A patient falls in your parking lot at 4:40 on a Friday, catches herself on an outstretched hand, and walks into your urgent care with a swollen wrist. Six weeks later the claim is paid and the encounter is closed. In between, protected health information from that single distal radius fracture visit has moved through nine to fourteen organizations your practice does not own.

This post maps those flows and sorts them into three buckets: vendors that require a signed business associate agreement, entities that do not, and the gray cases that eat an hour of your week. It is written for the person who maintains the vendor register — not for the person treating the wrist. There is no clinical guidance here.

Why a Wrist Fracture Is a Good Stress Test for Your Vendor Register

Administratively, a distal radius fracture is useful precisely because it is ordinary. It typically involves imaging, often a referral to an orthopedic practice, frequently a splint or brace supplied by someone, follow-up imaging, and sometimes physical therapy. None of that is exotic. All of it crosses organizational boundaries.

That boundary-crossing is the point. A diabetes management visit may live almost entirely inside your EHR. A fracture pathway pushes images, orders, referral packets, device claims, and therapy notes outward within days. If your BAA register has a hole in it, this pathway will find the hole.

Most practices discover the gap the same way: someone requests an accounting of disclosures, or a vendor announces a security incident, and the privacy officer opens the shared drive to find twenty-two signed agreements and no reliable list of who actually holds PHI.

The Trail: Where PHI Actually Leaves the Building

Walk the encounter chronologically and write down every system that receives, stores, or transmits identifiable information. For a typical distal radius fracture visit, that trail looks something like this.

Before and during the visit

  • Online scheduling or digital intake tool — collects name, DOB, chief complaint, insurance card image.
  • EHR vendor and its hosting provider — the obvious one, and the one most likely to already be papered.
  • Eligibility and benefits verification service — queries payers with member identifiers.
  • Imaging modality service contract — remote diagnostics and support access on the radiography unit.
  • PACS or cloud image archive — stores the wrist series with patient identifiers embedded in DICOM headers.
  • Teleradiology or overread service — this one is a gray case; see below.
  • Transcription or ambient documentation vendor — captures the encounter note.

After the visit

  • Referral and care coordination platform — packages the chart for the orthopedic practice.
  • Secure messaging, fax-to-email, or direct messaging service — moves the packet.
  • DME supplier or splint/brace distributor — receives an order with patient and insurance data.
  • Clearinghouse and billing service — submits the claim with diagnosis and procedure codes.
  • Patient statement and payment processor — prints and mails the balance.
  • Collections agency — if the balance ages.
  • Appointment reminder and recall texting vendor — schedules the two-week follow-up film.
  • Patient satisfaction survey vendor — pulls the visit roster.
  • Release-of-information vendor — handles the disability paperwork request that arrives three weeks later.
  • Managed IT provider, backup vendor, and document shredding company — quiet, constant, and almost always business associates.

That is fifteen to twenty line items for one fracture. Count yours. If your signed-BAA folder holds fewer agreements than your accounts-payable ledger holds software vendors, you have found your project for the quarter.

Does This Vendor Need a BAA? Four Questions

Run each name through this sequence. It resolves the large majority of cases in under a minute.

  1. Does the vendor create, receive, maintain, or transmit PHI on your behalf? If no, stop — no BAA. If yes, continue.
  2. Is the vendor performing a function or service for your practice, rather than treating the patient in its own right? Services (billing, storage, analytics, transcription, IT) require a BAA. Treatment by another provider does not.
  3. Is access incidental and unavoidable, or is the vendor merely a conduit? A courier or the phone company is a conduit. A cloud vendor that stores your data is not, even if it never looks at it.
  4. Will the vendor use subcontractors that touch the same data? If yes, your BAA must require the vendor to bind those subcontractors to equivalent terms.

HHS's guidance on who qualifies as a business associate is short and worth keeping open while you work the list. The cloud computing guidance settles the argument you will inevitably have with a hosting vendor that claims encryption exempts it — it does not.

The Entities in a Distal Radius Fracture Pathway That Do Not Need a BAA

This is where practices over-paper and waste negotiation time. Disclosures for treatment, payment, and health care operations between covered entities do not require a business associate agreement.

The orthopedic practice you refer to. They are a covered entity providing treatment. You send the chart under the treatment permission. No BAA.

The independent radiologist who interprets the film as a treating provider. Interpretation is a professional service delivered to the patient. Contrast that with a teleradiology company that also stores, routes, and archives your images as a service to your practice — that storage and routing function does require a BAA. Read the actual scope of work, not the vendor's marketing.

The health plan. Claims submission is a payment disclosure. Your clearinghouse, however, is a business associate standing between you and the plan.

