Every facility has a long list of vendors: the EHR company, the pharmacy, the copier lease, the shredding service, the cleaning crew, the IT provider, the therapy contractor. Which of them need a business associate agreement? The question comes up in nearly every HIPAA review, and the answer is not always obvious.
Under HIPAA, a business associate is a person or organization that creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides certain services to it that involve PHI. Covered entities include most healthcare providers who bill electronically, health plans and clearinghouses. A skilled nursing facility, assisted living with covered services or clinic will usually be a covered entity.
The key idea is access to PHI as part of the service. If a vendor can see, store or handle resident information to do their job, they are very likely a business associate.
EHR and software vendors hosting or supporting your clinical or billing systems
Managed IT and cloud providers that store data or have access to systems with PHI
Shredding and records storage companies handling records containing PHI
eFax and communication platforms transmitting resident information
Consultants and attorneys who review records
Subcontractors matter too. If your vendor uses another company to handle your PHI, that company is also a business associate of your vendor and needs its own agreement.
Workforce members. Employees are covered by your own policies.
Providers sharing information for treatment. A hospital sending records for a transfer, or a physician treating a resident, is generally not your business associate for that purpose.
Conduits. Organizations that merely transmit information without routinely accessing it, such as the postal service, are treated differently from a cloud storage company.
Vendors with no access to PHI. A landscaper or a food supplier, for example.
Incidental exposure, such as a cleaning crew in an office after hours, raises a different issue: safeguards like locked file rooms and logging off screens. Whether a vendor with incidental access needs an agreement depends on the facts. When it is unclear, ask your compliance advisor or counsel.
A business associate agreement, or BAA, is a written contract. At a minimum it should:
Describe the permitted uses and disclosures of PHI
Require the vendor to use appropriate safeguards, including Security Rule safeguards for electronic PHI
Require the vendor to report breaches, security incidents and unauthorized uses
Require subcontractors to agree to the same restrictions
Support individuals' access and amendment rights where applicable
Make PHI available for HHS compliance reviews
Return or destroy PHI at the end of the relationship where feasible
Many vendors have their own template. Review it rather than signing without reading. Look at breach reporting timelines, which should be fast enough for you to meet your own obligations, and check any limits on liability.
List every vendor, what they do for you and whether they touch PHI in any way. Check accounts payable records to catch vendors people forgot.
Mark each as business associate, not a business associate, or unclear. Document your reasoning for the unclear ones.
Confirm there is a signed BAA on file for each business associate, and note the effective date and who holds the original.
A BAA is a legal document, not a security control. For important vendors, ask how they protect data, whether they use multi-factor authentication, how they encrypt, and what happens after a breach.
Add new vendors, remove old ones and make sure agreements reflect current services. Terminate access when contracts end.
Assuming a vendor is covered because they are well known
Signing a BAA but never reviewing the vendor's security
Forgetting about former vendors who still hold data
Keeping agreements in a drawer nobody can find
UnityCare IT is itself a business associate for the healthcare organizations we support, and we can help you assess your technology vendors, review security questionnaires and organize your vendor documentation. Reach out if you would like help with an inventory.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172