Few HIPAA documents are signed as often and read as rarely as the business associate agreement (BAA). Vendors send them as standard forms, administrators sign to move a project along, and the signed copies end up in a folder nobody opens. But the BAA defines who is responsible when something goes wrong, and a weak one can leave your organization exposed.
Under HIPAA, a business associate is a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information on your behalf, or provides certain services involving PHI. Common examples in long-term care and clinics include:
EMR/EHR and billing software vendors
Managed IT providers and others with access to systems containing PHI
Cloud storage and email providers where PHI is stored or sent
Document shredding and records storage companies
Outsourced billing, coding or collections
Consultants and attorneys who handle PHI
eFax and telehealth platforms
Backup and disaster recovery services
Providers who treat residents, such as a visiting physician or a pharmacy, generally have their own HIPAA obligations as covered entities, and disclosures for treatment purposes typically do not require a BAA. Whether a particular relationship requires one can depend on the specifics, so ask your compliance officer or counsel when in doubt.
A vendor merely providing a conduit, such as a postal carrier, is different from one that stores information. Janitors or electricians with incidental exposure are generally not business associates, but they should still be bound by confidentiality expectations.
The HIPAA rules require certain elements. In general, the agreement must:
Describe the permitted and required uses and disclosures of PHI
Prohibit uses or disclosures other than those permitted or required by law
Require appropriate safeguards, including compliance with the Security Rule for electronic PHI
Require the business associate to report security incidents and breaches, including breaches of unsecured PHI
Ensure that subcontractors who handle PHI agree to the same restrictions
Provide access to PHI so you can meet individual rights requests
Make PHI available for amendments and an accounting of disclosures
Allow HHS to review the business associate's practices where required
Require return or destruction of PHI at termination, where feasible
Allow you to terminate the contract if the business associate violates a material term
If the vendor's form leaves out any of these, ask for them to be added.
A vague promise to notify "promptly" is hard to rely on. Ask for a specific window, such as a number of days after discovery, because your own deadlines under the Breach Notification Rule may be affected by when you learn of an incident. Ask what information the vendor must provide and who they will contact.
Many vendors rely on cloud hosts and support providers. Ask for the right to know who handles your PHI.
Some vendor forms limit liability to a small amount, such as fees paid in the last year. Breaches can cost far more in notifications, credit monitoring, forensic investigation and legal help. This is often negotiable, and an attorney should review it for critical vendors.
Ask where data is stored, whether it stays in the United States, and how you get it back in a usable format at the end of the contract.
Some organizations require vendors to carry cyber liability insurance and to provide proof.
Consider whether you can request security documentation or reports periodically.
It is reasonable to negotiate when:
The BAA conflicts with the main contract, and the vendor will not say which controls
The vendor will not commit to any notification timeline
The BAA allows the vendor to use your PHI for its own purposes beyond what HIPAA permits, such as selling data or unrelated marketing
There is no commitment to return or delete data
Liability is capped at an amount that would not cover a realistic incident
Large vendors sometimes refuse changes. In that case, decide whether the service is worth the risk and whether other controls, such as limiting what data you share, can compensate.
Maintain a list of every business associate, what PHI they hold, the BAA date, renewal dates and a contact. Review it at least yearly. Remove vendors you no longer use and confirm that their data was returned or deleted.
UnityCare IT signs BAAs with our healthcare clients and can help you assess vendors' technical safeguards. We can also help build a vendor inventory to support your risk analysis. Legal terms should always be reviewed by your counsel.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172