Radiology rules for compliance officers

Radiology BAA requirements for compliance officers include 45 CFR 164.504(e) clauses, subcontractor obligations, and the NRDR three year reuse rule.

Published 16 September 2026
Radiology compliance title card illustration

Yes. Radiology and imaging centers must execute a HIPAA Business Associate Agreement with any vendor that creates, receives, maintains, or transmits protected health information on their behalf. That covers PACS hosts, teleradiology reading partners, cloud DICOM storage, and AI diagnostic tools. If a signed BAA isn't in place, don't transmit a single study until it is.


TL;DR:

  • Vendors that store, transmit, or display patient-identifiable DICOM images must have a signed BAA before any PHI is shared, especially for cloud, AI, or third-party storage providers.
  • The BAA must include specific clauses on permitted uses, breach reporting, access rights, and subcontractor obligations, with signatures required prior to the first data transfer.
  • Subcontractors handling PHI also require their own signed BAAs with flow-down language, audit rights, and breach notification timelines to ensure full compliance.
  • Regular review and renewal of BAAs are crucial, with a recommended three-year maximum age for agreements signed after 2018 to stay aligned with current regulations.
  • AstraRad mandates a signed BAA before any study transmission and emphasizes operational clauses like turnaround times and data handling in vendor contracts.

Table of Contents

Who owns radiology BAA requirements inside the practice?

A radiology or imaging center is a HIPAA covered entity whenever it bills insurers or exchanges eligibility and claims data electronically, which describes nearly every practice in the United States. That status triggers the Hhs the moment PHI moves to an outside vendor.

Someone specific has to own this, and in most centers it splits three ways:

  • The compliance officer or privacy officer, who tracks which vendors touch PHI and confirms a BAA exists before onboarding.
  • The HIM director, who flags new data flows created by workflow changes (a new modality, a new referring portal).
  • The corporate account administrator, who actually signs and files the paperwork.

The rule that matters most: sign before the first transmission, not after. Sending studies to a teleradiology reading partner, uploading to a cloud PACS, or feeding images into an AI triage tool without a countersigned agreement already on file is a live violation, regardless of intent. AstraRad requires a fully executed BAA before it receives a single study from a new client, and that sequencing isn't a formality. It's the gating control that keeps a first integration test from becoming a reportable incident.

Which radiology vendors actually require a BAA?

Any vendor that stores or moves DICOM files carrying patient identifiers is functioning as a business associate, because those headers, patient name, medical record number, accession number, date of birth, qualify as PHI even when the image itself looks anonymous. That single fact is the reason the vendor list in radiology runs longer than most administrators expect:

  • PACS vendors and any hosted or cloud-based DICOM repository.
  • Teleradiology services and remote-reading partners, including subspecialist groups reading overnight or overflow volume.
  • AI diagnostic and triage tools that ingest images for prioritization, measurement, or preliminary flagging.
  • RIS platforms, referring-provider portals, and image-sharing tools used for outside consults.
  • Billing companies, medical transcription services, and outsourced administrative support handling patient records.

If a system can display, store, or forward an image tied to a name, it needs a BAA. Marketing language that calls a product HIPAA compliant is not the same as a signed agreement, and vendor sales sheets frequently blur that line.

What does 45 CFR 164.504(e) actually require in a BAA?

The regulation is specific, and radiology contracts get flagged during audits when they skip a clause rather than when they misstate one. The core elements 45 CFR 164.504(e) mandates are:

  • A description of permitted and required uses of PHI, limited to what the vendor needs to perform its function.
  • A prohibition on using or disclosing PHI beyond what the contract or law permits.
  • A requirement that the business associate implement Security Rule safeguards for electronic PHI.
  • A duty to report breaches and security incidents to the covered entity, ideally within a defined window.
  • Provisions supporting the patient's right to access, amend, and receive an accounting of disclosures.
  • A flow-down clause binding any subcontractor to the same restrictions.

In practice, "permitted uses" for a radiology vendor usually means: interpret the study, generate the report, and return both, nothing broader. Minimum necessary means a billing vendor doesn't need full imaging access, and an AI tool processing chest X-rays doesn't need access to unrelated modalities. Watch for termination language too. A well-drafted BAA lets the covered entity terminate on a pattern of violations, not just a single breach, and specifies a cure period rather than leaving remediation open-ended.

Do subcontractors need their own BAAs?

Yes, and this is the clause most radiology contracts get wrong. HHS Security Rule guidance makes clear that subcontractors of a business associate are themselves business associates, obligated to sign written agreements carrying the same restrictions as the original BAA. A teleradiology vendor that hosts studies on a third-party cloud platform must have its own signed BAA with that cloud provider, or your center remains exposed even though you never contracted directly with the subcontractor.

What to require in writing:

  • Explicit flow-down language naming subcontractor obligations, not a general reference to "applicable law."
  • Audit rights letting you request evidence of downstream agreements.
  • A defined notification timeline if a breach originates at the subcontractor level.

Pro Tip: Ask every vendor for a subcontractor list and copies of their downstream BAAs during onboarding, not after a breach. A vendor that resists sharing this is telling you something about how tightly they've documented their own supply chain.