The DME supplier that bills the patient's insurance directly. If the supplier is itself a covered entity furnishing an item to the patient and billing for it, the order transmission is a treatment or payment disclosure. If instead the supplier is warehousing your inventory data or handling your billing, you are back in BAA territory. Same company, different relationship — document which one you have.

The physical therapy clinic. Covered entity, treatment relationship, no BAA.

Building the Register: Who Does What, and When

A vendor map is only useful if someone owns it. Assign these roles by name, not by department.

Assignments

  • Privacy officer — owns the master register, makes the business-associate determination, signs off before any new tool touches PHI.
  • Practice manager — reconciles the register against the vendor payment list each quarter. Every recurring charge gets matched to a row or flagged.
  • Billing lead — owns clearinghouse, statement vendor, and collections agreements, including the annual review of their breach notification terms.
  • IT contact or MSP liaison — maintains the list of systems with administrative access to the EHR, PACS, and file shares.

Cadence

Quarterly: reconcile spend to register. Annually: confirm each agreement is current, the signing entity still exists under that name, and the contact for breach notification is a live human. On termination: send the written demand for return or destruction of PHI, and file the vendor's written confirmation. That confirmation is the document you will wish you had two years later.

What the agreement itself has to say

At minimum, your BAA must address permitted uses and disclosures, safeguards, reporting of security incidents and breaches, subcontractor flow-down, patient access and amendment support, disclosure accounting support, availability of records to HHS, and return or destruction at termination. HHS publishes sample business associate agreement provisions that track those requirements.

Beyond the minimum, negotiate three practical terms: a breach notification window short enough for you to meet your own 60-day obligation (ten business days is a reasonable ask), a named notification contact rather than a generic legal inbox, and a requirement that the vendor disclose the geographic location of PHI storage.

If you are drafting from scratch rather than redlining a vendor's paper, a guided BAA generator that produces a signature-ready agreement will get you to a compliant document faster than editing a template you found in a shared drive. It walks six steps and exports PDF and DOCX, one-time purchase. Use it for the smaller vendors who hand you nothing — the shredding company, the local IT shop, the answering service.

Subcontractors: The Layer Most Registers Miss

Your transcription vendor uses an offshore quality-review contractor. Your reminder-texting vendor uses a third-party SMS gateway. Your billing service uses a cloud analytics platform. Each of those is a subcontractor business associate, and each must be bound by an agreement no less protective than yours.

You do not sign those downstream agreements. You do have to require them, and you should ask for attestation that they exist. Add one line to your annual vendor questionnaire: List every subcontractor that creates, receives, maintains, or transmits our PHI, and confirm each is under a written business associate agreement. Vendors that cannot answer that question in writing are telling you something.

Browse the OCR breach portal and filter for business associate involvement. The pattern is consistent: a single vendor incident cascades across dozens of provider organizations at once, and every one of them owes its own patients notification.

When the Map Breaks: Shadow Tools at the Front Desk

The most common failure is not a bad contract. It is a good-faith staff member solving a real problem with a credit card.

Someone signs up for a scanning app to get splint fitting photos into the chart. Someone starts a group text thread to coordinate same-day imaging slots. Someone uploads a spreadsheet of overdue follow-up patients to a free scheduling tool. None of these show up in accounts payable, and none of them have a BAA.

Two controls work. First, make the register visible — a one-page list of approved tools posted where staff can check it, with a named person to ask. Second, put a five-minute item in every all-staff meeting: What did you use this month that isn't on the list? Ask it without consequence and people will tell you.

Documentation That Holds Up Under Inquiry

If OCR opens an inquiry after a vendor incident, you will be asked for the executed agreement, the date it was signed, evidence you evaluated the vendor's safeguards, and your incident response record. Keep those four artifacts together per vendor.

Tie the register to your risk analysis rather than maintaining it as a standalone spreadsheet. NIST's SP 800-66 Revision 2 gives a workable structure for documenting where ePHI lives, including data held by third parties. HHS has also proposed significant updates to the Security Rule that would tighten written assurances and verification expectations for business associates; confirm the current status before you plan around it.

Practices that automate the surrounding paperwork — risk analysis, policies, the full document set — spend less time reconstructing history under pressure. If your compliance file is a folder of PDFs from three different years, that is where to start.

Do This Week

Pick one recent distal radius fracture encounter. Trace it end to end and write down every organization that touched the record. Compare that list to your signed agreements. Whatever is missing is your work order.

For the vendors that turn up unpapered, generate a signature-ready business associate agreement and get it out this week — before the next incident makes the gap someone else's discovery. For the broader compliance document set behind it, automated risk analysis and policy generation will keep the register connected to the rest of your program.