A patient is imaged on a Tuesday for a suspected compression fracture. By Friday, that single encounter has pushed protected health information into at least nine organizations your practice does not own: the teleradiology group reading for the imaging center, your e-fax provider, the referral platform that routed the spine consult, the DME supplier who took the brace order, the ambient documentation tool your PA turned on, your clearinghouse, your appointment-reminder texting service, your offsite backup vendor, and the answering service that took the after-hours call.

Your BAA folder has four of them.

This post is a mapping exercise for practice administrators and privacy officers. It walks the third-party data flows that a compression fracture pathway typically triggers, sorts which of those vendors legally require a signed business associate agreement, and gives you a 30-day workflow to close the gaps you find. No clinical content — this is about paper, contracts, and who is holding your patients' data at 2 a.m.

Why This Pathway Exposes Vendor Gaps Better Than Most

Compression fractures are useful as a mapping exercise precisely because the encounter rarely stays inside one building. These cases commonly involve diagnostic imaging, a referral to a spine or orthopedic specialist, durable medical equipment, physical therapy, and sometimes a bone density workup — each of which is a separate organization with separate systems.

A routine sick visit might touch three vendors. This pathway touches ten to fifteen. If your BAA inventory can survive a walkthrough of a compression fracture case, it will survive most of what your practice does.

The other reason: these patients skew older, which means Medicare billing, DME documentation requirements, family caregivers requesting records, and often a skilled nursing or home health handoff. Every one of those creates a disclosure that someone in your office has to document or authorize.

Walking the Data Flow, Stop by Stop

Intake and scheduling

Before anyone sees the patient, PHI has already moved. Your online scheduling widget captured a name, DOB, and reason for visit. Your eligibility-verification tool queried a payer. Your reminder platform sent a text.

Ask a specific question about each: does the vendor store the data, or merely transmit it without persistent access? Storage almost always creates a business associate relationship. So does routine access, even if the vendor claims it "doesn't look at" the data.

Imaging and the reading group

If you send the patient to an outside imaging center, that center is a covered entity in its own right and the disclosure is treatment — no BAA needed between you. But the PACS vendor, image-sharing portal, or CD-burning service that moves the study back to you may be a business associate of one party or the other. Find out which. "The imaging center handles that" is not a documented answer.

If your practice operates its own imaging and contracts a teleradiology group, look at the contract structure. A group that reads and renders an interpretation is generally providing treatment. A vendor that hosts, routes, or archives images on your behalf is a business associate.

The referral itself

Referrals to a spine specialist typically move through one of three channels: direct fax, an EHR-integrated referral module, or a standalone referral-management platform. The first two are usually covered by agreements you already have. The third is the one that goes unsigned.

Standalone referral platforms are frequently adopted by a single physician or office manager without procurement review. They store demographics, clinical notes, and often the imaging report. They are business associates. Check whether yours has a countersigned agreement or just a click-through terms page.

Durable medical equipment

A brace order sends demographics, diagnosis codes, insurance information, and often a copy of the clinical note to the DME supplier. If the supplier is billing the payer directly and furnishing the item to the patient, that is a treatment and payment disclosure between covered entities — no BAA required.

But if the supplier also runs a prior-authorization service for you, or maintains a portal where your staff uploads documentation on the practice's behalf, examine that second function separately. One vendor can be both a covered entity and, for a distinct service line, your business associate.

Physical therapy and post-acute handoffs

Same analysis. PT clinics, home health agencies, and skilled nursing facilities receiving records for treatment purposes do not need a BAA with you. The health information exchange or care-coordination network sitting between you and them frequently does, depending on how it is organized. Ask the HIE for its participation agreement and its HIPAA role determination in writing.

Billing, coding, and collections

Your clearinghouse, outsourced coder, RCM firm, denial-management consultant, and any collections agency are unambiguously business associates. So is the analytics vendor producing your monthly revenue dashboards if that dashboard drills down to patient level.

The tools nobody put on the list

Transcription and ambient scribe tools. Cloud storage where someone parked a spreadsheet of pending referrals. The secure messaging app the front desk uses to ping the back office. Your IT managed service provider, who has domain admin. Your document shredding company. Your EHR's own subcontracted hosting provider.

Walk the physical office once with a notepad. Every screen, every app icon, every login. That list will be longer than your contract list.

Which Vendors in a Compression Fracture Pathway Need a BAA?

Short answer: any vendor that creates, receives, maintains, or transmits PHI on your practice's behalf needs a signed business associate agreement. Vendors that receive PHI for their own treatment, payment, or health care operations purposes as covered entities do not.

