information (PHI) on the covered entity's behalf.

The BAA is not optional. Under the HIPAA Omnibus Rule of 2013, if you exchange PHI with a vendor without a signed BAA in place, that is itself a HIPAA violation — a "willful neglect" category that carries the highest tier of fines (currently up to $1.9 million per violation category per year, per HHS OCR's annually adjusted penalty schedule).

⚠️ The trap: Many practices assume "we chose a secure VPN, so we're fine." That is not how HIPAA works. Security is one axis; legal contractual coverage is another. You need both. Encryption without a BAA is still a violation. A BAA without adequate encryption is also a violation. Both parts have to be in place.

What a BAA Legally Obligates a Vendor To Do

A BAA is not a formality. It is a binding contract that pushes real, enforceable obligations onto the vendor. At minimum, per the regulation, a BAA must require the business associate to:

  • Use PHI only for the purposes permitted by the contract
  • Implement appropriate safeguards to protect PHI
  • Report any PHI breach to the covered entity, generally within 60 days of discovery under 45 CFR § 164.410
  • Ensure any subcontractors that touch PHI enter into their own BAAs (the "downstream BAA" requirement)
  • Return or destroy all PHI at the end of the contract
  • Make its books, records, and internal practices available to HHS for enforcement purposes

That last bullet is the one most vendors quietly refuse to sign. Making your operational records available to the Department of Health and Human Services for federal audit is a serious commitment. It converts the VPN provider from a consumer-facing product into a regulated party subject to OCR enforcement. Most global consumer VPN businesses do not want that exposure.

Why a VPN Almost Always Qualifies as a Business Associate

There is a technical argument some providers make: "we do not store PHI, we only transmit encrypted traffic — so we are not a business associate." This argument fails.

The HIPAA definition at 45 CFR § 160.103 explicitly includes vendors that "transmit" PHI, not just those that store it. And in its official Business Associate guidance, HHS has clarified that "conduit" exceptions are narrow — reserved for entities like the postal service or a general-purpose internet service provider that provide transmission with only random or incidental access to PHI.

A VPN that a healthcare organization deploys specifically to secure remote clinical access is not a "random conduit." It is a purpose-built tool for handling PHI. That makes the VPN vendor a business associate. HHS has published enforcement actions confirming this reading, and the industry treats it as settled.

Why Most Consumer VPN Providers Refuse to Sign

Here is the honest structural reason: signing a BAA is expensive, legally exposing, and operationally demanding. It requires the VPN provider to:

Maintain HIPAA-grade operational security

Encryption in transit is the easy part. HIPAA also demands administrative safeguards (workforce training, access management, incident response), physical safeguards (data center security controls), and audit controls — none of which a consumer-focused VPN business is optimized to prove.

Accept 60-day breach notification obligations

Under 45 CFR § 164.410, a business associate must notify the covered entity of a breach involving PHI without unreasonable delay and no later than 60 days from discovery. That is a real operational commitment: a dedicated incident response process, forensic capacity, legal review, and formal notification workflows. Most consumer VPN providers do not run their support and security operations to that standard.

Manage subcontractors under downstream BAAs

A VPN provider uses many downstream vendors — data centers, monitoring tools, backend cloud services. Under HIPAA, each of those subcontractors that could touch PHI also needs a BAA with the VPN provider. That is a legal supply chain most consumer VPN businesses have never mapped.

Submit to HHS OCR enforcement

By signing a BAA, the vendor is now directly liable to OCR under the HITECH Act. OCR can (and does) audit business associates directly, not just covered entities. Consumer VPN companies do not want that jurisdiction — many are headquartered outside the US precisely to avoid US regulatory exposure.

💡 Practical reality: When you ask a global consumer VPN provider "will you sign a BAA," you are effectively asking them to change their business model. Most decline politely, some try to sell you an "enterprise" plan that quietly does not include a BAA either, and a few will simply not respond.

How to Actually Verify a Vendor Will Sign

Do not accept "we're HIPAA-compliant" as an answer. HIPAA compliance is a property of your program, not of any single vendor. Ask specific, discrete questions:

  1. "Do you sign a Business Associate Agreement?" — yes or no answer required.
  2. "Can I see a sample BAA before purchase?" — legitimate vendors will provide a template. Vendors who cannot are usually improvising and may not have a real one.
  3. "Is the BAA included in the plan I'm purchasing, or is it a paid add-on?" — some vendors gate the BAA behind a much more expensive tier without disclosing it upfront.
  4. "Which specific product SKU is the BAA scoped to?" — a BAA is scoped to specific services. Make sure it covers the VPN service you are actually deploying, not a different product line.
  5. "What is your breach notification process, and do you carry cyber liability insurance?" — a business associate that cannot answer these questions has not thought through what signing the BAA actually means.

Get answers in writing. Save them. If you are ever audited by OCR, your due diligence documentation is what protects you.

The CyberFence Position

CyberFence Teams offers a Business Associate Agreement to covered entities and their subcontractors on request. It is available as part of the Teams onboarding and is scoped explicitly to the VPN and threat-protection services CyberFence provides.

The BAA is one part of a compliance posture that also includes encryption of PHI in transit, US-based infrastructure and jurisdiction (which avoids international data transfer complications under HIPAA), and audit-friendly logging on the customer-administrator side. For a broader walkthrough of what HIPAA actually requires from a VPN, see our HIPAA-Compliant VPN Guide.

CyberFence being a US-headquartered, US-operated company is not a marketing point in this context — it is a compliance one. A BAA is only useful if the vendor is realistically subject to US enforcement. Signing a BAA with a vendor that is judgment-proof in a foreign jurisdiction is a paper commitment with no teeth.

What This Means If You're Making a Decision

If you are a covered entity — a medical practice, clinic, hospital, health plan, medical billing company, healthcare IT provider, or a legal firm handling healthcare cases — and you are choosing a VPN vendor, the BAA question is a hard gate. Not a nice-to-have. A gate.

Any vendor that will not sign one is not a valid option, no matter how strong their encryption or how good their pricing. Any vendor that will sign one still needs to prove it meets the Security Rule's technical safeguards. Only vendors that clear both bars belong on your shortlist.

CyberFence clears both, is US-based, and prices its Teams plan for small practices rather than enterprises alone. If you would like to see the BAA or start a Teams deployment, visit our Teams page or contact us directly.