Business Associate Agreements: What to Check Before You Sign

Facilities often sign vendor contracts without considering HIPAA, then discover a gap during an audit or after an incident. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA treats it as a business associate, and you need a signed business associate agreement, or BAA, in place before any data is shared.

Who counts as a business associate

The label depends on what the vendor does with your data, not on the size of the company. Common business associates for senior living and clinical organizations include:

Your IT managed services provider

Cloud hosting and backup providers

EHR and billing software vendors

eFax and secure messaging services

Shredding and document storage companies

Outsourced billing, coding and transcription services

Consultants or attorneys who access PHI

Pharmacy and therapy contractors, depending on the relationship

A business associate also includes subcontractors that handle PHI for the vendor. Some relationships are different. Another healthcare provider treating the same resident, for instance, typically does not need a BAA for treatment purposes. When in doubt, ask your compliance officer or counsel.

What the agreement must contain

The HIPAA Rules set the minimum content. A BAA should include:

The permitted and required uses and disclosures of PHI

A promise not to use or disclose PHI other than as allowed by the contract or by law

A commitment to use appropriate safeguards and, for electronic PHI, to comply with the Security Rule

A requirement to report any use or disclosure not allowed by the contract, including breaches of unsecured PHI and security incidents

A requirement that subcontractors agree to the same restrictions

Support for individuals who request access to or an accounting of their records

A requirement to return or destroy PHI when the contract ends, where feasible

The right for you to terminate the contract if the vendor violates it

If a template from the vendor omits any of these, ask for revisions.

Questions to ask before you sign

The agreement is only part of the picture. Ask the vendor:

How quickly will you notify us of an incident?

The agreement should include a specific timeframe, such as a number of days, that leaves you enough time to meet your own notification duties. Notification to individuals is required without unreasonable delay and no later than 60 days after discovery of a breach, and the clock can be affected by when the business associate discovers it.

Where is our data stored and who can access it?

Ask about data location, staff access, background checks and whether any work is performed offshore.

How do you protect the data?

Request a summary of encryption, access controls, logging, backup and employee training. Ask whether they have an independent assessment, such as a third-party security audit report.

Do you use subcontractors?

Ask for a list of subcontractors that touch your data and confirm they are bound by equivalent agreements.

What happens when we leave?

Confirm how data is returned or destroyed, in what format and how soon, and ask for written confirmation.

Keep your own records

You are responsible for managing your vendor relationships. Build a simple inventory with:

Vendor name and service

Type of PHI involved

Date the BAA was signed and the renewal or review date

A contact for incident reporting

Notes from your most recent review

Review this list at least once a year as part of your risk analysis, and whenever you change vendors. Retain BAAs and related documentation for six years from their creation or last effective date.

Common mistakes

Assuming a verbal agreement or a line in the invoice is enough

Letting a department purchase a cloud tool without involving compliance

Failing to update agreements when the services change

Forgetting to terminate access when a contract ends

How we can help

UnityCare IT signs business associate agreements with the healthcare organizations we serve and can help you review your vendor list for missing agreements or unclear security practices. If you would like a second set of eyes on a contract or a vendor inventory, we are glad to assist.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034