apointoo.
HIPAA

How to Build a BAA and Subprocessor Inventory

cmsapointoo··8 min read

Short answer: A BAA and subprocessor inventory should show every vendor, function, data category, region, agreement, access path, change notice, and return or destruction step. Build it from real data flows, not only procurement names. As of August 15, 2026, keep the inventory current and have qualified counsel review the HIPAA contract chain and any international transfer mechanism.

Vendor scope and BAA boundary

HHS sample business associate provisions describe terms that should flow through a defined relationship, including permitted uses, safeguards, incident reporting, cooperation, and return or destruction. The eCFR organizational requirements provide the regulatory context for business-associate arrangements. An inventory makes those terms operational by showing who receives what and why.

Start with the application data-flow map. Include the primary runtime and database, but also build systems, preview environments, error tracking, monitoring, email, SMS, queues, object storage, backups, key management, analytics, support tools, AI features, and contractors. If a service can receive a request body, record it. If a support engineer can view a record, record that access path.

The current source baseline was retrieved August 15, 2026. Subprocessor lists, regions, service features, BAA terms, and transfer rules can change. Each inventory row needs a last-verified date and a next-review trigger.

Feature, region, and subprocessor review

Inventory field Question Evidence
Vendor and function What service is performed and who directs it? Contract, statement of work, architecture map.
Data category Which fields and copies are received? Payload, schema, logs, queues, exports.
Agreement Which BAA, DPA, or security term applies? Effective contract, scope, notice, exit clause.
Region and access Where is data processed and who can support it? Location, identity, support, audit records.
Lifecycle How are changes, return, destruction, and deletion handled? Notice, export, deletion, verification evidence.

Do not group all cloud services under one provider row. A provider’s BAA may cover named services but not an external analytics destination or optional feature. Split rows when the purpose, data, region, or contract differs.

If EU personal data is involved, the European Commission’s international-transfer rules require a valid mechanism and safeguards for transfers outside the EEA. Remote support access can be relevant. Record the destination, access purpose, mechanism, supplementary safeguards, and counsel decision. HIPAA BAA review and GDPR transfer review are related but separate.

For Google Ads, record a separate disclosure row. Allow only generic conversion data after tenant-specific legal approval. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. Keep the integration disabled by default and document the recipient and policy review.

Use the cloud BAA checklist, the region-scope guide, and the shared-responsibility map for related controls.

Maintain the contract chain

For each row, identify the upstream party, downstream recipient, agreement owner, effective date, and termination behavior. Track whether the service is a business associate, subcontractor business associate, or another vendor with no access to protected data. Counsel should confirm the classification when the function or contract is ambiguous.

  • Keep a copy of the executed agreement and the version that was effective when data flowed.
  • Record permitted purpose, data category, incident notice clock, access support, and return or destruction terms.
  • Track changes to services, subprocessors, regions, features, and support personnel.
  • Require a review before enabling a new feature or sending a new field.
  • Link each row to security and risk evidence without copying unnecessary booking data into procurement tools.

A BAA does not prove that the application is compliant. The customer still owns tenant authorization, minimum necessary design, logs, backups, incident response, and retention. Keep provider evidence and customer evidence distinct.

Exit, support, and evidence questions

Run an offboarding exercise with synthetic data. Export records needed for continuity, revoke access, disable credentials, remove integrations, address backups and logs, request deletion where required, and record verification. Test what happens when a vendor changes a subprocessor or region. The inventory is useful only if it can drive an action.

Gate Pass condition Stop condition
Completeness All data recipients and copies appear in the inventory. Only procurement vendors are listed.
Agreement Each recipient has scope and effective terms. Provider page substitutes for a contract.
Transfer Regions and remote access have a legal review. Support access is invisible.
Exit Return, revoke, delete, and verify are tested. Backups or logs are not addressed.

Escalate when an unknown recipient appears in logs, when a vendor refuses needed terms, when a transfer mechanism is not documented, or when an advertising disclosure is proposed. Keep the service disabled until the row is approved.

Comparison decision checklist

  1. Trace every data flow and service dependency.
  2. Create one inventory row per function, data category, region, and agreement.
  3. Classify the role and contract chain with counsel.
  4. Review support, subprocessors, logs, backups, keys, and transfer mechanisms.
  5. Test change notice, offboarding, export, deletion, and incident escalation.
  6. Reopen after a material feature, vendor, region, or contract change.

Stop production onboarding when a recipient, agreement, region, or owner is unknown. The inventory is an approval gate, not a retrospective list.

Use data paths to find hidden subprocessors

Start with a request and trace it through every system. A web request may enter a runtime, call a database, emit a log, trigger a queue, send a message, create a backup, and appear in support tooling. A build can upload an artifact. A monitoring integration can receive an error. A human can export a report. Each destination belongs in the inventory if it receives data or can access it.

Compare technical evidence with procurement records. A vendor list may omit a service activated by a framework default or a cloud add-on. Logs and network traces can reveal a recipient that no contract list names. When a new recipient appears, disable or limit the flow, preserve evidence, and start the contract and role review.

Track changes and notice windows

Change Inventory action Approval
New feature Map fields, purpose, recipient, and region. Product, security, privacy.
New subprocessor Record contract, notice, access, and deletion. Procurement and counsel.
New region Review backup, support, transfer, and key paths. Privacy and tenant owner.
Incident Freeze deletion where required and link evidence. Incident lead and counsel.
Termination Export, revoke, destroy, and verify copies. Records and security.

Set a next-review date for each row, but do not wait for the calendar when a trigger occurs. A subprocessor change notice, new support country, new AI feature, backup migration, or new outbound field should reopen the row immediately.

Keep the inventory minimum necessary

The inventory needs enough detail to make a decision, not a copy of every booking record. Use field categories, examples that are synthetic, and opaque identifiers. Record whether a service receives a contact channel, appointment status, generic conversion event, or full record. Keep full data out of procurement notes and vendor tickets unless a reviewed process requires it.

For Google Ads, permit only generic conversion data after tenant-specific legal approval. Never send patient name, email, phone, hashed identifiers, service or treatment details, or clinical text. Keep the destination disabled by default and attach the approval reference to the inventory row. HIPAA contract review does not automatically approve advertising disclosure.

Make exit measurable

For each vendor, name the export format, return window, deletion request, backup treatment, key treatment, log treatment, and verification method. Test one synthetic offboarding path. If a vendor cannot explain deletion of a backup or support copy, record the gap and ask counsel whether the service can be used for the intended data.

Review inventory completeness with engineering, procurement, privacy, and security together. Each team sees different recipients and copies, so one owner should reconcile the final row set.

FAQ

What is the first verification step for a HIPAA subprocessor inventory?

Start with real data flows and list every service that can receive, store, log, back up, support, or export the data.

Which source or configuration detail could change the answer?

A new feature, subprocessor, region, support route, BAA term, backup, or international-access mechanism can change the inventory.

Does having an inventory prove compliance?

No. It proves a review structure. Contracts, controls, risk analysis, application configuration, and operations still need evidence.

What must be approved before a production claim or outbound action?

Approve recipient, purpose, fields, agreement, region, retention, and exact payload. For Google Ads, require tenant-specific legal approval and keep the event off.

References

Related articles