AST and ALT Results: Mapping Every Vendor That Needs a BAA
A patient comes in Tuesday morning with fatigue. The clinician orders a hepatic panel. Between the blood draw and the moment the ast and alt values land in the chart with a signed-off comment, that patient's name, date of birth, account number, and diagnosis code will pass through somewhere between six and twelve outside systems. If you are the privacy officer, your job is to name every one of them and know which ones hold a signed Business Associate Agreement.
Most practices can name three. This article walks the full pathway, sorts each hop into needs a BAA, does not need a BAA, and needs a BAA and probably doesn't have one, and gives you a repeatable exercise to do it for every order type in your practice.
Trace the Order, Not the Org Chart
Vendor inventories built from the accounts-payable list miss things. Vendor inventories built from a single order trace do not, because you follow the data instead of the invoice.
Here is a typical community-practice pathway for a routine hepatic panel that includes ast and alt values, with the actor at each hop:
- Order entry. Your EHR, hosted by a vendor, on infrastructure that vendor rents from a cloud provider.
- Order transmission. An interface engine or integration middleware pushes the HL7 order to the reference lab.
- Specimen collection and courier. Either in-house phlebotomy plus the lab's own courier, or a draw at the lab's patient service center.
- Resulting. The reference lab returns results through the same interface, or via a results portal, or by fax.
- Fax landing. If by fax, an e-fax vendor receives, stores, and converts the document.
- Scanning and indexing. A document management module, sometimes a separate vendor, sometimes an offshore indexing service.
- Clinician review and patient notification. A patient portal, a secure messaging platform, or an SMS notification vendor tells the patient results are ready.
- Follow-up scheduling. Your scheduling or recall vendor, which now holds a reason-for-visit field.
- Referral, if one is made. A referral management platform or a direct secure messaging service sends records to a gastroenterology or hepatology practice.
- Billing. Your clearinghouse and, in many practices, an outsourced revenue cycle management firm.
- Everything underneath. Your managed service provider with remote access to workstations, your backup vendor, your shredding company.
Eleven hops. If you outsource after-hours triage, add an answering service. If you use interpreters, add a language services vendor. If you participate in a registry or a payer quality program, add that data extract.
Which Vendors in the AST and ALT Pathway Need a BAA
Short answer: any vendor that creates, receives, maintains, or transmits protected health information on your behalf needs a signed BAA. That includes your EHR host, interface middleware, e-fax vendor, document indexing service, patient messaging platform, clearinghouse, billing company, IT managed service provider, cloud storage and backup provider, and offsite shredding company. It does not include the reference lab itself, the referral specialist, or the health plan, because those are covered entities exchanging information for treatment, payment, or health care operations under their own HIPAA obligations.
That distinction trips up a lot of practices. Your reference lab is not your business associate when it performs and reports a hepatic panel. It is a covered entity providing treatment, and the disclosure of the order to the lab is a treatment disclosure. Sending the lab a BAA for that relationship is harmless but unnecessary, and it can confuse the file. If that same lab also provides you an interface, hosts a results portal branded to your practice, or performs billing services for you, evaluate those services separately — those may well be business associate functions.
The same logic applies to the specialist. When ast and alt findings prompt a referral, sending the record to the receiving practice is a treatment disclosure between two covered entities. No BAA. What you do need is a documented release process and a minimum-necessary judgment about what accompanies the referral. HHS explains the boundaries of the business associate definition in its guidance on business associates, and it is worth reading before you argue with a vendor's legal team.
The Conduit Exception Is Narrower Than Your Vendor Claims
Expect at least one vendor to tell you they are a "mere conduit" and therefore exempt. That exception is deliberately narrow. It covers entities that transport information without accessing it other than randomly or incidentally — the postal service, a private courier, a telecommunications carrier moving packets.
It does not cover a vendor that stores the data. An e-fax service that keeps a copy of your inbound results for 90 days in a web inbox is storing PHI. A cloud provider that holds encrypted backups is storing PHI even if it has no decryption key. Persistence of custody, not the ability to read, is what pulls a vendor into business associate status. If a vendor invokes the conduit exception while offering you a searchable archive, they are wrong, and you should get that in writing before you accept it.
The Four Vendors Most Practices Miss on an AST and ALT Pathway
When I audit a vendor list against an actual order trace, the same four gaps show up.
1. The e-fax account someone opened with a credit card
Lab results still arrive by fax in most practices. Someone in the back office signed up for a consumer-tier fax service years ago because the old machine died. Consumer tiers usually do not offer a BAA at all. Check which tier you are on, not just which brand.
2. The notification vendor that touches the reason for the message
A text that says "Your results are ready, please log in" carries the patient's phone number, your practice name, and the fact of a clinical encounter. That is PHI. The vendor needs a BAA even if no numeric value ever leaves the EHR.
