A patient shows up Monday afternoon with a complaint your MA charts under a benign anorectal code. By Friday, count the outside organizations that have touched some fragment of that encounter: your cloud EHR host, your e-fax service, your transcription vendor, your clearinghouse, the colorectal specialist's office, the specialist's scheduling platform, your patient-reminder texting tool, your after-hours answering service, your managed IT provider, your document shredding company, and the analytics script running on the patient-education page about how to treat hemorrhoids that the patient read before booking. That's eleven. This post is not about how to treat hemorrhoids — that belongs to your clinicians. It's about which of those eleven you have a signed, current business associate agreement with, and what happens when you don't.

Eleven Organizations, One Proctology Encounter

Conditions like this are ordinary, high-volume, and frequently referred out. That combination is exactly what makes them useful for testing your vendor map. Nobody builds a special data-handling process for a routine anorectal complaint, so whatever your default plumbing does, it does here.

Pull one real encounter from six months ago and trace it. Not from memory — from logs. Ask your billing lead where the claim went and through how many hops. Ask your IT provider which systems held a copy of the chart note. Ask the front desk what they faxed to the specialist and what channel they used to confirm receipt.

Most practices that do this exercise find two or three data flows nobody on the compliance side knew existed. A scheduling coordinator who forwards referral packets from a personal-adjacent inbox. A transcription tool a physician started using on their own. A patient-survey platform the marketing consultant signed up for. Each one is a business associate relationship whether or not paperwork exists.

Do You Need a BAA With the Specialist You Refer To?

No. A disclosure from one covered entity to another covered entity for treatment purposes does not require a business associate agreement. When your physician sends records to a colorectal surgeon or gastroenterologist so that clinician can evaluate and treat the patient, that's a permitted treatment disclosure under the Privacy Rule. No BAA, no authorization.

You need a BAA when an outside party creates, receives, maintains, or transmits protected health information on your behalf — performing a function or service for your practice rather than treating the patient in their own right.

Needs a BAA

  • Cloud EHR and practice management hosts
  • Billing companies, revenue cycle vendors, and clearinghouses
  • Transcription and ambient documentation services
  • Managed IT providers and MSPs with access to systems holding PHI
  • E-fax platforms that store or process fax content
  • Patient texting, reminder, and secure-messaging tools
  • Answering services and after-hours triage vendors
  • Document shredding and media destruction companies
  • Patient survey, reputation, and outreach platforms
  • Offsite backup and disaster recovery providers

Does not need a BAA

  • Specialists and hospitals receiving records for treatment
  • Health plans receiving claims for payment
  • Financial institutions processing payment transactions
  • True conduits — the phone company, the postal service, an ISP moving packets without storing content
  • Janitorial and building services with incidental exposure only

The conduit exception is narrower than vendors claim. HHS has been explicit that it covers transmission-only services, not entities that maintain PHI. A cloud provider that stores encrypted data it can't read is still a business associate. Read the agency's business associate guidance before you accept a vendor's assurance that they're "just a pipe."

If that list turned up gaps — and it usually turns up three to five — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription. That's faster than waiting on a vendor's legal team to send you a template written entirely in their favor.

Five Clauses That Decide Whether a Vendor Breach Becomes Your Breach

A signed BAA in a folder is not risk management. The terms matter, and the vendor's standard template is drafted to limit the vendor's exposure, not yours.

1. Notification timing measured in business days, not the regulatory maximum

The Breach Notification Rule permits a business associate up to 60 calendar days from discovery to notify you. If your vendor uses all 60, you have almost no runway left for your own 60-day obligation to patients. Negotiate five to ten business days for suspected incidents, with a preliminary notice requirement even before the vendor's investigation concludes.

2. Subcontractor flow-down with a disclosure duty

Your BAA should require the vendor to obtain agreements from its own subcontractors — and to tell you who they are on request. The transcription company using an overseas subcontractor is a common surprise. So is the texting platform routing through a third-party carrier gateway.

