Behind every care organization is a long list of outside companies that touch resident or patient information: the EMR vendor, the IT provider, a shredding service, a cloud storage tool, a billing company, a therapy contractor. Under HIPAA, many of those relationships require a written business associate agreement, or BAA. When a vendor is breached, regulators and plaintiffs often ask a simple question first: did you have a proper agreement in place?
This checklist helps administrators and compliance officers sort out who needs one and what a good agreement covers.
A business associate is a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information (PHI) on your behalf, or provides certain services to you that involve PHI. Examples include:
IT and managed service providers with access to systems holding PHI
Cloud hosting, backup and email providers
Billing, coding and collections companies
Document shredding and records storage companies
Consultants, attorneys and accountants who handle PHI
Software vendors with access to data while supporting you
A subcontractor that handles PHI for your business associate is also covered, which is why your vendor needs its own agreements downstream.
Some relationships do not require one, such as workforce members, other providers receiving PHI for treatment of a resident, and organizations acting purely as a conduit like the postal service. Janitorial services without access to PHI generally do not either, though incidental exposure should be addressed through policy. When unsure, ask your compliance officer or counsel instead of guessing.
The HIPAA rules list required contents. In plain terms, the agreement should:
Describe the permitted uses and disclosures of PHI, and prohibit any other use
Require the vendor to use appropriate safeguards, and to comply with the Security Rule for electronic PHI
Require the vendor to report breaches, security incidents and unauthorized uses to you
Require the vendor to ensure that subcontractors agree to the same restrictions
Support individuals' rights, such as access to records and accounting of disclosures when applicable
Make the vendor's books and practices available to HHS for compliance review
Require return or destruction of PHI when the relationship ends, where feasible
Allow you to terminate the contract if the vendor violates a material term
Beyond the required terms, think through practical details.
Breach reporting timeline. A specific number of days gives you a way to hold the vendor accountable. Shorter is better, since your own legal clock may start when you learn of the breach.
Security expectations. Encryption, multi-factor authentication and audit logging are reasonable asks.
Cost and responsibility for breach notification, credit monitoring and investigation.
Insurance. Ask whether the vendor carries cyber liability coverage.
Data location. Know whether data is stored in the United States.
Offboarding. Describe how you will get your data back and how deletion will be verified.
The agreement is only useful if you know where it is. Create a simple register with the following columns.
Vendor name and contact
Services provided and type of PHI accessed
BAA signed date and renewal or review date
Where the signed copy is stored
Security documentation requested, such as a questionnaire or a third-party report
Last review date and owner
Review the list at least annually, and whenever you sign a new contract. Add a step to purchasing: no vendor gets access to PHI until compliance has checked whether a BAA is needed.
A signed agreement does not make a vendor secure. For higher-risk vendors, ask for evidence of security practices.
A completed security questionnaire
Summary of an independent audit, where available
Details of their incident response and backup practices
Confirmation of staff training and background checks
Proportion your effort to the risk. A vendor that hosts your entire document system warrants more scrutiny than one that occasionally sees a name on a schedule.
Using free or consumer tools, such as personal file-sharing accounts, with PHI and no BAA
Assuming the vendor's standard terms of service are sufficient
Never updating agreements after services change
Losing the signed copy, or never obtaining the countersignature
Forgetting that your IT provider needs an agreement too
As a managed IT provider serving healthcare organizations, UnityCare IT signs business associate agreements with the clients it supports. We can also help you inventory which technology vendors have access to PHI and flag the ones that deserve a closer look.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172