Pick one chart at random from last Tuesday — a chronic heart failure follow-up where the plan involved an acei for chf regimen, a cardiology co-management note, and a lab order. Now count the outside organizations that touched some version of that record within seven days. In most practices the honest number is between eight and fourteen. Your business associate agreement folder probably holds four.

That gap is the subject here. Not the medication, not the therapy decision — the paperwork trail. This post is for the person who signs vendor contracts, answers the OCR complaint letter, and explains to the owner physician why a texting vendor is now a reportable incident.

Trace one ACEI for CHF chart from your exam room outward

Chronic cardiac care is administratively noisy by design. It usually involves shared management between primary care and cardiology, periodic lab monitoring, ongoing prescription refills, and often a remote monitoring or care-management layer. Every one of those is a data movement, and most of them repeat monthly.

Here is the typical set of hops for a single encounter:

  • Your EHR vendor and whoever hosts it
  • An ambient documentation or transcription service, if your clinicians use one
  • The e-prescribing network and any medication history aggregator feeding it
  • The reference lab receiving the monitoring order and returning results
  • Your billing company or claims clearinghouse
  • A patient-engagement platform sending appointment and refill reminders
  • A remote patient monitoring vendor, if the practice bills for it
  • A chronic care management contractor making the between-visit calls
  • Your release-of-information vendor, when the cardiologist's office requests records
  • The IT managed service provider holding backups and remote access
  • A registry, ACO, or payer analytics feed pulling quality measures
  • The cloud fax or secure messaging service that moved the referral packet

The three destinations that are not business associates

Confusing a treatment disclosure with a vendor relationship wastes weeks. You do not need a BAA with the cardiologist you referred to — that is a provider-to-provider disclosure for treatment. You do not need one with the health plan processing the claim; that is payment, and the plan is a covered entity in its own right. And when a patient directs you to send their record to a consumer app under the right of access, the app is not your business associate.

Where practices get into trouble is the middle layer: the companies that exist only to move, store, process, or analyze the data on your behalf. Those are business associates, full stop. HHS's guidance on business associates is short and worth rereading before your next vendor onboarding.

Which vendors handling ACEI for CHF data need a business associate agreement?

Short answer: any organization that creates, receives, maintains, or transmits protected health information to perform a function on your practice's behalf needs a signed BAA before the first record moves. For a chronic cardiac encounter, that typically means your EHR host, transcription or scribe service, billing company, clearinghouse, patient-messaging platform, remote monitoring vendor, care-management contractor, release-of-information service, IT provider with system access, and any analytics or registry vendor. Other treating providers and health plans do not need one.

The test is not "do they read the chart." It is "could they." Your IT provider may never open a note, but persistent administrative access to the system that holds notes makes them a business associate. Same for the backup vendor holding encrypted images they cannot decrypt — HHS has been clear that a cloud service provider is a business associate even when it holds only encrypted data and lacks the key.

Subcontractor flow-down: your vendor's vendor

This is the exposure that grew fastest over the last two years. Your ambient documentation vendor may route audio through a third-party speech model. Your patient-messaging platform almost certainly uses an external SMS gateway. Your care-management contractor may staff overnight calls through an offshore partner.

Under the Privacy and Security Rules, a subcontractor that handles PHI on a business associate's behalf is itself a business associate, directly liable to OCR, and your vendor must have a written agreement with them. You do not sign that agreement. You do have to know it exists.

Add one line to your vendor intake: List every subcontractor with access to our data, and notify us in writing 30 days before adding one. If the vendor will not commit to that, you have learned something useful before signing.

The AI clause you should be writing in 2026

Ask directly whether the vendor uses your data — de-identified or otherwise — to train or improve models, and whether they consider de-identification to release them from the BAA. Get the answer in the contract, not the sales call. A vendor's internal de-identification decision made without your review is a downstream use you cannot defend during an audit.

Recurring care turns a one-time disclosure into a subscription

An episodic visit produces one packet. Ongoing management of an acei for chf regimen produces a stream: monitoring labs on a cycle, refill authorizations, between-visit check-in notes, device or symptom data if remote monitoring is in play, and periodic summaries back to cardiology.

That cadence changes your risk math. A vendor touching your data twelve times a year holds twelve times the record-days of one touching it once. When you rank vendors for security review, rank them by frequency and volume of PHI handled, not by contract value. The cheapest vendor on your accounts payable ledger is frequently the one with the largest standing data set.

It also changes your minimum-necessary analysis. A reminder platform needs a name, a phone number, and an appointment time. It does not need the diagnosis or medication list. Check what your integration actually pushes — in a surprising number of practices, the field mapping was set by the vendor's default template and never reviewed.

