Aphthous Ulcers Referrals: Which Vendors Need a BAA
A patient calls Monday morning about recurring mouth sores. By Friday, the chart note, an intraoral photo, a referral packet, a claim, and two text reminders have left your building. Count the outside companies that touched that data and you will land somewhere between eight and sixteen. This post is a vendor-mapping exercise built around a common, low-drama encounter — recurrent aphthous ulcers — because the administrative plumbing around a simple case is identical to the plumbing around a complicated one, and it is easier to see when the clinical noise is turned down.
You are reading this because you own the vendor list, and because the vendor list is where breach notification obligations get decided months before anyone breaches anything.
Fourteen Vendors, One Mouth Sore
Aphthous ulcers show up in primary care, urgent care, dental, and oral medicine. Recurrent or non-healing cases often route to a specialist, and that referral is the moment protected health information crosses an organizational boundary. That is the administrative fact that matters here — not the lesion.
Walk the pathway and write down every place data lands:
- Online scheduling widget on your website
- Practice management and EHR hosting
- Eligibility verification service
- Intraoral photography app or camera-to-cloud sync
- Image storage or PACS-lite service
- Ambient documentation or transcription vendor
- Referral platform or direct messaging service (HISP)
- The specialist's own portal for uploads
- Pathology lab (if tissue is sent)
- Clearinghouse
- Statement printing and mailing house
- Patient texting and recall vendor
- Interpreter or translation service
- Managed IT provider with remote access to workstations
Fourteen. And that list excludes the subcontractors each of those vendors uses. Your practice does not sign agreements with subcontractors, but you inherit the consequences when one of them gets encrypted by ransomware.
What Counts as a Business Associate in an Aphthous Ulcers Pathway
A business associate is any person or entity, outside your workforce, that creates, receives, maintains, or transmits protected health information to perform a function or service on your behalf. The test is function and access, not industry. A photo-storage company that has never heard of a canker sore is a business associate the moment your intraoral images sync to its servers. A specialist you refer to is not a business associate, because treatment disclosures between covered entities need no BAA. A landlord with a key to the file room is not a business associate; a shredding company that takes custody of charts is.
Three quick discriminators your staff can apply without calling counsel:
- Does the vendor perform a service for you? If yes and PHI is involved, BAA.
- Is the vendor a treating provider acting for the patient? If yes, no BAA — that is treatment, payment, or health care operations.
- Does the vendor only move sealed, encrypted data without routine access? That is the conduit exception, and it is narrow.
The conduit exception is narrower than your vendor's sales deck
The conduit exception covers entities like the postal service and telecom carriers — transmission only, random or incidental access, no persistent storage. Cloud storage providers do not qualify simply because they say the data is encrypted. HHS has been explicit that a cloud service provider that maintains encrypted PHI is a business associate even when it holds no decryption key. Read the agency's own guidance on business associates before you accept a vendor's claim that it is "just a pipe."
Mapping the Flow, Hop by Hop
Intake and scheduling
A patient books online and types "painful mouth sores, third time this year" into the reason-for-visit box. That free text is PHI the instant it leaves the browser. If your scheduling widget is a third-party embed, you need a BAA with that vendor and you need to know where the form data rests before it reaches your practice management system.
Same review applies to any analytics or advertising pixel on pages where patients describe symptoms or complete forms. Tracking technologies on authenticated patient-facing pages have drawn sustained regulator attention from both HHS and the FTC. If you cannot state which pixels fire on your appointment request page, that is a finding, not a footnote.
Documentation and imaging
Clinicians photograph oral lesions to track healing across visits. Ask three questions of whatever tool captures those images: where is the file stored, does it back up to a personal cloud account tied to the clinician's phone, and who at the vendor can view it for support purposes. Personal-device photo sync is one of the most common uncontrolled data flows in small practices, and it usually surfaces during a risk analysis rather than during vendor onboarding.
Ambient scribes and transcription services deserve the same scrutiny plus one more question: is your audio or transcript used to train models, and does the BAA and the underlying service agreement say so consistently. Contradictions between the BAA and the terms of service are common. The BAA controls PHI use, but a conflicting ToS is a negotiation you want to have before go-live, not after.
The referral hop
Recurrent or atypical aphthous ulcers frequently generate a referral to oral medicine, ENT, dermatology, or GI, and sometimes a biopsy. Records move. This is where practices get sloppy, because the referral feels like clinical work rather than data transfer.
Sort the referral hop into three buckets:
- Covered entity to covered entity. You fax or Direct-message the packet to the specialist. Treatment disclosure. No BAA.
- Through a platform. A referral management vendor, e-fax service, or HISP handles the transmission and often stores a copy. BAA required.
- Pathology. The lab is a covered entity performing its own treatment function. No BAA. But the courier, the specimen tracking app, and the results-delivery interface may each be business associates of someone — confirm whose.
