Count the organizations that touch a single erythrasma encounter at your practice. A patient presents with an intertriginous rash. Your medical assistant photographs it on a clinic tablet. The clinician orders a bench test, sends a specimen to a reference lab, and drafts a dermatology referral. Somewhere in there a prescription routes electronically, a claim goes to a clearinghouse, and a text reminder for the follow-up visit fires from a patient engagement tool.

That is seven external parties before lunch. This article is about the contracts, inventories, and handoff controls that govern those seven — not about the condition itself. If your vendor list has not been reconciled since your last risk analysis, this is the workflow to run.

Why an Erythrasma Visit Generates More Vendor Traffic Than You Expect

Erythrasma is a superficial bacterial skin infection that shows up in body folds and is frequently evaluated with a Wood's lamp, which produces a distinctive fluorescence. That single clinical fact has an administrative consequence: the encounter tends to produce an image. Images are the artifact that most often escapes your governed systems.

The second consequence is referral traffic. Skin findings in body folds are commonly routed to dermatology or, in ambiguous presentations, to infectious disease. Referrals mean records leave your walls under a different legal theory than vendor processing — treatment disclosure rather than business associate service — and most practices handle both through the same overworked front-desk process.

Nothing in this post is clinical guidance. The point is that a low-acuity dermatologic visit is a surprisingly good stress test for your third-party data map, precisely because nobody treats it as high risk.

The Seven Touchpoints: Build the Map Before You Build the Contracts

Sit with your practice manager and a whiteboard. Trace one representative encounter end to end. For a typical erythrasma workup, you will land on some version of this list:

  • The EHR or practice management host — business associate, almost certainly under contract already.
  • The clinical photography or image storage tool — often a phone app, a tablet gallery, or a dermatology-specific capture product. Frequently uncontracted.
  • The teledermatology or e-consult platform — business associate when it stores or transmits identifiable images on your behalf.
  • The reference laboratory — a covered entity in its own right receiving a treatment disclosure, not a business associate.
  • The e-prescribing network — usually covered by your EHR's downstream agreements; verify rather than assume.
  • The billing service or clearinghouse — business associate, and often the one with the deepest data retention.
  • The reminder, survey, or reputation-management vendor — business associate the moment it receives a name plus an appointment.

Assign the map to one owner. In practices under twenty providers, that is usually the privacy officer wearing a second hat. Give them read access to accounts payable — the fastest way to find shadow vendors is to look at what the practice pays for monthly.

The Vendors That Never Make the List

Three categories reliably escape the inventory. Transcription and scribe services, including AI-assisted documentation tools a clinician enabled on their own. Secure-messaging or file-transfer utilities used to move images to a referral partner. And IT contractors with persistent remote access to workstations, who qualify as business associates even if they never intentionally open a chart.

Does a Teledermatology Platform Need a Business Associate Agreement?

Yes, in nearly every configuration. If a vendor creates, receives, maintains, or transmits protected health information on your behalf — including a photograph of a rash tied to a patient identifier — that vendor is a business associate and requires a signed BAA before it touches the data. The narrow conduit exception covers entities that only transport data without persistent access, such as the postal service or a telecom carrier. A platform that stores images, indexes them, or lets a remote reviewer log in does not qualify.

The test is access and persistence, not intent. A cloud storage provider that holds encrypted images and does not have the key is still a business associate under HHS guidance, because it maintains the PHI. HHS publishes sample business associate agreement provisions that establish the floor — required uses and disclosures, safeguards, subcontractor flow-down, breach reporting, and return or destruction at termination.

Clinical Photos Are the Highest-Risk Artifact in the Chart

An erythrasma image is small, easy to share, and visually identifiable in ways a lab value never is. It also carries metadata. Device photos often embed timestamps and, depending on settings, geolocation. If your staff photograph on personal phones, the image may sync to a consumer cloud account outside any BAA within seconds of capture.

Four Controls That Close Most of the Gap

  1. Capture device policy. Clinic-owned devices only, with photo sync to consumer accounts disabled at the MDM level. Write it down; audit it quarterly by inspecting two devices at random.
  2. Direct-to-chart capture. If your EHR supports capture that writes straight to the encounter without storing locally, require it. If it does not, require deletion from the device gallery before the MA leaves the room, and log the deletion.
  3. Retention parity. Images are part of the designated record set. They are subject to the same access-request obligations as the note, and patients can request them. Make sure your release-of-information workflow actually finds them.
  4. Consent language for secondary use. Teaching files, marketing, and social media are separate questions from treatment. Authorization for those uses is not covered by the standard notice of privacy practices.

