Business Associate Agreements: What to Check and When to Push Back

Few HIPAA documents are signed as often and read as rarely as the business associate agreement (BAA). Vendors send them as standard forms, administrators sign to move a project along, and the signed copies end up in a folder nobody opens. But the BAA defines who is responsible when something goes wrong, and a weak one can leave your organization exposed.

Who Needs a BAA?

Under HIPAA, a business associate is a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information on your behalf, or provides certain services involving PHI. Common examples in long-term care and clinics include:

EMR/EHR and billing software vendors

Managed IT providers and others with access to systems containing PHI

Cloud storage and email providers where PHI is stored or sent

Document shredding and records storage companies

Outsourced billing, coding or collections

Consultants and attorneys who handle PHI

eFax and telehealth platforms

Backup and disaster recovery services

Providers who treat residents, such as a visiting physician or a pharmacy, generally have their own HIPAA obligations as covered entities, and disclosures for treatment purposes typically do not require a BAA. Whether a particular relationship requires one can depend on the specifics, so ask your compliance officer or counsel when in doubt.

A vendor merely providing a conduit, such as a postal carrier, is different from one that stores information. Janitors or electricians with incidental exposure are generally not business associates, but they should still be bound by confidentiality expectations.

What a BAA Must Cover

The HIPAA rules require certain elements. In general, the agreement must:

Describe the permitted and required uses and disclosures of PHI

Prohibit uses or disclosures other than those permitted or required by law

Require appropriate safeguards, including compliance with the Security Rule for electronic PHI

Require the business associate to report security incidents and breaches, including breaches of unsecured PHI

Ensure that subcontractors who handle PHI agree to the same restrictions

Provide access to PHI so you can meet individual rights requests

Make PHI available for amendments and an accounting of disclosures

Allow HHS to review the business associate's practices where required

Require return or destruction of PHI at termination, where feasible

Allow you to terminate the contract if the business associate violates a material term

If the vendor's form leaves out any of these, ask for them to be added.

Clauses Worth Reading Closely

Breach notification timing

A vague promise to notify "promptly" is hard to rely on. Ask for a specific window, such as a number of days after discovery, because your own deadlines under the Breach Notification Rule may be affected by when you learn of an incident. Ask what information the vendor must provide and who they will contact.

Subcontractors

Many vendors rely on cloud hosts and support providers. Ask for the right to know who handles your PHI.

Liability and indemnification

Some vendor forms limit liability to a small amount, such as fees paid in the last year. Breaches can cost far more in notifications, credit monitoring, forensic investigation and legal help. This is often negotiable, and an attorney should review it for critical vendors.

Data location and return

Ask where data is stored, whether it stays in the United States, and how you get it back in a usable format at the end of the contract.

Insurance

Some organizations require vendors to carry cyber liability insurance and to provide proof.

Audit and assessment rights

Consider whether you can request security documentation or reports periodically.

When to Push Back

It is reasonable to negotiate when:

The BAA conflicts with the main contract, and the vendor will not say which controls

The vendor will not commit to any notification timeline

The BAA allows the vendor to use your PHI for its own purposes beyond what HIPAA permits, such as selling data or unrelated marketing

There is no commitment to return or delete data

Liability is capped at an amount that would not cover a realistic incident

Large vendors sometimes refuse changes. In that case, decide whether the service is worth the risk and whether other controls, such as limiting what data you share, can compensate.

Keep Track

Maintain a list of every business associate, what PHI they hold, the BAA date, renewal dates and a contact. Review it at least yearly. Remove vendors you no longer use and confirm that their data was returned or deleted.

How UnityCare IT Can Help

UnityCare IT signs BAAs with our healthcare clients and can help you assess vendors' technical safeguards. We can also help build a vendor inventory to support your risk analysis. Legal terms should always be reviewed by your counsel.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172