A four-physician practice asked us to review its compliance file before a payer audit. The folder held signed business associate agreements with the EHR vendor, the billing clearinghouse and the shredding company. It did not hold one with the answering service that took after-hours calls and texted the on-call physician patient names and symptoms, the marketing firm that had been given a mailing list of 3,000 patients for a flu shot campaign, the IT company with administrator access to every workstation, or the collection agency. Four vendors handling protected health information every week, with no agreement, and nobody had noticed because nobody had ever written the list down.

That pattern is normal. Practices sign a HIPAA business associate agreement when the vendor sends one, and most of the large vendors do. The gap is the smaller vendors and the ones that do not think of themselves as healthcare companies. The Office for Civil Rights has settled with practices for exactly this: Raleigh Orthopaedic Clinic paid $750,000 in April 2016 after handing X-ray films to a vendor without an agreement, North Memorial Health Care paid $1.55 million in March 2016 in a case that included a missing agreement with a contractor, and Advanced Care Hospitalists paid $500,000 in December 2018 after a billing vendor with no agreement exposed patient data online.

This article is the explainer we give practice managers: what makes a vendor a business associate, which common vendors are and are not, what the agreement has to say, and how to build the inventory in two weeks.

Key takeaways

  • A business associate is any person or company, outside your workforce, that creates, receives, maintains or transmits protected health information on your behalf.
  • The test is the function, not the industry: an IT company, an attorney or a marketing firm becomes a business associate the moment it handles your patient data for you.
  • Other providers treating the patient, health plans paying claims, and true transmission-only conduits are not business associates.
  • Since the 2013 Omnibus Rule, business associates are directly liable under HIPAA and must flow the same obligations down to their subcontractors.
  • The agreement must contain specific required terms; a vendor's standard confidentiality clause is not one.

The definition, in plain terms

The HIPAA rules define a business associate as a person or entity, not a member of the covered entity's workforce, that performs functions or activities on behalf of the covered entity involving the use or disclosure of protected health information, or that provides certain services (legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, financial) where the service involves disclosure of protected health information. Since the Omnibus Rule took effect on September 23, 2013, the definition also expressly covers anyone who maintains protected health information on your behalf, even if they never look at it, and it covers subcontractors of business associates.

Glossary line: protected health information (PHI) is individually identifiable health information held by a covered entity or business associate, in any form. A patient's name next to an appointment date is PHI. A list of patients due for a flu shot is PHI. Encrypted PHI is still PHI.

Three things follow. First, "on behalf of" is the hinge. A specialist you refer to receives PHI, but for their own treatment of the patient, not on your behalf, so they are not your business associate. Second, maintaining counts. A cloud storage company that holds your encrypted backups and has no key is still a business associate; OCR said so in its 2016 cloud computing guidance. Third, the workforce exception is about control. Employees, volunteers and trainees under your direct control are workforce, not business associates, even if they are not on payroll.

Twenty vendors, sorted

Here is how we sort the vendors we see most in independent practices. The reasoning column is the part to learn, because the next vendor you sign will not be on this list.

VendorBusiness associate?Why
Medical billing companyYesHandles claims and PHI on your behalf; this includes our own billing service and every competitor
ClearinghouseYesReceives and transmits claims containing PHI on your behalf
EHR and practice management vendorYesMaintains PHI; cloud hosting makes this unambiguous
IT managed services providerYesAdministrator access to systems holding PHI counts as maintaining it, whether or not they open a chart
Cloud backup or storageYesMaintains PHI even when encrypted and even without the key
Email encryption or e-fax serviceYesStores messages containing PHI; more than a conduit
Answering serviceYesReceives patient names and clinical details on your behalf
Appointment reminder, text messaging or patient portal vendorYesHolds patient identifiers and appointment data
Telehealth platformYesTransmits and often stores clinical encounters
Transcription or ambient documentation vendorYesCreates and maintains clinical notes
Coding auditor, RCM consultant, credentialing vendor with chart accessYesConsulting services involving PHI disclosure
Collection agencyYesReceives patient identifiers and service dates for your accounts
Shredding and record storage companyYesMaintains and destroys PHI on your behalf
Attorney or accountant who receives PHIYesNamed service categories in the definition when PHI is disclosed
Marketing firm given patient listsYesUses PHI on your behalf; also check the marketing authorization rules before sharing the list at all
Website developerDependsYes if the site collects intake forms or messages with PHI or hosts a portal; no for a brochure site with no patient data
Health plans and payersNoCovered entities receiving PHI for payment; disclosure is permitted without an agreement
Referral specialists, hospitals, labs treating your patientNoReceive PHI for their own treatment, not on your behalf
U.S. Postal Service, couriers, internet service providerNoConduit exception: transmission only, with random or infrequent access
Cleaning service, building maintenanceNoAny exposure is incidental; they perform no function involving PHI. Train staff to lock screens anyway

The conduit exception deserves a warning because vendors invoke it far too broadly. It applies to services that merely transport PHI, like the mail or a phone carrier, and have only transient access. A vendor that stores your data, even briefly, even encrypted, is not a conduit. If a vendor tells you it does not need an agreement because it is "just a conduit" and it has a login to anything of yours, get the agreement.

