Who Is a Business Associate? Sorting Your Vendor List for HIPAA

Every facility has a long list of vendors: the EHR company, the pharmacy, the copier lease, the shredding service, the cleaning crew, the IT provider, the therapy contractor. Which of them need a business associate agreement? The question comes up in nearly every HIPAA review, and the answer is not always obvious.

The basic definition

Under HIPAA, a business associate is a person or organization that creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides certain services to it that involve PHI. Covered entities include most healthcare providers who bill electronically, health plans and clearinghouses. A skilled nursing facility, assisted living with covered services or clinic will usually be a covered entity.

The key idea is access to PHI as part of the service. If a vendor can see, store or handle resident information to do their job, they are very likely a business associate.

Likely business associates

EHR and software vendors hosting or supporting your clinical or billing systems

Managed IT and cloud providers that store data or have access to systems with PHI

Billing and coding companies

Shredding and records storage companies handling records containing PHI

eFax and communication platforms transmitting resident information

Backup and disaster recovery providers

Consultants and attorneys who review records

Outsourced transcription or call-answering services

Subcontractors matter too. If your vendor uses another company to handle your PHI, that company is also a business associate of your vendor and needs its own agreement.

Usually not business associates

Workforce members. Employees are covered by your own policies.

Providers sharing information for treatment. A hospital sending records for a transfer, or a physician treating a resident, is generally not your business associate for that purpose.

Conduits. Organizations that merely transmit information without routinely accessing it, such as the postal service, are treated differently from a cloud storage company.

Vendors with no access to PHI. A landscaper or a food supplier, for example.

Incidental exposure, such as a cleaning crew in an office after hours, raises a different issue: safeguards like locked file rooms and logging off screens. Whether a vendor with incidental access needs an agreement depends on the facts. When it is unclear, ask your compliance advisor or counsel.

What a business associate agreement must include

A business associate agreement, or BAA, is a written contract. At a minimum it should:

Describe the permitted uses and disclosures of PHI

Require the vendor to use appropriate safeguards, including Security Rule safeguards for electronic PHI

Require the vendor to report breaches, security incidents and unauthorized uses

Require subcontractors to agree to the same restrictions

Support individuals' access and amendment rights where applicable

Make PHI available for HHS compliance reviews

Return or destroy PHI at the end of the relationship where feasible

Many vendors have their own template. Review it rather than signing without reading. Look at breach reporting timelines, which should be fast enough for you to meet your own obligations, and check any limits on liability.

Building and maintaining the list

Step 1: Inventory

List every vendor, what they do for you and whether they touch PHI in any way. Check accounts payable records to catch vendors people forgot.

Step 2: Classify

Mark each as business associate, not a business associate, or unclear. Document your reasoning for the unclear ones.

Step 3: Verify agreements

Confirm there is a signed BAA on file for each business associate, and note the effective date and who holds the original.

Step 4: Ask about security

A BAA is a legal document, not a security control. For important vendors, ask how they protect data, whether they use multi-factor authentication, how they encrypt, and what happens after a breach.

Step 5: Review annually

Add new vendors, remove old ones and make sure agreements reflect current services. Terminate access when contracts end.

Common mistakes

Assuming a vendor is covered because they are well known

Signing a BAA but never reviewing the vendor's security

Forgetting about former vendors who still hold data

Keeping agreements in a drawer nobody can find

How we can help

UnityCare IT is itself a business associate for the healthcare organizations we support, and we can help you assess your technology vendors, review security questionnaires and organize your vendor documentation. Reach out if you would like help with an inventory.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172