The Referral Handoff: Minimum Necessary Does Not Apply — Until It Does

When you send an erythrasma record to a dermatologist for treatment purposes, the minimum necessary standard does not restrict the disclosure. Treatment disclosures are exempt. That surprises a lot of front-desk staff who have been trained to send as little as possible.

The exemption evaporates when the recipient is a business associate performing a service rather than a clinician treating the patient. A prior-authorization vendor, a coding contractor, or a care-coordination platform all get the minimum necessary treatment. HHS keeps a clear explainer on the minimum necessary standard; put the two-paragraph version in your annual training deck rather than the regulatory text.

Practically: build two referral packet templates. One for clinician-to-clinician treatment, which includes the full relevant history and images. One for administrative recipients, which is scoped to the data element the vendor actually needs. Let the staff pick from a menu instead of judging on the fly.

What to Demand in the Contract Before You Sign

The HHS sample provisions are a floor, not a ceiling. For any vendor that will hold identifiable images or referral records, negotiate these six terms explicitly:

  • Breach notification timing. The regulation says "without unreasonable delay." Your contract should say a specific number of days — many practices land between five and fifteen — because your own 60-day clock to HHS runs from discovery, and a vendor sitting on news for 50 days destroys your timeline.
  • Subcontractor disclosure. Require a written list of downstream subcontractors that handle PHI, updated annually. Flow-down obligations are already required; visibility into who they are is not, so contract for it.
  • Data location. Ask directly whether processing or support occurs outside the United States. Offshore support is not prohibited, but it changes your risk analysis and your patients' expectations.
  • Return or destruction at termination. Specify format and deadline. "Infeasible to return" is a real carve-out in the regulation and vendors lean on it. Pin down what happens to image archives specifically.
  • Security documentation. Request evidence of a current risk analysis and encryption at rest and in transit. HHS proposed a substantial Security Rule overhaul in January 2025 that would push toward explicit written verification of business associate safeguards; whether or not the final rule has reached your desk, writing that expectation into contracts now costs nothing.
  • Cooperation in an investigation. Obligate the vendor to produce logs and participate in your breach risk assessment at their expense.

If the gap you find is simply that agreements were never executed — the common outcome of this exercise — you can generate a signature-ready Business Associate Agreement through a guided six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, which matters when you are papering eleven vendors in a week and do not want a recurring line item for each.

A 30-Day Vendor Reconciliation Sprint

Do not attempt a comprehensive program. Run a bounded sprint with named owners and dates.

Days 1–7: Discovery

Practice manager pulls twelve months of accounts payable and every SaaS charge on the practice credit card. Privacy officer interviews one clinician, one MA, and one front-desk lead about what tools they actually use. Expect three to six vendors nobody on the leadership team knew about.

Days 8–14: Classification

Sort each vendor into business associate, covered entity recipient, conduit, or no-PHI. Document the reasoning in one sentence per vendor. That sentence is your defense if a regulator later asks why the landscaping company has no BAA.

Days 15–24: Papering

Request executed BAAs from every vendor classified as a business associate. Where the vendor cannot produce one, issue yours. Where the vendor refuses reasonable terms, escalate to a replace-or-accept-risk decision with the managing partner — in writing.

Days 25–30: Closure

Store executed agreements in one location with expiration and review dates. Update your risk analysis to reflect the new vendor list. If your risk analysis is stale, the broader automated risk analysis and policy document set will get you to a defensible baseline faster than rebuilding a spreadsheet.

When the Vendor Is the Breach

A vendor-side incident is still your reporting obligation for your patients. The business associate notifies you; you notify individuals, and HHS, and — above 500 residents of a state or jurisdiction — the media. The HHS breach notification rule permits you to delegate notification to the business associate by contract, but delegation does not transfer liability. If they botch it, you answer for it.

Before you sign any imaging or teledermatology vendor, spend fifteen minutes on the OCR breach portal searching the vendor name and its parent company. It is free, it is public, and it is the single highest-yield due diligence step available to a small practice.

The Practical Takeaway

An erythrasma visit is not a high-stakes encounter clinically, and that is exactly why it exposes weak vendor governance. Low-acuity workflows get built casually. Images get captured on whatever is nearest. Referrals get faxed by whoever is at the desk. The contracts lag the practice by eighteen months.

Run the seven-touchpoint map on one real chart this week. Whatever gaps surface for erythrasma will be identical for every other dermatologic, wound-care, and podiatric encounter in your schedule. Then close the contract gaps — build and export the Business Associate Agreements you are missing — and put a calendar reminder to re-run the inventory in twelve months.