A dental practice in the Midwest used a cloud based practice management platform. The platform held appointment records, treatment notes, and patient contact details for the practice and for thousands of others like it. In March of this year the federal Office for Civil Rights announced a settlement with that platform's parent company over a breach affecting roughly 15 million individuals.
The practices whose patients were exposed did not lose that data themselves. Their own computers were fine. Their own staff did nothing wrong. The data left through a vendor they had signed a contract with and then stopped thinking about.
That contract has a name. Under the HIPAA Rules it is a Business Associate Agreement, and the obligation to have one sits at 45 CFR 164.308(b). It is one of the shortest requirements in the Security Rule and one of the most commonly unmet, because signing it feels like paperwork and maintaining it feels like nothing at all.
What a business associate actually is
The definition is broader than most practice owners assume. A business associate is any person or organization, other than a member of your workforce, that creates, receives, maintains, or transmits protected health information on your behalf.
Note the verb list. Maintains is in there. A vendor does not have to read the data, analyze it, or do anything with it to be a business associate. Holding it is enough. That single word pulls in a category of vendor that practices routinely overlook: the offsite backup provider, the cloud file storage account, the document shredding company that takes custody of paper charts before destroying them.
It also does not matter whether the vendor is large or small, local or national, or whether they describe themselves as HIPAA compliant on their website. The test is functional. If they touch the information on your behalf, the agreement is required.
The vendors that are almost always business associates
Working from what we see in practice assessments, these are the ones that come up in nearly every small medical, dental, or behavioral health office.
The billing and revenue cycle company, which by definition handles claims containing diagnoses and patient identifiers. The information technology provider or managed service provider, because administrative access to the network is access to everything on it. The electronic health record vendor, including the hosted or cloud version. The offsite or cloud backup service, which holds a complete copy of the record by design. The answering service or scheduling service that takes patient calls. The transcription service. The shredding vendor. The practice management consultant who reviews charts. The cloud storage account where someone saved a spreadsheet of patient balances.
Two categories cause the most confusion, so they are worth stating plainly. A vendor that only encounters protected health information incidentally, such as a janitorial service, is generally not a business associate. And a provider you refer patients to for treatment is not a business associate either, because treatment disclosures are permitted on their own terms. The line is whether they are performing a function or service for you that involves the information.
What the agreement has to say
A Business Associate Agreement is not a formality that can be satisfied with a sentence in a service contract. The required content is specified, and a document missing these terms does not do the job:
It must establish the permitted and required uses and disclosures of protected health information by the business associate, and state that the business associate will not use or disclose the information other than as permitted by the contract or required by law.
It must require the business associate to use appropriate safeguards, and to comply with the Security Rule with respect to electronic protected health information. Since the 2013 Omnibus Rule, business associates are directly liable for Security Rule compliance, not merely contractually liable to you.
It must require the business associate to report breaches and security incidents to you, and to report any use or disclosure not permitted by the contract.
It must require the business associate to ensure that any subcontractor it engages agrees to the same restrictions. This is the flow down term, and it is the one most often missing. Your billing company's offshore data entry contractor is reached through this clause or not at all.
It must address the return or destruction of protected health information at termination, and provide for termination of the contract if the business associate violates a material term.
It must make the business associate's internal practices, books, and records available to the Secretary of Health and Human Services for determining compliance.
Why this is the finding that arrives with company
Business Associate Agreement failures rarely get discovered on their own. They surface during the investigation of something else, which means they arrive at the worst possible moment and they compound whatever else was found.
The pattern runs like this. A vendor is breached. The vendor notifies you. You notify patients and the Office for Civil Rights, because the obligation to notify follows the data, not the server it was sitting on. The investigation opens. Early in that process a regulator asks for the agreement with that vendor, and separately for your risk analysis showing that you had identified where protected health information lives.
If the agreement does not exist, is unsigned, predates the 2013 Omnibus Rule, or lacks the subcontractor flow down, that is a separate violation from the breach itself. It is also one that no incident response can undo, because the document either existed before the incident or it did not.
Five questions worth answering this week
None of this requires a consultant. It requires someone to spend an afternoon with a list of vendors and a filing cabinet.
Can you produce a complete list of every vendor that touches patient information? Not the vendors you remember. The list assembled by walking the accounts payable ledger and the list of software the practice logs into. Practices routinely find two or three they had forgotten.
For each one, can you put your hands on a signed agreement today? Signed by both parties, with a date. An unsigned template in a folder is not an agreement, and neither is an email in which a vendor said they are HIPAA compliant.
Does each agreement contain the subcontractor flow down clause? Search the document for the word subcontractor. If it is not there, the chain stops at your direct vendor and everything downstream of them is unaddressed.
Was it signed after September 2013? Agreements written before the Omnibus Rule took effect are missing the direct liability and breach notification provisions that rule added. A 2011 agreement is a historical document, not a current control.
Does the agreement say what happens to your data when the relationship ends? This is the clause that matters when you change billing companies or your information technology provider goes out of business, and it is the one nobody reads until that day arrives.
What to do with what you find
Expect gaps. Every practice we assess has them, and the number is usually between three and eight. The gaps are not the problem. Not knowing about them is the problem, because a documented gap with a plan attached is a manageable finding, and an undocumented gap discovered by an investigator is something else entirely.
Build the vendor list first and keep it current, because the risk analysis that regulators ask for depends on knowing where the information lives. Request agreements from the vendors that are missing them, which is a routine request that any legitimate healthcare vendor handles regularly. Replace anything signed before 2013. Note the ones that refuse or stall, because a vendor unwilling to sign a Business Associate Agreement is telling you something useful about how they handle your patients' information.
Related reading: what a HIPAA risk analysis actually involves, what happens when a vendor goes offline, and the gaps hiding in your IT service agreement. For contract language specifically, see our contract review service.
Do you know which vendor could take you offline?
The vendor dependency list takes about fifteen minutes and is the highest-return security exercise a small business can do without spending money. If you want help building it, and connecting it to the contingency and supply chain controls that CMMC and NIST 800-171 assessments check, start with a conversation.
Book a free thirty minute consultation