Business Associate Agreements Explained: An Administrator Walkthrough

Few HIPAA topics generate as many questions from administrators as business associate agreements. Do we need one for the shredding company? What about our IT provider? What does the document actually have to say? This walkthrough explains the essentials in plain language. It is general information, not legal advice, so consult your attorney for specific situations.

Who is a business associate

Under HIPAA, a business associate is a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information on your behalf, or provides certain services to you that involve access to PHI. Common examples in a long-term care or clinic setting include:

Managed IT and helpdesk providers with access to systems containing PHI

Cloud hosting, backup and email providers that store PHI

EMR and billing software vendors

eFax and document-scanning services

Consultants, accountants and attorneys who handle PHI

Shredding or records storage companies

Therapy or pharmacy services in certain arrangements, depending on the relationship

Subcontractors of business associates that handle PHI are also business associates, which creates a chain of obligations.

Who is not a business associate

Some relationships do not require a BAA. Disclosures to another provider for treatment purposes generally do not create a business associate relationship. A janitorial company that is not intended to have access to PHI is typically not a business associate, though you should keep PHI secured and limit incidental exposure. Whether a vendor qualifies depends on facts, not labels, so when in doubt, ask your compliance advisor.

What the agreement must contain

The HIPAA Privacy and Security Rules specify required content. In general, a BAA must:

Describe the permitted and required uses and disclosures of PHI

Prohibit the business associate from using or disclosing PHI other than as permitted by the contract or as required by law

Require appropriate safeguards, and compliance with the Security Rule for electronic PHI

Require the business associate to report to you any use or disclosure not allowed by the contract, including breaches of unsecured PHI and security incidents

Require subcontractors that handle PHI to agree to the same restrictions

Make PHI available so individuals can exercise their rights of access, amendment and an accounting of disclosures

Allow HHS to review the business associate's practices where needed

Require return or destruction of PHI at termination, where feasible

Allow you to terminate the contract if the business associate violates a material term

Terms worth negotiating

Beyond the required language, consider asking for:

A specific timeframe for incident notification, such as a number of days, that supports your own breach notification deadlines

Clarity on who bears costs of notification, credit monitoring and investigation after a breach caused by the vendor

Cooperation duties during investigations

Insurance requirements

Rights to receive security documentation or audit results

Data location and offshore handling restrictions

Your attorney can help you decide which fit your risk level.

Common mistakes

No agreement at all. Using a vendor for PHI without a BAA is itself a HIPAA problem. Enforcement actions have involved missing agreements.

Outdated templates. Agreements written before the 2013 Omnibus Rule updates may not reflect current requirements.

Signed and forgotten. Contracts sit in a drawer with no owner, review date or vendor list.

Assuming the vendor's standard terms are enough. Review them for notification timing, subcontractor flow-down and termination language.

What to do if a vendor will not sign

If a vendor handles PHI for you and declines to sign a BAA, treat that as a stop sign. Options include choosing a different vendor, restructuring the service so the vendor never accesses PHI, or having counsel evaluate the situation. Do not ignore it.

Build a simple tracking process

Create a list of all vendors and flag those that touch PHI

Record BAA status, signature date and renewal or review date

Assign a responsible owner for each vendor

Review vendors annually and when services change

Keep copies where compliance staff can find them quickly

Your own role as a business associate

If you are an IT provider, billing company or consultant, you have direct obligations under the Security Rule and the breach notification requirements. Organizations that serve healthcare should be able to explain their safeguards clearly.

UnityCare IT signs business associate agreements with its healthcare clients and can help you inventory vendors, spot gaps and align technical safeguards with your agreements. If you are cleaning up your vendor files, we are happy to assist.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034