Count the organizations that touch one lab order. A primary care office orders an electrophoresis of serum panel for a patient with an unexplained protein abnormality. Before the result is filed, PHI has moved through an order-entry interface, a courier, a reference lab, a results-delivery channel, a referral packet to a specialist, a coding vendor, and a clearinghouse. That is eight external touchpoints for one test. Some of those organizations are your business associates. Some are not. If you cannot say which is which from memory, this article is your afternoon.

This is an administrative post for the person who signs vendor contracts and answers the phone when a result goes to the wrong fax number. Nothing here is clinical guidance.

The Eight-Hop Path of a Single Electrophoresis of Serum Order

Serum protein electrophoresis is a test that frequently precedes a specialist referral, which means the record does not stay in one building. That single clinical fact drives every administrative obligation below.

Trace the actual path in your own practice. A typical one looks like this:

  1. Order entry. The clinician places the order in your EHR. If your lab orders route through a third-party interface engine or integration platform, PHI has already left your control.
  2. Specimen collection and labeling. Draw happens in-house or at a patient service center. Requisition carries name, DOB, MRN, ordering provider, diagnosis code.
  3. Courier transport. A logistics company moves the specimen and paper requisition.
  4. Reference lab processing. The lab runs the assay and generates a report.
  5. Result delivery. Back through the interface, or by cloud fax, secure portal, or — in too many practices — a standalone fax machine at the nurses' station.
  6. Referral packet. Front desk or a referral coordinator sends the result plus chart notes to hematology or another specialty, sometimes via a referral management platform.
  7. Coding and billing. The encounter and lab charges go to an outsourced biller or coding vendor.
  8. Clearinghouse and payer. Claim transmits; payer may request records.

Now add the invisible hops: your cloud backup, your document storage vendor, your e-signature tool, your transcription service, your IT managed service provider with domain admin rights. Every one of them can reach the electrophoresis of serum report sitting in the chart.

Do You Need a BAA With the Lab That Runs an Electrophoresis of Serum?

Generally, no. A clinical laboratory that receives your order and performs the test is a covered entity in its own right, and the exchange between you is a disclosure for treatment purposes. HHS has been consistent that a covered health care provider furnishing treatment is not acting as your business associate when it does so. You do not need a business associate agreement to send a specimen to a lab or to receive the result back.

You almost certainly do need a BAA with the intermediaries: the interface or integration vendor that routes orders and results, the cloud fax service, the referral platform, the outsourced biller, the release-of-information company, the document storage host, and your IT provider. These entities create, receive, maintain, or transmit PHI on your behalf — which is the statutory trigger, not whether they are technically sophisticated or whether they promise never to look.

Two edge cases worth writing into your policy:

  • The conduit exception is narrow. It covers entities that merely transport PHI with only random or incidental access — the postal service, a private courier acting purely as transport. It does not cover anyone who stores your data. A vendor that holds results in a cloud environment is a business associate even if the data is encrypted and the vendor lacks the key.
  • Payers are not business associates. Sending a claim or supporting documentation to a health plan is a payment disclosure. Your clearinghouse, however, is acting on your behalf and needs an agreement.

Where Practices Actually Get Caught

The interface vendor nobody remembers signing

Lab interfaces are often installed once, years ago, by whoever set up the EHR. The BAA — if there is one — may be with an entity that has since been acquired, renamed, or subcontracted. Pull the agreement. Check the legal name against the entity currently sending you invoices. If they do not match, you have an unpapered relationship carrying live PHI every business day.

Fax that is not really fax

Most "fax numbers" now terminate in a cloud service that stores an image of every inbound and outbound page. That is a business associate holding a searchable archive of lab reports. Ask the vendor three questions: where the images are stored, how long they are retained by default, and whether retention can be shortened. Then get the answers in writing.

The referral coordinator's workaround

When the specialist's portal is down, staff improvise. Personal email, a phone photo of a printed report, a shared drive link with no expiration. Every one of those is a disclosure through an unvetted channel. Audit your referral workflow by asking the coordinator to walk you through the last five referrals, step by step, and write down every tool they name. You will find at least one you did not know about.

Subcontractors you never met

Your biller uses an offshore coding partner. Your ROI vendor uses a print-and-mail house. Your storage host uses a third-party support desk. Under the Privacy and Security Rules, subcontractors that handle PHI must themselves be bound by agreements, and your BAA should require that flow-down explicitly. Ask each vendor for a current list of subcontractors with PHI access. A vendor that cannot produce one within a week is telling you something.

