Diastolic Dysfunction Data Flows: Mapping Your BAAs
Count the outside organizations that touch one echocardiogram report. A patient presents with exertional shortness of breath, your physician orders an echo, and the imaging center's report comes back describing diastolic dysfunction. Between that order and the cardiology follow-up, the record passes through an imaging center, a PACS or image-exchange service, a transcription or ambient documentation tool, your EHR host, a secure messaging gateway, a patient portal, a clearinghouse for prior authorization, a release-of-information vendor, an IT managed service provider, an offsite backup provider, and a billing company. That is eleven organizations. This article is about which of them require a signed Business Associate Agreement, how to prove you have one, and what to do about the ones you missed.
Nothing here is clinical guidance. The condition is the context — it involves specialist referral and imaging, so protected health information leaves your building repeatedly — and the workflow around it is the subject.
One Echo Report, Eleven Organizations
Most practices maintain a vendor list built by accounting, not by privacy. It captures who gets paid. It does not capture who touches PHI, which is a different set with substantial but incomplete overlap.
Your janitorial service gets paid and probably needs no BAA. Your ambient documentation pilot may be free during the trial period, invisible to accounting, and squarely a business associate. The gap between the accounts-payable list and the PHI-flow list is where enforcement risk lives.
A cardiology-adjacent pathway makes the gap obvious because the record moves so much. Referral out, images back, report in, results to the patient, prior authorization to the payer, records to a second opinion, claim to the clearinghouse. Each hop is a disclosure, and each disclosure has a legal characterization you should be able to name in one sentence.
Which Vendors in a Diastolic Dysfunction Pathway Need a Signed BAA?
Short answer: any organization that creates, receives, maintains, or transmits PHI on your behalf to perform a function or service for you needs a signed BAA before it touches the data. Treatment disclosures to another covered entity — your referral to the cardiology group, your order to the imaging center — do not require a BAA. Payment disclosures to a health plan do not either.
Almost always business associates
- EHR vendor and its hosting environment
- Transcription services and ambient documentation tools
- Image-exchange or PACS-hosting platforms you contract with directly
- Patient portal, secure messaging, and appointment-reminder vendors
- Billing companies, coding contractors, and revenue cycle firms
- Clearinghouses processing your claims and eligibility checks
- Release-of-information vendors handling records requests
- Managed IT providers, offsite backup, and cloud storage
- Document shredding vendors that take custody of paper
- Answering services and outsourced call centers
- Cardiac remote monitoring platforms you contract with
Usually not business associates
- The cardiology practice you refer to — covered entity to covered entity, for treatment
- The imaging center performing the echo under your order — same reasoning
- The health plan receiving your claim
- The postal service and most common carriers — the conduit exception, which is narrow and applies to transmission only, not storage
- A patient's chosen personal health app receiving data at the patient's direction under their right of access
HHS publishes the governing definition and the required contract elements; the sample business associate agreement provisions are the baseline text every agreement in your file should meet or exceed.
Draw the Map Before You Chase Signatures
Collecting signatures without a map produces a folder of paper and no assurance. Build the flow first. One row per data movement, not one row per vendor — a single vendor may appear three times.
Columns that earn their keep: what data element moves, from which system, to which organization, by what transport, on what schedule, who at your practice authorized it, what agreement covers it, and the date of last review. Five columns is not enough; twelve is unmaintainable. Eight is about right.
Run the exercise against a real pathway rather than in the abstract. Pull one anonymized encounter where diastolic dysfunction appeared in the assessment, and trace every place that record went in the following ninety days. Your front desk will name vendors your vendor list does not have.
Who does the tracing
Assign it to two people who see different halves of the workflow: your privacy officer and whoever runs the front desk or referral coordination. The privacy officer knows the contracts. The coordinator knows that the imaging center's portal times out, so staff have been faxing to a number nobody has validated in two years.
The Imaging Handoff Is Where Maps Break
Echo images and reports are large, and large files find informal paths. The three failure patterns are consistent across practices.
First, an image-sharing platform sits between you and the imaging center, and neither party is certain who contracted it. Determine who signed. If your practice pays for it or configured it, you need a BAA. If the imaging center owns the relationship and you are simply a recipient of a treatment disclosure, document that conclusion in writing so the next auditor does not relitigate it.
Second, CDs and drives still move by courier in some markets. A courier that takes custody of unencrypted media is not a conduit in any comfortable reading — it holds the data. Get a BAA or stop using it.
Third, staff email reports to specialists using whatever works. Check your outbound mail logs for attachments over a few megabytes going to domains outside your BAA inventory. It is a fifteen-minute query and it usually finds something.
Ambient Scribes and Transcription: The Fastest-Growing Gap
Documentation tools that listen to the encounter and draft the note are now common in cardiology-adjacent practices, and they are business associates without qualification. They receive PHI, they process it on your behalf, and many of them retain audio.
Three questions to ask before the pilot, not after: Is audio retained, and for how long? Is our data used to train models, and is that use limited to what the BAA permits? Where is processing performed, and are subcontractors named?