Six contract terms that matter more than the boilerplate

HHS publishes sample business associate agreement provisions, and they are a floor, not a ceiling. The sample language satisfies the regulation. It does not protect your operations. Push on these six:

  1. Notification clock. "Without unreasonable delay" gives the vendor up to 60 days. Negotiate for notice within 5 business days of discovery of a suspected incident, with a preliminary report even if scope is unknown.
  2. Who notifies patients. Default is you. If the vendor performs notification, specify approval rights over the letter, the call center script, and the credit monitoring offer.
  3. Subcontractor disclosure and advance notice. Described above.
  4. Return or destruction at termination. Include a deadline, a certificate of destruction, and a named format for returned data. "Infeasible to return" cannot be a permanent excuse.
  5. Cooperation with access and amendment requests. If the vendor holds part of the designated record set, your 30-day right-of-access clock depends on their turnaround. Bind them to a shorter internal deadline.
  6. Security attestation cadence. Annual evidence — SOC 2 report, penetration test summary, or a completed security questionnaire. Note that no vendor is "HIPAA certified" by the government; HHS does not certify or endorse products or companies, so treat certification badges as marketing, not assurance.

Paper the relationship before the data moves

The most common failure I see is not a missing BAA. It is a BAA signed three weeks after the integration went live, backdated in spirit if not on paper, because the clinical need moved faster than the contract review. Interfaces get turned on during a go-live weekend. The privacy officer finds out at the next staff meeting.

Fix the sequencing by making the agreement cheap and fast to produce. If your holdup is drafting time or legal review scheduling, a six-step BAA generator that exports a signature-ready PDF or DOCX removes the excuse — one-time purchase, no subscription, and the output covers the required provisions plus the operational terms above. The rule for your team becomes simple: no PHI leaves the building until the agreement is executed and filed.

File it somewhere retrievable. A shared drive folder named by vendor, with the effective date, the renewal date, and the named contact for security incidents. When OCR asks — and in a vendor-caused breach, they will — you should be able to produce every executed agreement in under ten minutes.

A 90-day cleanup you can actually finish

Days 1–14: build the inventory from money, not memory

Pull twelve months of accounts payable. Pull the list of active integrations and API connections from your EHR admin console. Pull the SSO or user directory to see which external accounts have access. Merge them. That merged list is your real vendor universe; the one in your head is not.

Assign an owner per vendor — practice manager for operational vendors, billing lead for revenue cycle, IT contact for infrastructure. One name each, in a column.

Days 15–30: classify

Three buckets: business associate, not a business associate, unclear. Write the one-sentence rationale for every entry in the "not" bucket. That sentence is your audit defense. Escalate the unclear bucket to counsel in a single batch rather than one at a time.

Days 31–60: close the gaps

Send agreements to every unpapered business associate. Expect a third to counter with their own template — read it for the six terms above and redline. Expect a few to go silent, which tells you to plan a replacement.

Days 61–90: verify and connect to the risk analysis

Request current security attestations. Confirm subcontractor lists. Then feed the vendor register into your Security Rule risk analysis, because a documented risk analysis that ignores third-party data flows is incomplete on its face. NIST SP 800-66r2 maps Security Rule requirements to practical safeguards and is a useful structure if you are building this from scratch. If you would rather generate the risk analysis and policy set directly, the automated compliance document toolset handles that end.

What happens when the vendor is the one that breaks

Assume the call comes at 4:40 p.m. on a Friday. Your care-management contractor's help desk was compromised; the affected roster includes several hundred of your chronic cardiac patients, including the full acei for chf medication and monitoring history for each.

Your obligations start at discovery. As the covered entity, you notify affected individuals without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more residents of a state or jurisdiction also require media notice and contemporaneous notice to HHS; smaller breaches go in the annual log. Every submitted report lands on the public OCR breach portal, where anyone — including your referral partners — can read it.

Note what the last several years of that portal show: the largest incidents by patient count have come from vendors and clearinghouses, not from clinics losing laptops. Your practice's worst-case exposure is increasingly somebody else's server.

Three things make that Friday survivable. A current contact list for every vendor's security team. A BAA that already obligates them to give you scope data fast. And a vendor register that lets you answer "which patients were in their system" without a two-week reconstruction project.

Start with the vendors that touch the chart every month

You do not need to boil the ocean this quarter. Sort your vendor list by how often it receives PHI, take the top ten, and confirm each one has a current, signed, retrievable agreement with real notification terms. Chronic care vendors will cluster at the top — that is the nature of recurring management.

If any of those ten come back unpapered, generate and send the agreement this week rather than waiting for a legal review cycle. The contract that exists on Friday is worth more than the perfect one still in redline in September.