Business Associate Agreements: What Operators Must Verify

Many HIPAA problems start not inside a facility but with a vendor. The billing company, the cloud backup provider, the shredding service, the IT firm and the eFax provider may all handle protected health information on your behalf. HIPAA expects you to have written assurances from each of them. Those assurances come in the form of a business associate agreement, commonly called a BAA.

This post explains who needs one, what it should say and how to manage the paperwork without losing track.

Who counts as a business associate

Under the HIPAA Privacy and Security Rules, a business associate is a person or organization that creates, receives, maintains or transmits protected health information for a covered entity, or provides certain services involving that information. Common examples in long-term care and clinics include:

Managed IT and cybersecurity providers with access to systems holding PHI.

Cloud storage and backup vendors.

Billing and claims services, and consultants who review records.

Electronic fax and e-prescribing services.

Document destruction companies that handle records.

Software vendors, including EHR providers, that host your data.

Subcontractors of those vendors who also touch PHI.

A vendor that never sees PHI, such as a landscaping company, does not need a BAA. Be careful with edge cases, like a cleaning crew that works near records. Those are usually handled with confidentiality terms and physical safeguards instead.

What a BAA should include

HHS provides sample provisions, and a good agreement generally addresses the following:

Permitted uses and disclosures of PHI, limited to what the service requires.

A promise to apply appropriate safeguards and comply with the Security Rule's requirements for electronic PHI.

A duty to report breaches and security incidents to you, with a defined timeframe.

A requirement that subcontractors agree to the same restrictions.

Support for individual rights, such as access to records and amendments, where relevant.

Return or destruction of PHI when the relationship ends.

Your right to terminate if the vendor violates the agreement.

Pay close attention to the breach reporting timeline. HIPAA gives you limited time to notify affected individuals after discovery, so you want your vendors to tell you quickly, not weeks later.

Questions to ask before signing

Where will our data be stored, and who can access it?

Is the data encrypted in transit and at rest?

What happens to our data if we cancel?

Do you use subcontractors, and do they sign BAAs with you?

How do you notify us of incidents, and how quickly?

Can you describe your own security program or share a recent assessment?

A vendor that cannot answer these questions clearly is a risk even if the contract is signed.

Keep a living vendor inventory

A BAA signed years ago in a drawer is not much help if no one knows who has access today. Build a simple spreadsheet that records:

Vendor name and service provided.

Type of PHI they access.

BAA date and renewal or review date.

Owner inside your organization.

Security contact at the vendor.

Review it at least once a year and whenever you add or drop a service. Include free tools staff may have adopted on their own. A free file-sharing app used to send records can quietly create a compliance gap.

Common mistakes

Assuming a vendor is compliant because they say they are HIPAA friendly. Without a signed BAA, that phrase means little.

Using consumer tools that will not sign a BAA for resident information.

Letting agreements lapse during contract renewals or acquisitions.

Failing to offboard vendors, leaving accounts active after services end.

Overlooking that you also may be a business associate to someone else, such as a parent organization.

When something goes wrong

If a vendor reports an incident, treat it like one of your own. Start your own documentation, evaluate whether it is a reportable breach and follow the HIPAA Breach Notification Rule. Your BAA should make this easier by defining what the vendor must share.

How UnityCare IT can help

UnityCare IT signs business associate agreements with the healthcare clients it supports, and we can help you review your vendor list and spot gaps in your documentation. If it has been a while since you checked, we are happy to help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172