Business Associate Agreements: A Practical Review Checklist

Every healthcare organization works with outside companies: billing services, IT providers, shredding companies, cloud hosts, answering services, consultants. Under HIPAA, many of them are business associates, which means that if they create, receive, maintain or transmit protected health information for you, a written agreement is required.

Many facilities have a folder of agreements that were signed once and never looked at again. A periodic review catches missing agreements, expired contacts and vendors who no longer meet your expectations.

Who counts as a business associate?

In general, a business associate is a person or organization that performs a function or service for a covered entity that involves PHI. Examples include:

Managed IT and cloud providers that can access systems containing PHI

Electronic health record vendors

Billing, coding and collections companies

Outsourced transcription or answering services

Shredding and records storage companies

Attorneys, accountants and consultants who see PHI

Email, fax and secure messaging services that store or transmit PHI

HHS has also said that a cloud service provider that stores ePHI is a business associate even if it cannot view the data. Subcontractors of business associates are included too.

A member of your workforce is not a business associate, and a provider who receives PHI for treatment purposes generally does not need one for that disclosure. When in doubt, ask your compliance officer or counsel.

Step 1: Build a complete vendor list

Pull data from accounts payable, IT, department heads and your contract files. Mark each vendor as yes, no or unsure for PHI access. Resolve the unsure ones.

Step 2: Confirm an agreement exists

For each business associate, check that:

A signed agreement is on file

It is signed by someone with authority

It is currently in effect, including after any acquisition, rename or contract renewal

Subcontractors are covered by flow-down terms

Step 3: Review what the agreement should include

The HIPAA Rules describe required content. Look for:

Permitted uses and disclosures: what the vendor may do with PHI, and nothing beyond that

Safeguards: a commitment to appropriate administrative, physical and technical safeguards for ePHI, as required by the Security Rule

Reporting: a duty to report security incidents, breaches and unauthorized uses, with a timeframe

Subcontractors: requirements that downstream vendors agree to the same restrictions

Individual rights support: access, amendment and accounting of disclosures where relevant

Books and records: availability to HHS for compliance reviews

Termination: the ability to end the contract if the vendor violates the agreement, and return or destruction of PHI when it ends

Set notification timeframes that fit your obligations. Since you may have to notify individuals without unreasonable delay and no later than 60 days after discovering a breach, a vendor that takes weeks to tell you leaves little room.

Step 4: Look beyond the paperwork

A signed agreement does not make a vendor secure. Ask for:

A summary of their security program or recent assessments

Whether they use multi-factor authentication and encryption

How they handle employee access and training

Where your data is stored and who can see it

Match your diligence to the risk. A cloud EHR deserves more scrutiny than a document shredder.

Step 5: Track and renew

Keep a register with vendor, services, agreement date, renewal date, contact and last review. Check it at least annually, and when a contract ends, confirm that PHI has been returned or destroyed and access removed.

Common gaps

Agreements missing for IT or cloud vendors added informally

Old agreements that do not mention current breach reporting requirements

No record of what happened to data when a vendor was replaced

Assuming a vendor's standard terms satisfy HIPAA without reading them

No process to review new vendors before they get access

Make it part of procurement

The cleanest fix is a rule: no vendor receives PHI or system access until compliance has confirmed the agreement and security review. Add it to your purchasing checklist.

UnityCare IT works as a business associate for many healthcare clients, and we can help you map your vendor landscape and identify which relationships need attention.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172