Care organizations rely on many outside vendors: EHR providers, IT support firms, shredding companies, billing services, cloud storage, eFax providers, consultants and more. When any of them creates, receives, maintains or transmits protected health information on your behalf, HIPAA calls them a business associate, and you need a written business associate agreement, or BAA, in place before they touch that information.
A BAA is not a formality to sign and forget. It defines how your vendor will protect resident information, what happens if something goes wrong, and who is responsible for what. This article explains who needs one and what to look for.
A business associate is generally a person or organization that performs a function or service for a covered entity that involves protected health information. Common examples in long-term care and senior living include:
EHR, billing and revenue cycle vendors
Managed IT service providers with access to systems holding resident data
Cloud hosting, backup and email providers
Document storage and shredding companies
Answering services and telehealth platforms
Consultants, accountants and attorneys who view PHI
Eligible subcontractors of any of the above
Some relationships do not require a BAA, such as a healthcare provider disclosing information to another provider for treatment, or a cleaning crew with no access to PHI. When unsure, ask your compliance officer or legal counsel.
The HIPAA Privacy and Security Rules set out required elements. In general, an agreement should:
Describe the permitted and required uses and disclosures of PHI
Prohibit uses or disclosures other than those permitted by the contract or required by law
Require appropriate safeguards, and compliance with the Security Rule for electronic PHI
Require the business associate to report breaches, security incidents and impermissible uses
Require subcontractors that handle PHI to agree to the same restrictions
Support individuals' rights to access and amend records and to receive an accounting of disclosures, as applicable
Require return or destruction of PHI when the relationship ends, if feasible
Allow you to terminate the contract if the business associate violates a material term
Beyond the required elements, a few details can matter a great deal in practice:
Breach reporting timeline. The law sets outer limits, but your contract can require faster notice. If a vendor takes weeks to tell you about an incident, your own notification clock may already be running.
Definition of security incident. Make sure it is clear what the vendor must report and how.
Subcontractors. Ask whether the vendor uses subcontractors, where data is stored and whether storage is limited to the United States.
Data return and deletion. Confirm how you will get your data back, in what format and how deletion is verified.
Insurance and indemnification. Check whether the vendor carries cyber liability coverage and how responsibility for breach costs is allocated.
Audit and documentation rights. Can you request evidence of their safeguards, such as a risk analysis summary or independent assessment?
Offshore access. Understand whether support staff outside the country can see your data.
A signed agreement does not guarantee good security. Before onboarding a vendor, consider asking:
Do you perform regular security risk analyses?
Do you use multi-factor authentication and encryption?
How do you back up and recover our data?
What is your incident response process?
Who at your company can access our information?
Maintain a simple spreadsheet listing each business associate, the services they provide, the date of the agreement, renewal terms and a contact person. Review it annually and remove vendors you no longer use after confirming that your data was returned or destroyed.
Working with a vendor before the BAA is signed
Accepting a vendor template without reading it
Failing to update agreements when services change
Not knowing which vendors have remote access to your systems
Neglecting to offboard vendors when contracts end
UnityCare IT signs business associate agreements with the healthcare clients we serve, and we can help you inventory your own vendors, ask the right security questions and identify who has access to your systems.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172