When a vendor handles resident or patient information on your behalf, HIPAA requires a written agreement before any data changes hands. That document, the Business Associate Agreement or BAA, is easy to treat as paperwork. In practice it is one of the few tools you have to set expectations for how a vendor protects your data and what happens if something goes wrong.
Here is what a BAA is, when you need one and how to read it.
A business associate is a person or company that creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity, or that provides certain services involving PHI. Under HIPAA and the HITECH Act, business associates are directly responsible for complying with parts of the Security Rule and the Breach Notification Rule.
Examples in long-term care and clinic settings include:
EHR and software vendors that host or access records
Managed IT and cybersecurity providers with access to systems holding PHI
Cloud storage, backup and email providers
Billing and coding companies
Telehealth and e-prescribing platforms
Document shredding and records storage companies
Consultants and attorneys who receive PHI
A vendor does not need to read the data to be a business associate. If they maintain it, such as by storing encrypted files, they may still qualify.
A few exceptions exist. Disclosures to another provider for treatment do not require a BAA. Workforce members are not business associates. A janitorial service whose staff do not routinely access PHI generally is not, though incidental exposure should still be managed through confidentiality terms. When you are unsure, ask your compliance lead or attorney.
HIPAA specifies required elements. A compliant agreement generally must:
Describe the permitted and required uses and disclosures of PHI
Prohibit the business associate from using or disclosing PHI other than as permitted by the agreement or required by law
Require appropriate safeguards and compliance with the Security Rule for electronic PHI
Require the business associate to report to you any use or disclosure not provided for by the agreement, including breaches of unsecured PHI and security incidents
Require the business associate to ensure that subcontractors who handle PHI agree to the same restrictions
Support residents' rights, including access to records, amendments and an accounting of disclosures
Require return or destruction of PHI at the end of the contract, where feasible
Allow you to terminate the agreement if the business associate materially violates it
The legal minimum is a floor. Consider asking for:
HIPAA allows business associates up to 60 days to notify a covered entity, but that is too slow for you to meet your own obligations comfortably. Many organizations ask for notice within a few days.
Requirements for encryption, multi-factor authentication, logging and periodic security assessments can be spelled out in the agreement or an attached schedule.
Ask for a list of subcontractors with access to your PHI and notice of changes.
Clarify who bears the cost of breach notification, credit monitoring and investigation if the incident arises from the vendor's systems.
Specify where data is stored and how it is returned at the end, in a usable format.
No BAA at all, because the vendor was set up by a department without compliance involvement
A BAA that was signed years ago and no longer matches the services provided
Missing signatures or dates
An outdated template that refers to long-superseded rules
No record of which vendors actually have BAAs
A vendor that handles PHI under a different entity name than the one you signed with
Maintain a list of every business associate with the vendor name, services, effective date, renewal or expiration date, contact and storage location of the signed agreement. Review it at least annually, check for services added since the original signing and keep documents for six years after they stop being in effect.
Do not share PHI. Either choose a different vendor or restructure the service so that PHI is not involved. Sharing data without a BAA is a violation regardless of the vendor's reputation.
As a managed IT provider with access to systems that contain PHI, UnityCare IT signs BAAs with our healthcare clients, and we can help you inventory your other vendors and identify any that are missing agreements. Your attorney should review final contract language, but we can help you organize the list and ask the right technical questions.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172