Business Associate Agreements: A Plain-English Walkthrough

Almost every healthcare organization relies on outside companies that touch protected health information, from the IT provider to the shredding service to the cloud software that stores records. HIPAA requires a written agreement with many of them, known as a business associate agreement, or BAA. Missing or outdated agreements are a common compliance gap, and an easy one to fix.

Who Is a Business Associate?

Under HIPAA, a business associate is a person or entity that performs functions or services for a covered entity involving the use or disclosure of PHI, or that creates, receives, maintains or transmits PHI on its behalf. Examples often include:

Managed IT and helpdesk providers who can access systems containing PHI

EHR and billing software vendors

Cloud hosting and backup providers

Email, eFax and messaging services that handle PHI

Billing and coding companies

Consultants and attorneys who receive PHI

Document destruction and storage companies

Telehealth platforms

A subcontractor that handles PHI for a business associate is also covered, which is why your vendors should have agreements with theirs.

Who Is Not

Workforce members, and other healthcare providers involved in a resident's treatment, are generally not business associates for treatment disclosures. A janitorial service that has no meaningful access to PHI is typically not one, though that can depend on circumstances. Mere incidental exposure is treated differently from regular access. If you are unsure, ask your attorney or compliance advisor.

What a BAA Must Include

The HIPAA Privacy and Security Rules specify required elements. In summary, an agreement should:

Describe the permitted and required uses and disclosures of PHI

Prohibit the business associate from using or disclosing PHI other than as permitted or required by law

Require appropriate safeguards, and compliance with the Security Rule for electronic PHI

Require reporting of unauthorized uses or disclosures, security incidents and breaches of unsecured PHI

Require the business associate to ensure that subcontractors who handle PHI agree to the same restrictions

Provide access to PHI for individual rights, such as access, amendment and accounting of disclosures, where relevant

Make books and records available to HHS for compliance review

Require return or destruction of PHI at termination, if feasible

Allow you to terminate the contract if the business associate violates a material term

HHS provides sample BAA provisions on its website that you can use as a reference.

Practical Terms Worth Negotiating

Beyond the required language, consider:

A specific timeframe for notifying you of a breach, such as a number of days

Responsibility for costs of notification and mitigation when the vendor is at fault

Cyber liability insurance requirements

Location of data storage

Clear data return and deletion procedures with timelines

These are business and legal decisions, so involve counsel.

Keeping Agreements Organized

Build a vendor register

Create a spreadsheet or tracker listing each business associate, what PHI they handle, the service, the BAA date, renewal or review date, and a contact person.

Tie BAAs to purchasing

Make it a rule that no vendor gets access to PHI until a BAA is signed. Add the check to your purchasing or onboarding process.

Review periodically

At least annually, confirm the list is current, agreements are still in force and former vendors no longer hold data. Request confirmation of deletion where appropriate.

Keep copies accessible

Store signed agreements where compliance staff can find them quickly, along with correspondence about incidents.

Common Problems

Free or consumer tools used for PHI without any agreement

A vendor that refuses to sign a BAA yet receives PHI

Agreements signed years ago, never reviewed after services changed

No record of which departments adopted which tools

Staff using personal email or messaging apps to share resident information

When You Are the Business Associate

If your organization provides services to other covered entities, you are directly subject to many HIPAA requirements and need your own compliance program.

How UnityCare IT Fits In

UnityCare IT signs business associate agreements with healthcare clients and can help you identify which of your technology vendors need one. This article is general information, not legal advice, so please consult your attorney about specific agreements.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034