Billing and the money trail
The claim leaves through a clearinghouse, which is itself a covered entity when handling standard transactions and a business associate when performing services on your behalf. Get the BAA regardless — clearinghouses expect it. Statement printing, lockbox services, and any collections agency all require executed agreements, and the collections BAA should specify exactly which data elements the agency receives. There is rarely a reason for a collections vendor to see a diagnosis.
Patient communication
Follow-up texts, recall reminders, portal messages, and post-visit surveys all route through vendors. A survey platform that asks "how was your visit with Dr. Reyes on July 14" is handling PHI. So is the texting vendor that stores message history. Both sign.
Vendors That Practices Wrongly Exclude
When I audit a vendor list, the same five gaps recur:
- The managed IT provider. Remote access to a workstation with an open chart is access to PHI. Always a business associate.
- The answering service. Takes symptom details after hours. Business associate.
- The interpreter agency. Hears the entire encounter. Business associate.
- The document shredding company. Takes custody of charts. Business associate.
- The email or file-sharing platform. If clinicians attach anything to anything, business associate.
And the reverse error: practices that chase BAAs from janitorial services, plumbers, and the vending machine company. Incidental exposure is not the standard. Function plus PHI is the standard. Chasing signatures you do not need burns credibility with vendors you do need.
Clauses That Matter When Records Leave Your Building
A BAA that only restates the regulation is a compliance artifact, not a control. Four provisions do real work:
Breach notification timing. The rule gives you 60 days from discovery to notify affected individuals. If your BAA lets the vendor take 60 days to tell you, your clock is already expired. Negotiate to 10 business days or fewer, with immediate preliminary notice. Review the Breach Notification Rule requirements so you know exactly what you will need from the vendor to build a notice.
Subcontractor flow-down. The vendor must bind its subcontractors to equivalent terms. Ask for the list. A referral platform running on three cloud regions and a support desk in a fourth country is a supply chain, not a product.
Return or destruction at termination. Specify format and deadline. "Commercially reasonable" means whatever the vendor decides in the middle of a contract dispute.
Access and amendment support. When a patient requests records that live only in the vendor's system, the vendor must produce them fast enough for you to meet the 30-day access deadline. Put that in writing.
HHS publishes sample business associate agreement provisions as a floor. If drafting from that baseline for each new vendor is what keeps stalling, a six-step BAA generator that exports signature-ready PDF and DOCX removes the excuse — one-time purchase, no subscription, and the output is consistent enough that your files stop looking like they were assembled by four different people over six years.
A Two-Week Vendor Mapping Sprint
You do not need a project plan. You need two weeks and one person who will not let it drift.
Days 1–3: Build the raw list
Pull every recurring vendor payment from the last 18 months of accounts payable. Add every app on the front desk workstations, every browser extension, and every integration listed in your EHR's marketplace tab. Ask each clinician what they use on their phone during a visit. Office manager owns this step; expect 30 to 60 line items.
Days 4–6: Apply the three-question test
Privacy officer sorts each vendor into BAA required, not required, or unclear. Document the reasoning in one sentence per vendor. The unclear pile is where you spend your judgment — and where you write to the vendor and ask directly what PHI it touches.
Days 7–10: Reconcile against signed agreements
Match every "BAA required" vendor to an executed, countersigned, dated document. Unsigned counts as missing. A BAA signed in 2016 by a practice manager who left in 2019, for a product the vendor has since rebuilt, is a document worth re-executing.
Days 11–14: Close gaps and set a review date
Send agreements to every gap vendor. Log responses. Set a calendar reminder to re-run the sprint annually and any time you add a system. Feed the finished map into your security risk analysis — a vendor inventory is a required input, and the NIST SP 800-66r2 implementation guidance is the clearest free walkthrough of how that connects. If you would rather generate the risk analysis and supporting policies from structured inputs than from a blank template, the automated compliance document set handles that side.
When the Vendor Refuses to Sign
It happens, usually with consumer-grade tools a clinician adopted without asking. The response is not a longer email chain. It is a decision: either the tool stops touching PHI, or the tool leaves. Document the decision, the date, and who made it. "We asked and they said no" is not a defense; "we asked, they declined, and we migrated to an alternative on March 3" is.
For a workflow as routine as evaluating aphthous ulcers, no single vendor is worth an unbounded disclosure. That is the useful thing about mapping a low-acuity pathway — nothing on the list is so clinically indispensable that you cannot replace it.
Start With One Pathway
Pick the aphthous ulcers pathway, or any encounter type your practice sees weekly. Trace it end to end. You will find vendors nobody remembered onboarding and agreements nobody remembered signing. Then generate the missing BAAs, file them where your next auditor will find them, and put the annual review on the calendar before you close the tab.