Every healthcare organization works with outside companies: billing services, IT providers, shredding companies, cloud hosts, answering services, consultants. Under HIPAA, many of them are business associates, which means that if they create, receive, maintain or transmit protected health information for you, a written agreement is required.
Many facilities have a folder of agreements that were signed once and never looked at again. A periodic review catches missing agreements, expired contacts and vendors who no longer meet your expectations.
In general, a business associate is a person or organization that performs a function or service for a covered entity that involves PHI. Examples include:
Managed IT and cloud providers that can access systems containing PHI
Electronic health record vendors
Billing, coding and collections companies
Outsourced transcription or answering services
Shredding and records storage companies
Attorneys, accountants and consultants who see PHI
Email, fax and secure messaging services that store or transmit PHI
HHS has also said that a cloud service provider that stores ePHI is a business associate even if it cannot view the data. Subcontractors of business associates are included too.
A member of your workforce is not a business associate, and a provider who receives PHI for treatment purposes generally does not need one for that disclosure. When in doubt, ask your compliance officer or counsel.
Pull data from accounts payable, IT, department heads and your contract files. Mark each vendor as yes, no or unsure for PHI access. Resolve the unsure ones.
For each business associate, check that:
A signed agreement is on file
It is signed by someone with authority
It is currently in effect, including after any acquisition, rename or contract renewal
Subcontractors are covered by flow-down terms
The HIPAA Rules describe required content. Look for:
Permitted uses and disclosures: what the vendor may do with PHI, and nothing beyond that
Safeguards: a commitment to appropriate administrative, physical and technical safeguards for ePHI, as required by the Security Rule
Reporting: a duty to report security incidents, breaches and unauthorized uses, with a timeframe
Subcontractors: requirements that downstream vendors agree to the same restrictions
Individual rights support: access, amendment and accounting of disclosures where relevant
Books and records: availability to HHS for compliance reviews
Termination: the ability to end the contract if the vendor violates the agreement, and return or destruction of PHI when it ends
Set notification timeframes that fit your obligations. Since you may have to notify individuals without unreasonable delay and no later than 60 days after discovering a breach, a vendor that takes weeks to tell you leaves little room.
A signed agreement does not make a vendor secure. Ask for:
A summary of their security program or recent assessments
Whether they use multi-factor authentication and encryption
How they handle employee access and training
Where your data is stored and who can see it
Match your diligence to the risk. A cloud EHR deserves more scrutiny than a document shredder.
Keep a register with vendor, services, agreement date, renewal date, contact and last review. Check it at least annually, and when a contract ends, confirm that PHI has been returned or destroyed and access removed.
Agreements missing for IT or cloud vendors added informally
Old agreements that do not mention current breach reporting requirements
No record of what happened to data when a vendor was replaced
Assuming a vendor's standard terms satisfy HIPAA without reading them
No process to review new vendors before they get access
The cleanest fix is a rule: no vendor receives PHI or system access until compliance has confirmed the agreement and security review. Add it to your purchasing checklist.
UnityCare IT works as a business associate for many healthcare clients, and we can help you map your vendor landscape and identify which relationships need attention.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172