Almost every healthcare organization relies on outside companies that touch protected health information, from the IT provider to the shredding service to the cloud software that stores records. HIPAA requires a written agreement with many of them, known as a business associate agreement, or BAA. Missing or outdated agreements are a common compliance gap, and an easy one to fix.
Under HIPAA, a business associate is a person or entity that performs functions or services for a covered entity involving the use or disclosure of PHI, or that creates, receives, maintains or transmits PHI on its behalf. Examples often include:
Managed IT and helpdesk providers who can access systems containing PHI
EHR and billing software vendors
Cloud hosting and backup providers
Email, eFax and messaging services that handle PHI
Billing and coding companies
Consultants and attorneys who receive PHI
Document destruction and storage companies
Telehealth platforms
A subcontractor that handles PHI for a business associate is also covered, which is why your vendors should have agreements with theirs.
Workforce members, and other healthcare providers involved in a resident's treatment, are generally not business associates for treatment disclosures. A janitorial service that has no meaningful access to PHI is typically not one, though that can depend on circumstances. Mere incidental exposure is treated differently from regular access. If you are unsure, ask your attorney or compliance advisor.
The HIPAA Privacy and Security Rules specify required elements. In summary, an agreement should:
Describe the permitted and required uses and disclosures of PHI
Prohibit the business associate from using or disclosing PHI other than as permitted or required by law
Require appropriate safeguards, and compliance with the Security Rule for electronic PHI
Require reporting of unauthorized uses or disclosures, security incidents and breaches of unsecured PHI
Require the business associate to ensure that subcontractors who handle PHI agree to the same restrictions
Provide access to PHI for individual rights, such as access, amendment and accounting of disclosures, where relevant
Make books and records available to HHS for compliance review
Require return or destruction of PHI at termination, if feasible
Allow you to terminate the contract if the business associate violates a material term
HHS provides sample BAA provisions on its website that you can use as a reference.
Beyond the required language, consider:
A specific timeframe for notifying you of a breach, such as a number of days
Responsibility for costs of notification and mitigation when the vendor is at fault
Cyber liability insurance requirements
Location of data storage
Clear data return and deletion procedures with timelines
These are business and legal decisions, so involve counsel.
Create a spreadsheet or tracker listing each business associate, what PHI they handle, the service, the BAA date, renewal or review date, and a contact person.
Make it a rule that no vendor gets access to PHI until a BAA is signed. Add the check to your purchasing or onboarding process.
At least annually, confirm the list is current, agreements are still in force and former vendors no longer hold data. Request confirmation of deletion where appropriate.
Store signed agreements where compliance staff can find them quickly, along with correspondence about incidents.
Free or consumer tools used for PHI without any agreement
A vendor that refuses to sign a BAA yet receives PHI
Agreements signed years ago, never reviewed after services changed
No record of which departments adopted which tools
Staff using personal email or messaging apps to share resident information
If your organization provides services to other covered entities, you are directly subject to many HIPAA requirements and need your own compliance program.
UnityCare IT signs business associate agreements with healthcare clients and can help you identify which of your technology vendors need one. This article is general information, not legal advice, so please consult your attorney about specific agreements.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034