Say your referral coordinator sends out forty calprotectin collection kits a month. Now count the separate organizations that touch identifiable patient data before the result lands in the chart. In most practices the honest number is eight to twelve. The vendor register lists four.

This post is a mapping exercise for whoever owns your business associate agreements. It uses a single, ordinary lab order — a fecal calprotectin, commonly ordered during a gastrointestinal workup and often paired with a specialist referral — as a tracer dye through your administrative plumbing. The clinical question is not the point. The point is that this one order generates a requisition, a specimen, a courier handoff, an interface message, a result document, a portal notification, a prior authorization, and a claim, and each of those steps may sit in a vendor's system.

Trace One Calprotectin Order End to End

Before you can decide who needs a business associate agreement, you need the flow written down. Do this with the actual staff who perform the steps, not from memory in a conference room.

Order entry and transmission

The order originates in your EHR. It may leave through a lab-supplied ordering portal, a standalone interface engine maintained by a third party, or an e-fax service. Ask specifically: who hosts the interface engine? Who holds the credentials? If a regional health information exchange carries the order, that organization belongs on the list too.

Specimen and kit logistics

Stool-based testing frequently involves a collection kit the patient takes home, which means an address, a name, and often a printed requisition move through a fulfillment vendor and a return-shipping arrangement. Some practices use a kit fulfillment service that receives a patient list weekly. That list is PHI. That vendor is a business associate.

Result delivery and patient communication

Results arrive by interface, portal download, or fax. Then your staff notify the patient — often through a secure messaging platform, an automated text and voice reminder vendor, or a patient engagement tool that pushes "your results are ready" notifications. Each of those platforms stores at minimum the fact that a specific person is receiving calprotectin results from a GI-focused practice. That is protected health information, not metadata.

Referral, prior authorization, and revenue cycle

An abnormal result commonly triggers a specialist referral, which means a records release, possibly through a release-of-information vendor. The claim moves through a clearinghouse. Denials and appeals may route through an outsourced revenue cycle firm. Patient statements go through a print-and-mail house. Balances may land with a collection agency.

Write all of it on one page. Most practices are surprised twice: by how many vendors appear, and by how many of them have no executed agreement on file.

Does Your Reference Lab Need a BAA for Calprotectin Testing?

Generally, no. When your practice sends a calprotectin order and specimen to an independent reference laboratory, the lab is a covered health care provider receiving PHI for treatment purposes. Disclosures between covered entities for treatment do not create a business associate relationship, and HIPAA does not require a business associate agreement for them. HHS states this directly in its guidance on business associates.

But the analysis flips when the lab does something for you rather than for the patient. You likely need an agreement if the lab also:

  • Hosts an ordering or results portal that stores your practice's patient data
  • Provides and remotely services an in-office analyzer that transmits identifiable results
  • Handles patient billing or statements on your behalf under a client-bill arrangement
  • Supplies interface middleware installed in your environment
  • Aggregates your ordering data into reports or analytics delivered back to you

Couriers are a separate question. HHS has described a narrow "conduit" exception covering entities that merely transport information without accessing it other than randomly or infrequently — the postal service and comparable carriers. A contracted courier moving labeled specimens and paper requisitions often falls inside that exception. Document your reasoning either way, because "we assumed" is not a defensible position during an investigation.

The Six Vendors Practices Miss on This Pathway

Across vendor inventories, the same categories go undocumented. Check these against your list today.

  1. The e-fax provider. Results and referral packets often ride on it. If it stores fax images in the cloud, it holds PHI at rest.
  2. The appointment reminder and recall texting platform. A recall campaign for patients with pending calprotectin follow-up is a PHI disclosure to that vendor.
  3. The IT managed service provider. They have domain administrator rights. Persistent access to systems containing PHI creates the relationship, even if they never open a chart.
  4. The clearinghouse. Clearinghouses are covered entities in their own right, but when performing claims functions on a provider's behalf they act as business associates. Have the agreement.
  5. Translation and interpretation services. A telephonic interpreter walking a patient through home specimen collection hears clinical detail tied to an identity.
  6. Document shredding and offsite storage. Requisition copies, kit labels, and result printouts end up in these bins.

