Facilities often sign vendor contracts without considering HIPAA, then discover a gap during an audit or after an incident. If a vendor creates, receives, maintains or transmits protected health information on your behalf, HIPAA treats it as a business associate, and you need a signed business associate agreement, or BAA, in place before any data is shared.
The label depends on what the vendor does with your data, not on the size of the company. Common business associates for senior living and clinical organizations include:
Your IT managed services provider
Cloud hosting and backup providers
EHR and billing software vendors
eFax and secure messaging services
Shredding and document storage companies
Outsourced billing, coding and transcription services
Consultants or attorneys who access PHI
Pharmacy and therapy contractors, depending on the relationship
A business associate also includes subcontractors that handle PHI for the vendor. Some relationships are different. Another healthcare provider treating the same resident, for instance, typically does not need a BAA for treatment purposes. When in doubt, ask your compliance officer or counsel.
The HIPAA Rules set the minimum content. A BAA should include:
The permitted and required uses and disclosures of PHI
A promise not to use or disclose PHI other than as allowed by the contract or by law
A commitment to use appropriate safeguards and, for electronic PHI, to comply with the Security Rule
A requirement to report any use or disclosure not allowed by the contract, including breaches of unsecured PHI and security incidents
A requirement that subcontractors agree to the same restrictions
Support for individuals who request access to or an accounting of their records
A requirement to return or destroy PHI when the contract ends, where feasible
The right for you to terminate the contract if the vendor violates it
If a template from the vendor omits any of these, ask for revisions.
The agreement is only part of the picture. Ask the vendor:
The agreement should include a specific timeframe, such as a number of days, that leaves you enough time to meet your own notification duties. Notification to individuals is required without unreasonable delay and no later than 60 days after discovery of a breach, and the clock can be affected by when the business associate discovers it.
Ask about data location, staff access, background checks and whether any work is performed offshore.
Request a summary of encryption, access controls, logging, backup and employee training. Ask whether they have an independent assessment, such as a third-party security audit report.
Ask for a list of subcontractors that touch your data and confirm they are bound by equivalent agreements.
Confirm how data is returned or destroyed, in what format and how soon, and ask for written confirmation.
You are responsible for managing your vendor relationships. Build a simple inventory with:
Vendor name and service
Type of PHI involved
Date the BAA was signed and the renewal or review date
A contact for incident reporting
Notes from your most recent review
Review this list at least once a year as part of your risk analysis, and whenever you change vendors. Retain BAAs and related documentation for six years from their creation or last effective date.
Assuming a verbal agreement or a line in the invoice is enough
Letting a department purchase a cloud tool without involving compliance
Failing to update agreements when the services change
Forgetting to terminate access when a contract ends
UnityCare IT signs business associate agreements with the healthcare organizations we serve and can help you review your vendor list for missing agreements or unclear security practices. If you would like a second set of eyes on a contract or a vendor inventory, we are glad to assist.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034