Many healthcare organizations sign dozens of vendor contracts each year. Fewer stop to ask which of those vendors are business associates under HIPAA, and whether a proper agreement is in place. Gaps here are easy to create and can be costly. If a vendor handling protected health information has no business associate agreement, the covered entity may be out of compliance even if nothing has gone wrong yet.
This guide explains the basics in plain language so administrators and compliance leads can sort their vendor list with confidence.
Under the HIPAA rules, a business associate is generally a person or organization, other than a member of your workforce, that creates, receives, maintains or transmits protected health information on your behalf, or provides certain services to you that involve access to it.
Common examples for care organizations include:
Electronic health record and billing software vendors
Managed IT and helpdesk providers with access to systems containing PHI
Cloud hosting and backup providers
eFax and secure messaging services
Document shredding and records storage companies
Outsourced billing, coding and collections firms
Consulting, legal and accounting firms that see PHI
Shred, scanning and transcription services
Subcontractors of business associates that handle PHI are business associates as well, and the original business associate must have its own agreements with them.
Not every vendor qualifies. Generally, you do not need a business associate agreement with:
Members of your own workforce
Healthcare providers receiving PHI to treat a resident, such as a hospital or physician involved in care
A janitorial service with no access to PHI beyond incidental exposure, though good practices still apply
A mere conduit, such as a postal carrier or internet service provider that does not routinely access content
If you are unsure, ask your compliance officer or legal counsel. Misclassifying a vendor can leave a gap.
HIPAA specifies required elements. At a high level, a business associate agreement should:
Describe the permitted and required uses and disclosures of PHI
Prohibit the vendor from using or disclosing PHI beyond what the contract or law allows
Require appropriate safeguards, including compliance with the Security Rule for electronic PHI
Require the vendor to report breaches, security incidents and unauthorized uses or disclosures
Require the vendor to ensure subcontractors agree to the same restrictions
Support individuals' rights, such as access to and amendment of records, where relevant
Make the vendor's books and practices available to HHS for compliance review
Require return or destruction of PHI when the contract ends, if feasible
Allow you to terminate the contract if the vendor violates a material term
These are minimums. Your attorney can add stronger terms.
Beyond the required elements, consider asking for:
A specific timeframe for incident notification, such as within a set number of days of discovery
Responsibility for breach-related costs, including notification and investigation
Insurance requirements, including cyber coverage
Rights to receive security documentation or independent audit results
Clear data location and retention terms
Keep a central list that includes:
Vendor name and service provided
Whether PHI is involved
Whether a BAA is signed, with date and renewal terms
Primary contacts and security contacts
Systems and data the vendor can access
Last review date and risk rating
Review it at least annually, and whenever you add or change a vendor. This register also informs your HIPAA risk analysis.
Make BAAs part of procurement. No PHI should flow before the agreement is signed.
Use a standard template. Having your own reviewed template speeds negotiations, though many vendors will present theirs first.
Read the vendor's version carefully. Check that it includes the required elements and does not limit your rights unreasonably.
Track expirations. Agreements may renew automatically or require updates.
Retire vendors cleanly. Confirm PHI is returned or destroyed, and document it.
Assuming a big, well-known vendor does not need an agreement
Forgetting less obvious vendors such as copier and printer companies that store images on a hard drive
Missing agreements with IT providers who have broad access
Letting agreements lapse when contracts change
Assuming a signed agreement means the vendor is secure
An agreement establishes responsibility, but it does not verify practice. Combine it with security questions and periodic review.
UnityCare IT signs business associate agreements with our healthcare clients and can help you review your vendor list from a technical perspective, including which systems hold PHI. For legal interpretation, we recommend working with your counsel or compliance advisor.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034