How do you sign, submit, and renew radiology BAAs?

A working checklist for onboarding any new radiology vendor:

  1. Identify the relationship. Does this vendor create, receive, maintain, or transmit PHI? If yes, a BAA is mandatory.
  2. Request the vendor's standard BAA and compare it against the 45 CFR 164.504(e) elements above.
  3. Confirm subcontractor flow-down language before signing.
  4. Execute the agreement before any PHI moves, not after implementation begins.
  5. File the signed copy centrally and log the signature date, vendor name, and renewal trigger.

The ACR/NRDR registry program offers a concrete model for this discipline. A signed BAA is required for every corporate account, and NRDR will only accept a reused BAA if it was signed on or after 2018 and is less than three years old. Facilities must submit both a participation agreement and the BAA before any registry data submission proceeds. Apply that same age and reuse logic to your vendor contracts: stale BAAs signed under outdated regulatory language should trigger a renewal review, not a rubber stamp.

What contract language should you add for teleradiology and cloud vendors?

Beyond the baseline HIPAA elements, radiology-specific agreements need operational teeth. The clauses worth negotiating line by line:

  • Turnaround-time SLAs with an escalation path when a STAT read runs late.
  • Data retention and deletion timelines, including what happens to stored studies at contract termination.
  • DICOM metadata handling responsibilities, including who de-identifies images for research or AI training use.
  • Integration terms confirming studies flow through your existing PACS without forcing staff into a separate portal.
  • Audit and log access so you can verify who touched a study and when.

SLA compliance figures can offer a useful benchmark when comparing prospective vendors' contract terms. If a vendor doesn't put a specific SLA percentage in writing, that's a negotiation red flag, not a detail to skip past. Review our PACS integration workflow for a walkthrough of where BAA coverage needs to sit relative to the actual data path.

What are the breach notification timelines in a radiology BAA?

Under the Breach Notification Rule, business associates must report breaches of unsecured PHI to the covered entity, and Security Rule guidance from HHS expects that reporting to happen promptly, not on the vendor's own schedule. Most well-drafted radiology BAAs specify a concrete window, commonly within a set number of business days of discovery, rather than relying on vague statutory language.

Build cooperation duties into the contract itself:

  • A named contact responsible for incident notification on both sides.
  • Forensic support obligations if the vendor's systems are implicated.
  • Documentation requirements so your center can meet its own downstream notification duties to patients and, when thresholds are met, HHS.

Where compliance teams keep getting caught off guard

The most common oversight is simple: assuming a vendor's marketing language (HIPAA compliant, enterprise-grade security) substitutes for a signed BAA. It doesn't. The second most common failure is missing subcontractor flow-down entirely, discovered only after a breach traces back to a cloud host nobody vetted directly.

BAA flow-down from vendor to subcontractor

Three habits fix most of this. Keep a live vendor inventory tied to PHI exposure, not just contract value. Maintain a BAA tracker with signature dates and renewal triggers, the same discipline NRDR enforces with its three-year reuse window. Run a quarterly audit comparing active data flows against signed agreements on file.

Block time this month for a full BAA inventory review. Most centers find at least one vendor relationship that predates their current compliance process, and that gap is exactly where an OCR investigation starts.

Rafael Vieira

How AstraRad handles BAAs for teleradiology partnerships

AstraRad requires a signed BAA before receiving a single study, integrates directly into your existing PACS workflow without adding another portal for your team to manage, and reads through board-certified subspecialists licensed across the states where you operate. That combination matters because a compliant contract is only useful if the read quality and turnaround behind it actually hold up.

AstraRad teleradiology homepage with a chest X-ray open in the reading viewer

Compliance officers vetting a new teleradiology partner should ask for the SLA history, not just the BAA template. AstraRad backs guaranteed turnaround, under an hour for STAT cases, under 24 hours for routine studies, with 99.4% SLA compliance over the past year, and stringent peer review sits behind every signed report. If you're comparing per-report costs alongside compliance terms, check current teleradiology pricing by study type and request a compliance packet with a sample BAA to review against your own checklist before your next vendor decision.

Where to verify radiology BAA requirements

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources

FAQ

Do I need a BAA to be HIPAA compliant?

Yes. Any covered entity that shares PHI with a vendor performing services on its behalf must have a signed BAA in place before that data moves, per HHS guidance.

Does AstraRad require a BAA before reading studies?

Yes. AstraRad requires a fully executed BAA before receiving any imaging studies, and PHI transmission does not begin until that agreement is signed.

Do two covered entities need a BAA between them?

Generally no, when both parties are covered entities exchanging PHI for treatment purposes, a BAA isn't required. A BAA becomes necessary once one party is acting as a service provider handling PHI on the other's behalf.

How often should a BAA be updated?

There's no universal renewal calendar under HIPAA, but the ACR/NRDR program treats a BAA as reusable only if signed on or after 2018 and less than three years old, a useful benchmark for reviewing any radiology vendor contract.

Put a radiologist's name on your next read.

Tell us your modalities and monthly volume. A complete per-report rate card, with turnaround tiers and SLA terms in writing, lands in your inbox within one business day.