Your organization may have strong internal safeguards and still be exposed through a vendor. Under HIPAA, covered entities must have a written business associate agreement, or BAA, with any business associate that creates, receives, maintains or transmits protected health information on their behalf. Many practices and facilities have gaps: a vendor with no agreement, an agreement nobody can find, or a contract that was signed once and never reviewed.
This checklist will help you bring order to the process.
A business associate is a person or entity that performs a function or service for you that involves PHI. Common examples in long-term care and clinics include:
EHR and practice management vendors
Managed IT and helpdesk providers with access to systems holding PHI
Cloud hosting and backup providers
eFax and secure messaging services
Billing, coding and collections companies
Transcription services
Document shredding and records storage companies
Consultants and attorneys who see PHI
Email and productivity platforms where PHI may be present
A person who only sees PHI incidentally, such as a janitorial staff member, is generally not a business associate, though reasonable safeguards still apply. When unsure, ask your privacy officer or counsel.
Create a spreadsheet of every vendor, and mark whether they touch PHI. Pull names from accounts payable, software license lists, your IT environment and department managers. Departments often buy tools on their own, such as scheduling or survey software, without telling IT or compliance.
For each vendor, record:
Services provided and the type of PHI involved
Business owner inside your organization
Whether a BAA is in place, and its date
Contract renewal date
Security contact and incident reporting contact
HIPAA lists required elements for a BAA. In general, confirm that the agreement:
Limits the vendor's use and disclosure of PHI to what is permitted by the contract and law
Requires appropriate safeguards, including compliance with the Security Rule for electronic PHI
Requires the vendor to report breaches and security incidents to you, ideally with a defined timeline
Requires subcontractors that handle PHI to agree to the same restrictions
Supports your obligations to provide access, amendments and an accounting of disclosures where relevant
Describes the return or destruction of PHI when the relationship ends
Allows termination if the vendor violates the agreement
A vendor's standard terms may be vague, so consider negotiating a specific reporting window, such as a number of days to notify you of an incident.
A signed agreement is a legal minimum, not proof of good security. Before you sign, and periodically afterward, ask:
Do you encrypt data at rest and in transit?
Do you use multi-factor authentication for staff accessing our data?
Where is our data stored and who can see it?
How do you handle backups and disaster recovery?
Have you had an independent security assessment or audit?
What is your process for notifying customers of an incident?
Which subcontractors do you use?
Scale the depth of review to the risk. A vendor hosting your entire EHR deserves more scrutiny than a scheduling add-on that sees only names.
Vendors with remote access to your network are a frequent entry point for attackers.
Give each vendor individual accounts, not a shared login
Limit access to the systems they need
Require multi-factor authentication
Enable access only when needed and review logs
Remove accounts promptly when a contract ends
Set an annual calendar reminder to confirm that the inventory, agreements and contacts are current. Renewals are a good moment to revisit terms and security answers.
Before signing, ask how you can get your data back in a usable format and how deletion will be confirmed. Hold a plan for what happens if the vendor suffers a breach or goes out of business.
Signed BAAs and amendments
The vendor inventory with review dates
Security questionnaires and responses
Notes of any vendor incidents and your follow-up
These records support your HIPAA documentation and help during audits or investigations.
UnityCare IT helps healthcare organizations inventory vendors, review technical safeguards and manage remote access. We also sign business associate agreements for our own managed services. If your vendor list is overdue for a cleanup, we are glad to help you start.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172