Do You Need a BAA With Your IT Vendor? Questions Answered

Few HIPAA topics generate as many hallway questions as business associate agreements. Administrators know they are supposed to have them, but it is not always clear which vendors count, what the paperwork has to contain, or who is responsible when a vendor makes a mistake. This post answers the questions we hear most from nursing homes, assisted living communities and clinics.

What is a business associate?

Under the HIPAA Privacy and Security Rules, a business associate is a person or company that creates, receives, maintains or transmits protected health information (PHI) on your behalf, or provides certain services to you that involve access to PHI. Your managed IT provider, cloud hosting company, eFax service, document shredding vendor, and the company that hosts your EMR or EHR typically all qualify.

The test is not whether the vendor intends to look at PHI. It is whether the vendor could access it or hold it as part of the service. An IT technician who remotes into a nurse station computer with PointClickCare open can see resident information, even if that is not the purpose of the visit.

Do we really need a signed agreement with each one?

Yes. HIPAA requires a written business associate agreement (BAA) before a business associate handles PHI for you. Operating without one is a compliance gap by itself, even if nothing ever goes wrong. It also leaves you without contractual commitments about how the vendor will protect the data or report problems.

A few common exceptions are worth knowing:

A person who only has incidental exposure, such as a janitorial service, is generally not a business associate, though good practice is to restrict their access to records areas.

Disclosures to another provider for treatment purposes, such as sending records to a hospital, do not require a BAA.

Members of your own workforce are covered by your policies and training, not by a BAA.

What must the agreement include?

The HIPAA rules list required elements. In general, a BAA should:

Describe the permitted uses and disclosures of PHI.

Require the vendor to use appropriate safeguards and, for electronic PHI, comply with the Security Rule.

Require the vendor to report security incidents and breaches to you, ideally with a defined time limit.

Require the vendor to pass the same restrictions down to any subcontractors that touch PHI.

Make PHI available so you can honor resident access and amendment requests.

Require return or destruction of PHI when the relationship ends, where feasible.

Allow you to terminate the contract if the vendor violates the agreement.

A reporting window is not spelled out in the rule for the vendor-to-you step, so negotiate one. Many organizations ask for notice within a few business days so they have time to meet their own deadlines.

Who is liable if the vendor is the problem?

Business associates are directly accountable to HHS for certain Security Rule requirements, and a vendor that breaches PHI can face enforcement on its own. But that does not erase your obligations. As the covered entity, you still decide whether a breach occurred and you still notify residents and regulators. A strong BAA and careful vendor selection reduce the odds that you are surprised.

How do we keep track of all of them?

Most small operators discover that BAAs live in a dozen different places. A simple system works better than a perfect one:

Build a vendor inventory listing every company that touches PHI, the service they provide, and what data they see.

Store the signed BAA, the contract and the vendor's security contact in one shared folder.

Record the renewal date and review the list at least once a year.

Add a BAA check to your purchasing process so no new software goes live before the paperwork is signed.

Remove access promptly when a vendor relationship ends, and keep confirmation of data return or destruction.

Questions to ask before signing

A BAA is only as good as the vendor behind it. Ask whether they carry cyber liability insurance, where PHI is stored, whether data is encrypted in transit and at rest, whether they use subcontractors, and how they handle employee background checks and access. Written answers go in the vendor file and become part of your risk analysis.

Where UnityCare IT fits in

We sign BAAs with the healthcare organizations we support and can help you inventory your vendors, spot missing agreements, and review the technical safeguards behind each one. If your BAA folder is incomplete or you are not sure which vendors need one, a short vendor review is a practical place to begin.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034