Every year, regulators find organizations that shared protected health information with a vendor without a proper contract in place. The paperwork is not exciting, but it is one of the clearest compliance requirements in HIPAA, and it is easy to get wrong when a facility works with many vendors and the list changes over time.
Under HIPAA, a business associate is a person or company that performs a function or service for a covered entity involving the use or disclosure of protected health information. Covered entities include most healthcare providers that bill electronically, such as nursing facilities, clinics and many senior living operators with licensed care.
Common business associates include:
Your EMR or electronic health record vendor.
Managed IT and cybersecurity providers with access to systems containing PHI.
Cloud hosting and backup providers.
Billing and revenue cycle companies.
Outside therapy, pharmacy and consulting services that handle PHI on your behalf.
Document shredding and records storage companies.
eFax and email service providers.
Attorneys and accountants who see PHI.
Not everyone who touches your building is a business associate. A janitorial service typically is not, though the line depends on whether PHI is accessed. Another provider treating the same resident may be a different kind of relationship. When unsure, ask your privacy officer or counsel.
The HIPAA rules require a written contract, called a business associate agreement or BAA, that includes certain terms. In general, the business associate must:
Use and disclose PHI only as permitted by the contract or required by law.
Use appropriate safeguards and, for electronic PHI, comply with the Security Rule.
Report breaches and security incidents to you.
Ensure that subcontractors that handle PHI agree to the same restrictions.
Make PHI available so you can honor patient rights such as access and amendment.
Return or destroy PHI at the end of the relationship, where feasible.
Make its practices available to HHS for compliance reviews.
You can usually use the vendor's template, but you should read it. Template terms do not always favor you.
Breach notification timing. HIPAA sets an outer limit, but many covered entities prefer faster notice so they can meet their own deadlines. Look for a specific number of days, and the contents of the notice.
Subcontractors. Know who else may touch your data and where.
Liability and indemnification. Understand who bears the costs of a breach, such as notification, credit monitoring and investigation.
Insurance. Ask whether the vendor carries cyber liability coverage.
Data return and deletion. Confirm how you get your data back and how deletion is verified.
Audit rights. Know whether you can request evidence of their security practices.
Create a simple spreadsheet listing:
Vendor name and service.
Type of PHI involved.
BAA signed date and renewal or review date.
Contract owner internally.
Security contact at the vendor.
Notes on risk reviews.
Review it at least annually, and whenever you onboard or terminate a vendor. Include IT vendors who may only access PHI incidentally, because they often have broad access.
Starting service before the BAA is signed.
Assuming a vendor is covered because they say they are HIPAA compliant. There is no official HIPAA certification for products, so ask for the agreement itself.
Losing track of expired or outdated agreements.
Failing to act when a vendor reports an incident.
If a business associate reports a breach, you need to assess it quickly. Depending on the facts, you may need to notify individuals and HHS. Your agreement should make it clear how they will cooperate.
UnityCare IT signs business associate agreements with its healthcare clients and can help you review the technical side of your vendor relationships. If you want help building a vendor inventory, we are happy to assist.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034