The training question deserves a specific contract clause. A BAA that merely permits "data aggregation services" is not a clear authorization for model training. Write the permitted use plainly or prohibit it plainly. Ambiguity in a BAA resolves against the party that drafted it, and you are usually not that party.
If you find yourself needing an agreement in place before Monday's go-live, a six-step wizard that produces a signature-ready Business Associate Agreement with PDF and DOCX export will get a defensible document in front of the vendor same-day, as a one-time purchase rather than another subscription line item.
Portals, Remote Monitoring, and the Rule That Applies When HIPAA Doesn't
Patients in a cardiac pathway often end up using consumer apps — weight trackers, blood pressure cuffs, symptom diaries. When the patient directs their data to an app of their choosing, that app is generally not your business associate, and you should not sign a BAA that implies otherwise.
The distinction matters in the other direction too. Apps and vendors outside HIPAA's reach may still fall under the FTC's Health Breach Notification Rule, which the Commission amended in 2024 to clarify its application to health apps and connected devices. If your practice recommends or resells a monitoring product, know which regime governs it and say so in your patient-facing materials.
Website tracking is the adjacent trap. If your appointment-request page or a condition-specific landing page loads third-party analytics or advertising pixels, those scripts may transmit identifiers alongside health-related browsing. Inventory the tags on any page describing cardiac services. Remove what you cannot justify, and paper what remains.
Subcontractor Chains: The BAA You Never See
Your billing company uses a document-imaging subcontractor. That subcontractor uses a cloud host. Each link requires its own agreement, flowing down obligations at least as protective as yours.
You will not sign those downstream agreements, and you should not try. What you should do is require, in your BAA, that the business associate maintain a current list of subcontractors with PHI access and provide it on request. Then request it annually. A vendor that cannot produce the list in ten business days has told you something useful about its own program.
The public HHS breach portal is worth twenty minutes of your time each quarter. Search your vendors by name. Business associate incidents routinely affect dozens of downstream practices, and you would rather learn about one there than from a patient.
What Your BAA Must Actually Say
The required elements sit at 45 CFR 164.504(e). Read your three most important agreements against this list this week:
- Permitted and required uses and disclosures of PHI, stated specifically
- A prohibition on uses beyond what the contract or law allows
- Appropriate safeguards, including Security Rule compliance for ePHI
- Reporting of any use or disclosure not permitted, including breaches
- Flow-down of obligations to subcontractors
- Support for individual access, amendment, and accounting of disclosures
- Availability of books and records to HHS
- Return or destruction of PHI at termination, or an explanation of why that is infeasible
- Termination rights on material breach
Two clauses worth negotiating beyond the minimum: a breach notification window measured in days rather than "without unreasonable delay," and a defined security contact with a monitored address. Ten calendar days is a reasonable ask and gives you room inside your own sixty-day obligation.
A 90-Day Cleanup Schedule With Names Attached
Days 1–15: Inventory
Privacy officer and referral coordinator trace one full pathway end to end. Output: a spreadsheet of every organization touching PHI, with a business-associate yes/no determination and a one-line rationale for each.
Days 16–45: Reconcile
Office manager pulls the signed BAA file and matches it row by row. Flag three categories: missing entirely, present but pre-dating the Omnibus Rule, and present but unsigned by one party. All three are findings.
Days 46–75: Remediate
Send agreements to the missing vendors with a fourteen-day response expectation. For vendors that refuse or stall, escalate to a named practice leader with authority to suspend the relationship. A vendor that will not sign is a decision, not a problem to be admired.
Days 76–90: Document and schedule
File determinations, set annual review dates, and fold the vendor inventory into your risk analysis. NIST's SP 800-66 Revision 2 maps Security Rule requirements to practical activities and is a defensible framework to cite when someone asks how you decided what to assess. If you are rebuilding the underlying risk analysis and policy set at the same time, automated generation of the full compliance document set keeps the vendor inventory and the risk documentation pointing at the same facts.
Five Failure Modes Auditors Find First
- The unsigned countersignature. You signed; the vendor never returned it. Check the second signature block on every agreement in the file.
- The BAA for an entity that no longer exists. Vendors merge. The surviving entity's name must appear on a current agreement.
- The free tool nobody expensed. Trial software, browser extensions, and departmental sign-ups bypass procurement entirely.
- The BAA that assumes you are the business associate. Template confusion is common; read the definitions section, not just the signature page.
- No termination provision exercised. Ended a vendor relationship last year? Confirm in writing that PHI was returned or destroyed, and keep the confirmation.
A pathway like this one moves records constantly, across organizations, under time pressure, with clinical urgency that makes staff improvise. Your job is not to slow that down. It is to make sure every path the record takes is one you chose, documented, and covered by an agreement you can produce in an afternoon.
Start with the pathway you handle most often. Trace it, list the vendors, and if any of them is operating without a current agreement, generate a signature-ready BAA and send it before the end of the week. One-time purchase, exported as PDF or DOCX, ready for the vendor's signature block.