Contract Terms That Change Outcomes

The HHS sample business associate agreement provisions are the floor, not the ceiling. Four terms are worth negotiating for lab-adjacent vendors specifically:

  • Breach notification timing. The regulation gives a business associate up to 60 days to notify you. That consumes your entire clock. Contract for notification within 5 business days of discovery, with a preliminary notice within 24 hours of any suspected incident.
  • Subcontractor disclosure. Require a written list, updated annually, and advance notice before a new subcontractor gains PHI access.
  • Return or destruction at termination. Specify format and deadline. "Commercially reasonable efforts" language means your lab results live on the vendor's servers indefinitely.
  • Cooperation with access and amendment requests. If the vendor holds part of your designated record set, the BAA must obligate them to produce it fast enough for you to meet your 30-day deadline.

If you are staring at a vendor list with three signed agreements and eleven blanks, the fastest path is to generate clean, consistent paper for all of them. A signature-ready business associate agreement built through a guided six-step wizard gives you PDF and DOCX output you can send the same afternoon, which is usually better than waiting six weeks for a vendor's own template that favors the vendor.

What a Records Request Does to This Map

A patient asks for "everything related to my blood work." Your clock is 30 days from receipt, with one 30-day extension available if you notify the patient in writing of the reason and the new date. See the OCR right of access guidance for the fee and format rules.

Practical questions the map answers:

  • Is the electrophoresis of serum report in your EHR, or only in the lab's portal? If your staff view it through a portal window rather than a filed result, it may not be in your designated record set — but if you used it to make care decisions and stored it anywhere, treat it as included.
  • Does your ROI vendor pull from the EHR only, or also from scanned paper and the fax archive? Requests fulfilled from one source while records sit in another produce incomplete disclosures, which is a recurring source of access complaints.
  • Can you meet a request for electronic format? Patients may request a specific electronic form and format if you can readily produce it.

Note for your front desk script: under the CLIA amendments finalized in 2014, patients may also request lab results directly from the laboratory. When a patient calls confused about which door to knock on, staff should be able to explain both paths without arguing about it.

When a Result Goes to the Wrong Place

Misdirected lab results are one of the most common small incidents in ambulatory practice. The workflow is the same whether the report is a metabolic panel or an electrophoresis of serum.

  1. Contain. Confirm the recipient, request deletion or return, document the request and the response.
  2. Assess. Run the four-factor risk assessment: nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. Document all four in writing, not in a hallway conversation.
  3. Notify. If it is a reportable breach, notify affected individuals without unreasonable delay and no later than 60 days from discovery. Breaches affecting fewer than 500 individuals go into your annual log, submitted to HHS within 60 days after the end of the calendar year. The Breach Notification Rule guidance covers the mechanics.
  4. Close the hole. Change the workflow that allowed it. A one-off retraining does not survive audit scrutiny.

If the misdirection happened at a vendor, your BAA determines how fast you learn about it — which is exactly why the notification clause above matters more than the indemnification language your attorney will want to spend an hour on.

A Quarterly Vendor Review You Can Actually Finish

Block ninety minutes per quarter. Assign it to a named person, not "compliance."

Month one of the quarter: inventory

Pull the accounts payable list. Every recurring payment is a candidate vendor. Mark each as PHI access: yes, no, or unknown. Resolve the unknowns by asking the vendor directly in writing.

Month two: paper

For every yes, confirm a signed BAA exists, the signing entity name is current, and the effective date precedes the first PHI transmission. File the executed copies in one location with a renewal date.

Month three: evidence

Request one artifact per high-risk vendor — a SOC 2 report, a summary of their most recent security assessment, or their subcontractor list. Log what you received and what you did not. That log is your documentation that you performed diligence, which is what an investigator asks for after an incident.

The NIST SP 800-66r2 implementation guide maps Security Rule requirements to concrete safeguards and is useful when you need to justify a specific control to a skeptical practice owner.

Start With the Fifteen Vendors That Touch Lab Data

You do not have to boil the ocean. Take the eight-hop path above, write down the actual company name at each hop plus the invisible infrastructure vendors, and you have a working exposure map in under an hour. Then check which of those names has a current, correctly-titled agreement on file.

For the gaps, generate a business associate agreement you can send for signature today — one-time purchase, PDF and DOCX, no subscription to manage. If the review also surfaces missing policies or an out-of-date risk analysis, automated risk analysis and policy generation covers the rest of the document set. Either way, the map comes first: you cannot paper a relationship you have not written down.