Every care organization works with outside companies that touch resident information: EHR vendors, billing services, shredding companies, IT providers, therapy contractors, cloud hosts and more. Under HIPAA, a vendor that creates, receives, maintains or transmits protected health information (PHI) on your behalf is generally a business associate, and a written business associate agreement (BAA) is required before it handles that data.
Many organizations sign whatever the vendor sends. A short review can catch problems early.
Common examples:
EHR and clinical software vendors
Managed IT and cybersecurity providers with access to systems containing PHI
Cloud storage, email hosting and backup services
Billing, coding and collections companies
Consultant pharmacists and outside therapy providers, depending on the relationship
Document destruction and scanning companies
Law firms and accountants who see PHI
Telehealth platforms
Not every vendor needs one. A janitorial company that never sees PHI typically does not. Workforce members and other treatment providers sharing information for treatment are generally handled differently. When unsure, ask counsel.
HIPAA requires that a BAA, among other things:
Describe the permitted and required uses and disclosures of PHI
Prohibit the business associate from using or disclosing PHI other than as permitted or required by the contract or by law
Require appropriate safeguards, including compliance with the Security Rule for electronic PHI
Require reporting of unauthorized uses or disclosures, including breaches of unsecured PHI and security incidents
Require subcontractors that handle PHI to agree to the same restrictions
Support individuals' rights, such as access to and amendment of records, and an accounting of disclosures where applicable
Make books and records available to HHS
Require return or destruction of PHI at termination, where feasible
Allow termination if the business associate violates a material term
Does it describe what PHI the vendor will actually handle?
Is the permitted use limited to services for you, rather than broad rights to use data for the vendor's own purposes?
Are de-identification or data aggregation rights clearly bounded?
Is there a specific deadline to notify you? The legal outer limit is 60 days for a business associate, but you often need much faster notice, such as days.
What details must the vendor provide: dates, data involved, individuals affected, steps taken?
Who pays for notification, credit monitoring and investigation costs if the vendor is at fault?
Does it require specific safeguards, such as encryption and access controls, or only vague language?
Is there a right to receive security documentation or audit results?
Are there obligations around training and background checks?
Does the vendor disclose which subcontractors handle PHI, and are they bound by equivalent terms?
Is offshore handling of data permitted or prohibited?
What happens to your data when the contract ends?
Is there a timeline for return and certified destruction?
Can you export data in a usable format?
Are there caps on liability that make breach costs unrecoverable?
Does the vendor carry cyber liability insurance?
Is there an indemnification clause for violations?
Can you terminate quickly if the vendor violates the agreement?
Are obligations to protect PHI continuing after termination?
Maintain a single list of business associates with:
Vendor name and contact
Services provided and types of PHI
BAA signature and renewal dates
Security documentation received and date reviewed
Internal owner
Review it annually and whenever a vendor is added or removed.
Assuming a vendor's standard terms of service replace a BAA
Forgetting to sign BAAs with IT providers who have administrative access
Letting BAAs lapse when contracts renew
Not tracking subcontractors
Never asking the vendor for evidence of security practices
Storing agreements in one person's email
If you are a business associate to another covered entity, you carry direct obligations under the Security Rule and breach notification provisions. Many care operators serve in both roles.
UnityCare IT signs business associate agreements with its healthcare clients and can help you inventory vendors and assess their security practices as part of your risk analysis. Legal review remains the job of your attorney, but we can help with the technical questions.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172