Add a seventh line item that is not a vendor but behaves like one: the personal cloud drive someone on your staff uses to move a spreadsheet home. Vendor mapping surfaces those.

Build the Register: Five Columns, One Named Owner

A usable vendor register has five columns and no more. Anything longer stops being maintained by month three.

  • Vendor and service. Legal entity name, not the product nickname staff use.
  • Data touched. Specific fields, not "patient info." Name plus test type plus date of service is a different exposure than name plus phone number.
  • Relationship classification. Business associate, covered entity treatment disclosure, conduit, or no PHI. With a one-line rationale.
  • Agreement status and date. Executed, requested, or gap. Include the countersignature date, not the date you sent it.
  • Internal owner. A person. The practice manager owns the courier; the billing manager owns the clearinghouse and statement vendor; the privacy officer owns the register itself.

When the register shows gaps — and on a first pass it always does — you need executable agreements quickly, not a three-week legal cycle for a shredding contract. A six-step wizard that produces a signature-ready business associate agreement with PDF and DOCX export handles the routine cases as a one-time purchase, which keeps the register from stalling on the small vendors while counsel focuses on the two or three contracts that genuinely warrant negotiation.

Contract Terms That Matter More Than the Signature

HHS publishes sample business associate agreement provisions. Those are a floor. Three terms deserve your attention on a lab-heavy pathway.

Subcontractor flow-down

Your kit fulfillment vendor uses a printing subcontractor. Your RCM firm uses offshore coders. The agreement must require written assurances from every downstream subcontractor that handles PHI, and you should have the right to ask who they are. Ask once a year in writing.

The breach reporting clock

The Breach Notification Rule gives covered entities up to 60 calendar days from discovery to notify affected individuals. If your vendor consumes 55 of those days before telling you, you have five. Negotiate a contractual reporting obligation measured in days from discovery — many practices set five business days for a suspected incident and 24 hours for confirmed unauthorized access. Review the requirements at the HHS breach notification page and align your incident policy to whatever your contracts actually say.

Return or destruction at termination

When you switch reference labs or drop a texting platform, specify what happens to the historical data, in what format you receive it, and how destruction is certified. Put the deliverable timeline in the contract — 30 days from termination is typical. Offboarding is where orphaned PHI accumulates.

A 90-Day Cleanup Schedule

If you have never mapped this pathway, do it on a calendar rather than in bursts.

Days 1–15. Shadow the workflow. One staff member from front desk, one from clinical support, one from billing. Build the five-column register from what they actually do.

Days 16–45. Classify every row. Pull existing agreements from wherever they live — shared drives, an old contract binder, a former administrator's email. Note expiration and amendment dates. Search the vendor names against the OCR breach reporting portal to see whether any have reported incidents affecting 500 or more individuals.

Days 46–75. Execute the gaps. Start with the vendors holding the most sensitive combinations: the results delivery platform, the RCM firm, the MSP.

Days 76–90. Update your risk analysis to reflect the mapped data flows, and update your onboarding checklist so the next vendor cannot go live without a countersigned agreement. NIST's SP 800-66r2 is a practical reference for tying vendor inventory into Security Rule risk management.

What to Recheck During Your 2026 Review

Two items belong on this year's agenda. First, the proposed Security Rule update HHS published in January 2025 would tighten expectations around asset inventories, network mapping, and written assurances from business associates. Confirm its current status before assuming your obligations are unchanged, but note that a defensible vendor map is useful regardless of how the rulemaking resolves.

Second, if your organization receives records from a federally assisted substance use disorder program, the Part 2 alignment requirements that took effect in February 2026 change what your agreements need to say about redisclosure. That is a contract-language review, not a workflow change.

Set a fixed annual date for the register review — the same week each year, owned by the privacy officer, with sign-off from the practice administrator. A vendor map that is refreshed once and then filed is a document you will regret during an investigation.

Start With the Gaps You Already Know About

You probably named two or three unpapered vendors while reading this. Pull those first. If you need the agreements drafted and signed this week, generate them through the BAA wizard, and if your broader documentation set — risk analysis, policies, workflow records — has drifted since the last review, automating the full compliance document set is a reasonable next step once the vendor map is stable.