Business Associate Agreements: A Vendor Management Checklist

Your organization may have strong internal safeguards and still be exposed through a vendor. Under HIPAA, covered entities must have a written business associate agreement, or BAA, with any business associate that creates, receives, maintains or transmits protected health information on their behalf. Many practices and facilities have gaps: a vendor with no agreement, an agreement nobody can find, or a contract that was signed once and never reviewed.

This checklist will help you bring order to the process.

Who counts as a business associate?

A business associate is a person or entity that performs a function or service for you that involves PHI. Common examples in long-term care and clinics include:

EHR and practice management vendors

Managed IT and helpdesk providers with access to systems holding PHI

Cloud hosting and backup providers

eFax and secure messaging services

Billing, coding and collections companies

Transcription services

Document shredding and records storage companies

Consultants and attorneys who see PHI

Email and productivity platforms where PHI may be present

A person who only sees PHI incidentally, such as a janitorial staff member, is generally not a business associate, though reasonable safeguards still apply. When unsure, ask your privacy officer or counsel.

Step 1: Build a vendor inventory

Create a spreadsheet of every vendor, and mark whether they touch PHI. Pull names from accounts payable, software license lists, your IT environment and department managers. Departments often buy tools on their own, such as scheduling or survey software, without telling IT or compliance.

For each vendor, record:

Services provided and the type of PHI involved

Business owner inside your organization

Whether a BAA is in place, and its date

Contract renewal date

Security contact and incident reporting contact

Step 2: Check the agreement itself

HIPAA lists required elements for a BAA. In general, confirm that the agreement:

Limits the vendor's use and disclosure of PHI to what is permitted by the contract and law

Requires appropriate safeguards, including compliance with the Security Rule for electronic PHI

Requires the vendor to report breaches and security incidents to you, ideally with a defined timeline

Requires subcontractors that handle PHI to agree to the same restrictions

Supports your obligations to provide access, amendments and an accounting of disclosures where relevant

Describes the return or destruction of PHI when the relationship ends

Allows termination if the vendor violates the agreement

A vendor's standard terms may be vague, so consider negotiating a specific reporting window, such as a number of days to notify you of an incident.

Step 3: Ask security questions

A signed agreement is a legal minimum, not proof of good security. Before you sign, and periodically afterward, ask:

Do you encrypt data at rest and in transit?

Do you use multi-factor authentication for staff accessing our data?

Where is our data stored and who can see it?

How do you handle backups and disaster recovery?

Have you had an independent security assessment or audit?

What is your process for notifying customers of an incident?

Which subcontractors do you use?

Scale the depth of review to the risk. A vendor hosting your entire EHR deserves more scrutiny than a scheduling add-on that sees only names.

Step 4: Control access

Vendors with remote access to your network are a frequent entry point for attackers.

Give each vendor individual accounts, not a shared login

Limit access to the systems they need

Require multi-factor authentication

Enable access only when needed and review logs

Remove accounts promptly when a contract ends

Step 5: Review on a schedule

Set an annual calendar reminder to confirm that the inventory, agreements and contacts are current. Renewals are a good moment to revisit terms and security answers.

Step 6: Plan for exit

Before signing, ask how you can get your data back in a usable format and how deletion will be confirmed. Hold a plan for what happens if the vendor suffers a breach or goes out of business.

Documentation you should keep

Signed BAAs and amendments

The vendor inventory with review dates

Security questionnaires and responses

Notes of any vendor incidents and your follow-up

These records support your HIPAA documentation and help during audits or investigations.

Getting support

UnityCare IT helps healthcare organizations inventory vendors, review technical safeguards and manage remote access. We also sign business associate agreements for our own managed services. If your vendor list is overdue for a cleanup, we are glad to help you start.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172