HIPAA Business Associates in Care: EHR, Billing and Shredding Vendors

Every care organization works with outside companies that touch resident information: EHR vendors, billing services, shredding companies, IT providers, therapy contractors, cloud hosts and more. Under HIPAA, a vendor that creates, receives, maintains or transmits protected health information (PHI) on your behalf is generally a business associate, and a written business associate agreement (BAA) is required before it handles that data.

Many organizations sign whatever the vendor sends. A short review can catch problems early.

Who Needs a BAA

Common examples:

EHR and clinical software vendors

Managed IT and cybersecurity providers with access to systems containing PHI

Cloud storage, email hosting and backup services

Billing, coding and collections companies

Consultant pharmacists and outside therapy providers, depending on the relationship

Document destruction and scanning companies

Law firms and accountants who see PHI

Telehealth platforms

Not every vendor needs one. A janitorial company that never sees PHI typically does not. Workforce members and other treatment providers sharing information for treatment are generally handled differently. When unsure, ask counsel.

What the Agreement Must Include

HIPAA requires that a BAA, among other things:

Describe the permitted and required uses and disclosures of PHI

Prohibit the business associate from using or disclosing PHI other than as permitted or required by the contract or by law

Require appropriate safeguards, including compliance with the Security Rule for electronic PHI

Require reporting of unauthorized uses or disclosures, including breaches of unsecured PHI and security incidents

Require subcontractors that handle PHI to agree to the same restrictions

Support individuals' rights, such as access to and amendment of records, and an accounting of disclosures where applicable

Make books and records available to HHS

Require return or destruction of PHI at termination, where feasible

Allow termination if the business associate violates a material term

Practical Review Checklist

Scope

Does it describe what PHI the vendor will actually handle?

Is the permitted use limited to services for you, rather than broad rights to use data for the vendor's own purposes?

Are de-identification or data aggregation rights clearly bounded?

Breach and incident reporting

Is there a specific deadline to notify you? The legal outer limit is 60 days for a business associate, but you often need much faster notice, such as days.

What details must the vendor provide: dates, data involved, individuals affected, steps taken?

Who pays for notification, credit monitoring and investigation costs if the vendor is at fault?

Security expectations

Does it require specific safeguards, such as encryption and access controls, or only vague language?

Is there a right to receive security documentation or audit results?

Are there obligations around training and background checks?

Subcontractors

Does the vendor disclose which subcontractors handle PHI, and are they bound by equivalent terms?

Is offshore handling of data permitted or prohibited?

Data return and destruction

What happens to your data when the contract ends?

Is there a timeline for return and certified destruction?

Can you export data in a usable format?

Liability and insurance

Are there caps on liability that make breach costs unrecoverable?

Does the vendor carry cyber liability insurance?

Is there an indemnification clause for violations?

Term and termination

Can you terminate quickly if the vendor violates the agreement?

Are obligations to protect PHI continuing after termination?

Keep an Inventory

Maintain a single list of business associates with:

Vendor name and contact

Services provided and types of PHI

BAA signature and renewal dates

Security documentation received and date reviewed

Internal owner

Review it annually and whenever a vendor is added or removed.

Common Mistakes

Assuming a vendor's standard terms of service replace a BAA

Forgetting to sign BAAs with IT providers who have administrative access

Letting BAAs lapse when contracts renew

Not tracking subcontractors

Never asking the vendor for evidence of security practices

Storing agreements in one person's email

Be Aware of Your Role Too

If you are a business associate to another covered entity, you carry direct obligations under the Security Rule and breach notification provisions. Many care operators serve in both roles.

How UnityCare IT Can Help

UnityCare IT signs business associate agreements with its healthcare clients and can help you inventory vendors and assess their security practices as part of your risk analysis. Legal review remains the job of your attorney, but we can help with the technical questions.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172