Applied to this pathway:

  • BAA required: referral-management platforms, clearinghouses, RCM and coding firms, transcription and scribe tools, cloud storage and backup, IT managed service providers, patient texting and reminder services, e-fax vendors, appointment scheduling widgets that retain data, analytics vendors with patient-level access, collections agencies, shredding companies handling PHI.
  • No BAA required: the imaging center, the spine specialist, the PT clinic, the home health agency, the DME supplier furnishing and billing the item, and the patient's health plan — all receiving PHI for treatment or payment as covered entities.
  • Depends on the arrangement: health information exchanges, teleradiology groups, prior-authorization services, and any vendor that performs more than one function for you.

HHS maintains guidance on business associate status and publishes sample agreement provisions that set the required floor. The sample provisions are a floor, not a contract — they omit indemnification, insurance, breach cost allocation, and termination mechanics you will want.

The Subcontractor Layer You Inherit

Your business associates have business associates. Under the HIPAA rules, a subcontractor that handles PHI on a business associate's behalf is itself a business associate and must be bound by a downstream agreement. You are not required to sign directly with them — but you are entitled to know the chain exists and to require, contractually, that it be papered.

Ask each vendor for a list of subprocessors that touch PHI, and a commitment to notify you before adding new ones. Cloud hosting, offshore coding labor, SMS gateways, and email delivery services are the usual four you will find. Offshore access in particular should be a named term in your agreement, not a discovery you make during a breach investigation.

If a vendor cannot tell you where its data is processed within a week of being asked, that is your answer about their program maturity.

A 30-Day Workflow to Close Your BAA Gaps

Days 1–5 — Build the inventory. Privacy officer owns this. Pull three sources: the accounts payable vendor list, the browser bookmarks and installed apps on three clinical workstations, and a five-minute interview with each department lead asking "what do you log into?" Merge into one spreadsheet with columns for vendor, function, data touched, and contract on file yes/no.

Days 6–10 — Classify. For each row, mark business associate, covered entity, conduit, or no PHI. Document the reasoning in a sentence. The reasoning matters more than the label; an auditor will accept a defensible judgment and will not accept a blank cell.

Days 11–20 — Chase signatures. Office manager owns outreach. For vendors with no agreement, send the request with your own template attached rather than asking for theirs. You will get to signature faster and on better terms. If you do not have a template, a six-step wizard that generates a signature-ready business associate agreement with PDF and DOCX export will get you a usable document in an afternoon — one-time purchase, no subscription — and gives you a consistent baseline across every vendor instead of fifteen different vendor-drafted contracts.

Days 21–25 — Review what you already have. Existing agreements signed in 2013 and never touched since are common. Check for: breach notification timelines stated in days, subcontractor flow-down language, return-or-destroy provisions at termination, and whether the signing entity still exists under that name after acquisition.

Days 26–30 — Decide about the holdouts. Some vendor will refuse. Escalate once, then make a business decision and write it down. Continuing to send PHI to a vendor that has refused a BAA is a documented, willful gap — the worst kind to have on paper.

Breach Timelines Your Agreement Must Actually Support

The Breach Notification Rule gives covered entities up to 60 calendar days from discovery to notify affected individuals. If your business associate takes 55 of those days to tell you, your notification is late and it is your name on the public breach portal.

Negotiate a shorter internal clock. Ten calendar days from discovery to initial notice, with a defined point of contact and a requirement to provide the affected-individual list in a usable format, is reasonable and most competent vendors will accept it. Also specify who pays for notification letters, call center capacity, and credit monitoring — that allocation is worth more than any other clause in the document.

What Your Auditor Will Ask to See

Three artifacts, and they are all boring:

  1. A current vendor inventory with classification reasoning.
  2. Executed agreements, countersigned, with dates, matched to that inventory.
  3. Evidence that the inventory is reviewed on a schedule — a dated annual review memo is sufficient.

Tie this to your risk analysis rather than keeping it in a separate silo. NIST's SP 800-66 Revision 2 maps Security Rule requirements to practical implementation steps and treats third-party relationships as an input to risk assessment, not an afterthought. HHS proposed substantial Security Rule updates in early 2025; regardless of final timing, the business associate obligations described here are already in force and have been since 2013.

If your risk analysis, policies, and vendor documentation live in three different places and none of them agree, automating the full compliance document set is a faster path than rebuilding the binder by hand each year.

Start With One Chart

Pick a recent compression fracture case from your schedule. Trace every system that touched it, from the scheduling widget to the collections file. Write the vendor names on a whiteboard. Then check each one against your contract folder.

Whatever gaps that single chart reveals, they exist across every chart in your practice. Close them starting with the agreement itself — generate a signature-ready BAA, send it to your three largest unsigned vendors this week, and put the countersigned copies where your next auditor will find them.