Business Associate Agreements: Who Needs One and What to Check

Many healthcare organizations sign dozens of vendor contracts each year. Fewer stop to ask which of those vendors are business associates under HIPAA, and whether a proper agreement is in place. Gaps here are easy to create and can be costly. If a vendor handling protected health information has no business associate agreement, the covered entity may be out of compliance even if nothing has gone wrong yet.

This guide explains the basics in plain language so administrators and compliance leads can sort their vendor list with confidence.

What Is a Business Associate?

Under the HIPAA rules, a business associate is generally a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information on your behalf, or provides certain services to you that involve access to it.

Common examples for care organizations include:

Electronic health record and billing software vendors

Managed IT and helpdesk providers with access to systems containing PHI

Cloud hosting and backup providers

eFax and secure messaging services

Document shredding and records storage companies

Outsourced billing, coding and collections firms

Consulting, legal and accounting firms that see PHI

Shred, scanning and transcription services

Subcontractors of business associates that handle PHI are business associates as well, and the original business associate must have its own agreements with them.

Who Is Not a Business Associate?

Not every vendor qualifies. Generally, you do not need a business associate agreement with:

Members of your own workforce

Healthcare providers receiving PHI to treat a resident, such as a hospital or physician involved in care

A janitorial service with no access to PHI beyond incidental exposure, though good practices still apply

A mere conduit, such as a postal carrier or internet service provider that does not routinely access content

If you are unsure, ask your compliance officer or legal counsel. Misclassifying a vendor can leave a gap.

What the Agreement Must Include

HIPAA specifies required elements. At a high level, a business associate agreement should:

Describe the permitted and required uses and disclosures of PHI

Prohibit the vendor from using or disclosing PHI beyond what the contract or law allows

Require appropriate safeguards, including compliance with the Security Rule for electronic PHI

Require the vendor to report breaches, security incidents and unauthorized uses or disclosures

Require the vendor to ensure subcontractors agree to the same restrictions

Support individuals' rights, such as access to and amendment of records, where relevant

Make the vendor's books and practices available to HHS for compliance review

Require return or destruction of PHI when the contract ends, if feasible

Allow you to terminate the contract if the vendor violates a material term

These are minimums. Your attorney can add stronger terms.

Terms Worth Negotiating

Beyond the required elements, consider asking for:

A specific timeframe for incident notification, such as within a set number of days of discovery

Responsibility for breach-related costs, including notification and investigation

Insurance requirements, including cyber coverage

Rights to receive security documentation or independent audit results

Clear data location and retention terms

Build and Maintain a Vendor Register

Keep a central list that includes:

Vendor name and service provided

Whether PHI is involved

Whether a BAA is signed, with date and renewal terms

Primary contacts and security contacts

Systems and data the vendor can access

Last review date and risk rating

Review it at least annually, and whenever you add or change a vendor. This register also informs your HIPAA risk analysis.

Process Tips

Make BAAs part of procurement. No PHI should flow before the agreement is signed.

Use a standard template. Having your own reviewed template speeds negotiations, though many vendors will present theirs first.

Read the vendor's version carefully. Check that it includes the required elements and does not limit your rights unreasonably.

Track expirations. Agreements may renew automatically or require updates.

Retire vendors cleanly. Confirm PHI is returned or destroyed, and document it.

Common Pitfalls

Assuming a big, well-known vendor does not need an agreement

Forgetting less obvious vendors such as copier and printer companies that store images on a hard drive

Missing agreements with IT providers who have broad access

Letting agreements lapse when contracts change

Assuming a signed agreement means the vendor is secure

An agreement establishes responsibility, but it does not verify practice. Combine it with security questions and periodic review.

How UnityCare IT Can Help

UnityCare IT signs business associate agreements with our healthcare clients and can help you review your vendor list from a technical perspective, including which systems hold PHI. For legal interpretation, we recommend working with your counsel or compliance advisor.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034