Which Care Facility Vendors Need a Business Associate Agreement

Care organizations rely on many outside vendors: EHR providers, IT support firms, shredding companies, billing services, cloud storage, eFax providers, consultants and more. When any of them creates, receives, maintains or transmits protected health information on your behalf, HIPAA calls them a business associate, and you need a written business associate agreement, or BAA, in place before they touch that information.

A BAA is not a formality to sign and forget. It defines how your vendor will protect resident information, what happens if something goes wrong, and who is responsible for what. This article explains who needs one and what to look for.

Who Counts as a Business Associate?

A business associate is generally a person or organization that performs a function or service for a covered entity that involves protected health information. Common examples in long-term care and senior living include:

EHR, billing and revenue cycle vendors

Managed IT service providers with access to systems holding resident data

Cloud hosting, backup and email providers

Document storage and shredding companies

Answering services and telehealth platforms

Consultants, accountants and attorneys who view PHI

Eligible subcontractors of any of the above

Some relationships do not require a BAA, such as a healthcare provider disclosing information to another provider for treatment, or a cleaning crew with no access to PHI. When unsure, ask your compliance officer or legal counsel.

What HIPAA Requires a BAA to Include

The HIPAA Privacy and Security Rules set out required elements. In general, an agreement should:

Describe the permitted and required uses and disclosures of PHI

Prohibit uses or disclosures other than those permitted by the contract or required by law

Require appropriate safeguards, and compliance with the Security Rule for electronic PHI

Require the business associate to report breaches, security incidents and impermissible uses

Require subcontractors that handle PHI to agree to the same restrictions

Support individuals' rights to access and amend records and to receive an accounting of disclosures, as applicable

Require return or destruction of PHI when the relationship ends, if feasible

Allow you to terminate the contract if the business associate violates a material term

Clauses Worth a Closer Look

Beyond the required elements, a few details can matter a great deal in practice:

Breach reporting timeline. The law sets outer limits, but your contract can require faster notice. If a vendor takes weeks to tell you about an incident, your own notification clock may already be running.

Definition of security incident. Make sure it is clear what the vendor must report and how.

Subcontractors. Ask whether the vendor uses subcontractors, where data is stored and whether storage is limited to the United States.

Data return and deletion. Confirm how you will get your data back, in what format and how deletion is verified.

Insurance and indemnification. Check whether the vendor carries cyber liability coverage and how responsibility for breach costs is allocated.

Audit and documentation rights. Can you request evidence of their safeguards, such as a risk analysis summary or independent assessment?

Offshore access. Understand whether support staff outside the country can see your data.

Vendor Due Diligence Beyond the Paperwork

A signed agreement does not guarantee good security. Before onboarding a vendor, consider asking:

Do you perform regular security risk analyses?

Do you use multi-factor authentication and encryption?

How do you back up and recover our data?

What is your incident response process?

Who at your company can access our information?

Keep a BAA Inventory

Maintain a simple spreadsheet listing each business associate, the services they provide, the date of the agreement, renewal terms and a contact person. Review it annually and remove vendors you no longer use after confirming that your data was returned or destroyed.

Common Mistakes

Working with a vendor before the BAA is signed

Accepting a vendor template without reading it

Failing to update agreements when services change

Not knowing which vendors have remote access to your systems

Neglecting to offboard vendors when contracts end

Keeping It Manageable

UnityCare IT signs business associate agreements with the healthcare clients we serve, and we can help you inventory your own vendors, ask the right security questions and identify who has access to your systems.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172