3. The managed service provider with a remote-access agent
Your MSP does not want to touch PHI and probably never opens a chart. Irrelevant. Persistent administrative access to systems holding PHI creates business associate status. This includes the after-hours help desk their contract subcontracts to.
4. The analytics or registry extract nobody owns
Quality reporting extracts, care-gap dashboards, and payer-sponsored population health tools pull lab values including ast and alt into third-party platforms. These are frequently configured by a clinician or a payer rep without routing through the privacy officer. Find them by asking your EHR vendor for a list of active API and interface connections.
The 90-Minute Vendor Mapping Exercise
Block ninety minutes. Bring your practice administrator, one clinical lead, and whoever holds the EHR admin credentials.
Minutes 0–20. Pick one real order from last week. Walk it hop by hop on a whiteboard. Do not consult the vendor list yet — you will anchor on it and miss things.
Minutes 20–40. For each hop, write the vendor's legal entity name, the contract owner inside your practice, and whether PHI is stored or only transited.
Minutes 40–60. Pull the contract file. Mark each vendor: BAA on file and current, BAA on file but signed before the last material change to services, no BAA, or not applicable with a documented reason.
Minutes 60–90. Assign owners and dates for every gap. Nothing leaves the room unassigned.
Repeat the exercise for imaging orders, prescriptions, and prior authorizations. Four traces will surface nearly your entire vendor footprint. NIST's SP 800-66r2 frames this kind of asset and data-flow inventory as the foundation of a defensible risk analysis, and OCR expects the risk analysis to reflect where PHI actually lives — not where you assume it lives.
What Boilerplate BAAs Leave Out
Getting a signature is step one. Getting terms you can operate against is step two. HHS publishes sample business associate agreement provisions, and they are a floor, not a ceiling. Five clauses to check on every agreement covering a lab-results pathway:
- Breach notification timing. The regulatory outer limit gives you 60 days from discovery to notify individuals. If your BA takes 55 of those days to tell you, you cannot comply. Negotiate notification to you within 5 business days of discovery, with a preliminary notice within 24 hours.
- Subcontractor flow-down, named. Require the BA to maintain agreements with its subcontractors and to disclose material subcontractors on request. Your e-fax vendor's storage provider is in your chain whether you named it or not.
- Permitted uses beyond your instruction. Many agreements quietly authorize de-identification and "product improvement." Decide whether you accept that, and strike it if you don't.
- Return or destruction at termination. Specify a format you can actually ingest and a deadline. "Commercially reasonable efforts" is not a deadline.
- Cooperation with patient access requests. If a vendor holds a designated record set component, your 30-day clock under the access right does not pause while you wait for them.
If the exercise above turned up three or four vendors with no agreement on file, you need signature-ready documents this week, not next quarter. A six-step BAA generator that exports signature-ready PDF and DOCX will get those out the door same-day for a one-time cost, which is usually faster than routing a redline through counsel for a $40-a-month fax service. Save the legal review budget for the EHR and RCM contracts, where the negotiation actually matters.
Where the Records Request Lands After the Referral
Elevated ast and alt values frequently generate a specialist referral, and referrals generate records requests in both directions. Your front desk needs to distinguish three things that arrive looking identical:
A patient request for their own records. Thirty days to respond, one 30-day extension with written notice, fee limited to a reasonable cost-based amount. This is the request that generates enforcement actions, and it is the one front-desk staff most often mishandle by demanding a form the regulation does not require.
A treatment request from the specialist's office. Permitted disclosure, no authorization needed, minimum necessary does not apply to treatment disclosures. Verify the requester, then send.
A request from an attorney, insurer, or employer. Authorization required, and the authorization must be valid on its face. Train staff to check the expiration date and the specific description of information — a blanket "all records" authorization signed three years ago is not a green light.
Practices that delay or obstruct these transfers also risk information blocking exposure under the ONC framework. HealthIT.gov maintains current information blocking guidance and exceptions, and "our vendor charges us for the export" is not among the recognized exceptions.
Put It on a Calendar or It Won't Happen
Vendor mapping decays. New integrations get added, contracts renew with changed terms, vendors get acquired. Three recurring items keep the map alive:
- Quarterly: pull the list of active EHR interfaces and API connections. Compare against your BAA register. Anything new gets an owner within five business days.
- Annually: re-trace one order end to end. Update the risk analysis to reflect what you found.
- At every contract renewal: confirm the BAA still matches the services. A vendor that added a storage feature since signing has changed the risk profile.
Keep the register somewhere an auditor can read it without your narration: vendor legal name, services, PHI touched, BAA execution date, subcontractor disclosure status, and last review date. If you are rebuilding the broader documentation set at the same time — risk analysis, policies, workforce training records — automating the full compliance document set is less painful than assembling it from templates the week before a payer audit.
Start with one order trace this week. Pick the hepatic panel. Follow the ast and alt result from the draw chair to the chart to the referral packet, name every hand it passes through, and close the agreements you find missing. Ninety minutes now beats a breach investigation later.