A business associate agreement is supposed to be the document that protects you.
Most of the ones in circulation were drafted to protect the vendor.
Scope
"HIPAA protected" is a floor, not a fence
HIPAA governs protected health information. Strip the identifiers and the data
stops being PHI — at which point HIPAA stops applying and the vendor may use it
however it sees fit. A BAA that promises HIPAA compliance is promising the floor.
It says nothing about what happens on the other side of de-identification.
Retention
Indefinite retention, unfettered internal use
Terms commonly allow data to be held indefinitely and used internally without
further limit — for product development, analytics, quality, "service
improvement," and whatever else that phrase is later read to cover. There is
usually no number in the retention clause and no ceiling on the internal use.
Deletion
"We erase your data" — which copy?
Deletion language routinely covers the identified record while staying silent on
what was captured and processed before it. If a de-identified derivative was
created upstream, erasing the original does not reach it. Ask specifically what
is generated from your data, when, and what deletion actually removes.
Leverage
Stock agreements, take it or leave it
Many vendors require you to accept their terms before you can use the tool at all,
and offer a stock BAA with no negotiation. You are agreeing to a document written
by the party it protects. And when the tool is free, the arrangement is not
charity — if you aren't paying for it, you're what's being sold.