What a HIPAA business associate agreement must say

The Privacy Rule at 45 CFR 164.504(e) lists the required contents, and a vendor's standard confidentiality clause does not meet them. The agreement must establish the permitted and required uses and disclosures of PHI; prohibit uses beyond those the covered entity itself could make; require appropriate safeguards, including compliance with the Security Rule for electronic PHI; require reporting of any use or disclosure not permitted by the contract, including breaches of unsecured PHI and security incidents; require the same restrictions to be flowed down to subcontractors in writing; require the business associate to support your obligations to give patients access, amendments and an accounting of disclosures; require the business associate to make its books and records available to HHS; require return or destruction of PHI at termination where feasible; and permit you to terminate for a material violation.

Two terms are worth negotiating rather than accepting. Breach notification timing: the rule requires a business associate to notify you without unreasonable delay and no later than 60 days after discovery, and 60 days is far too long when your own clock to notify patients is also 60 days from when you are deemed to know. We ask for five to ten business days. And the definition of "discovery" and what counts as a security incident, because a vendor that only reports confirmed breaches will leave you learning about ransomware from the news. The Change Healthcare attack of February 21, 2024 taught many practices what a business associate incident does to cash flow; the agreement is where you set what the vendor owes you when it happens.

Sign the agreement before the vendor receives any PHI. An agreement signed after the fact does not cure the disclosure that preceded it, though it is still better than none.

Building the inventory in two weeks

Week one is discovery. Pull the accounts payable vendor list for the last twelve months and mark every vendor that could touch PHI, using the table above as the filter. Then walk the building: what services take phone calls, what software is installed, what devices connect to the network, who has keys and logins. Ask each department head what they send outside the practice and to whom. In our experience this step finds two to five vendors nobody in the compliance role knew about, usually a texting app, a transcription tool a physician signed up for personally, or a consultant with portal access.

Week two is documentation. For each vendor on the list, find the signed agreement or request one, and record the vendor, the service, the PHI involved, the agreement date, the breach notification term and the renewal or termination date on one spreadsheet. Where a vendor refuses to sign, stop the PHI flow until they do or replace them. Where a vendor is not a business associate, write down why, so the reasoning survives staff turnover. Then put a recurring annual review on the calendar and add a line to the purchasing process: no new vendor that touches PHI gets paid until the agreement is on file.

If your website collects intake forms or messages, confirm the developer and the form-processing service are on the list; our healthcare website development team builds intake so the data flow and the agreements are settled before launch. And this inventory is one of the documents an RCM audit asks for, because the vendors that handle claims are the ones with the most PHI.

Questions we hear

Our EHR vendor says its agreement covers the IT company it recommended. Does it?

Only if the IT company is the EHR vendor's subcontractor, paid by and working for the vendor. If you contract with and pay the IT company directly, it is your business associate and needs its own agreement with you. Ask who signs the invoice.

Do we need an agreement with a locum tenens physician or a per diem nurse?

Usually not. If they work under your direct control, using your systems, on your schedule, they are workforce for HIPAA purposes even if they are paid through an agency, and you train them as staff. The staffing agency itself needs an agreement only if it receives PHI, for example for credentialing or scheduling; most do not.

Is a signed agreement enough, or do we have to check the vendor's security?

The rule requires the agreement and "satisfactory assurances." It does not require you to audit the vendor. In practice, a short questionnaire about encryption, access controls, backup and incident history is reasonable due diligence for any vendor holding a lot of PHI, and a vendor that cannot answer it is telling you something. We also ask for the vendor's own SOC 2 report or HIPAA compliance attestation where one exists.

What to do this week

  1. Pull the twelve-month vendor list from accounts payable and mark every vendor that could create, receive, maintain or transmit PHI.
  2. Walk the office and ask each department what leaves the building and to whom, including software anyone signed up for individually.
  3. Match each marked vendor to a signed agreement; request agreements from the rest and pause PHI sharing with any that refuse.
  4. Check breach notification terms in the agreements you have and request an amendment where the term is 60 days.
  5. Add "agreement on file" as a condition of vendor setup in purchasing and put the annual review on the compliance calendar.