3. Return or destruction at termination, with a certificate

When you switch billing companies, what happens to eight years of claim data? Specify return or destruction within a fixed window, require written certification, and calendar the follow-up. Practices lose track of terminated vendors still holding full patient histories more often than they lose track of active ones.

4. No secondary use, including de-identified aggregation

Several categories of vendor make money on aggregated data. If you don't want your patient population feeding a product roadmap, prohibit uses beyond the contracted service explicitly.

5. Cooperation and cost allocation for investigations

If OCR opens an inquiry, you need documents from the vendor fast. Put cooperation obligations, audit rights, and who pays for notification and credit monitoring in writing. Otherwise you are negotiating those terms during a crisis.

HHS proposed a significant Security Rule overhaul in early 2025 that would, among other changes, require business associates to verify their technical safeguards through written analysis on a recurring basis. Track its status rather than assuming today's minimum stays the minimum. The NIST SP 800-66r2 guidance on implementing the HIPAA Security Rule is a useful reference for what "reasonable and appropriate" looks like in practice.

Why "How to Treat Hemorrhoids" Page Views Became a Vendor Problem

Your marketing consultant publishes a patient-education page titled something close to how to treat hemorrhoids. It performs well. It also carries an analytics tag, an ad-retargeting pixel, and a chat widget — three third parties receiving IP addresses, device identifiers, and the URL of a page about a specific, sensitive condition.

OCR issued guidance on online tracking technologies in December 2022 and revised it in March 2024. A federal court vacated a portion of that guidance in 2024 as applied to unauthenticated public pages, so the legal picture is genuinely unsettled. What has not changed: the FTC continues to treat undisclosed health-data sharing as an unfair or deceptive practice, and pages behind a patient portal login remain squarely within HIPAA. The FTC's health privacy guidance for businesses is worth reading alongside anything OCR publishes.

Practical position for a practice administrator: treat any page tied to a specific condition as sensitive. Inventory the scripts on it. Require a BAA from any vendor whose script fires on authenticated pages, and remove third-party ad tech from condition-specific pages entirely unless you have a documented decision from counsel. This is one place where the safe answer is also the cheap one.

Minimum Necessary in the Referral Packet Your Front Desk Sends

When a coordinator preps a referral, the fast move is to export the whole chart. It's one click. It also sends behavioral health notes, substance use history, and unrelated diagnoses to an office that asked for a colorectal consult.

Treatment disclosures get latitude under the minimum necessary standard, but latitude is not permission to be sloppy. Build a referral template that defines the default packet: relevant chart notes, problem list, current medications, applicable results, demographics, insurance. Anything beyond that requires the referring clinician to say so.

Then audit it. Pull ten referral packets a quarter and check what actually went out. Assign this to your privacy officer with a named backup, and log the review — an audit you can't produce evidence of didn't happen. HHS maintains a plain summary of the minimum necessary requirement you can hand to staff during training.

When the Vendor Leaks, the Notification Letter Has Your Logo On It

Here's the asymmetry operators underestimate. Your billing vendor misconfigures a storage bucket. Their engineers made the mistake. Your practice sends the letters.

The clock: you have without unreasonable delay and no later than 60 calendar days from discovery to notify affected individuals. Breaches affecting 500 or more residents of a state or jurisdiction also require media notice and notice to HHS within that same 60 days, and they land on the public OCR breach portal where any patient, referral partner, or local reporter can find them. Smaller breaches get logged and submitted within 60 days after the end of the calendar year.

Discovery is the trigger, and your vendor's discovery date can start your clock depending on the relationship structure. That's why notification timing in the BAA is not a boilerplate paragraph. Review the mechanics in the HHS breach notification rule summary and confirm your incident response plan names the person who drafts letters, the person who approves them, and the mailing vendor who sends them.

A 30-Day Vendor Inventory Sprint

Do this once and maintenance becomes a quarterly hour instead of a fire drill.

Days 1–7. Pull the accounts payable list for the last 24 months. Every recurring payee gets one question: does this organization create, receive, maintain, or transmit PHI on our behalf? Add anything IT, billing, or the front desk names that isn't on the AP list — free tiers and trials rarely appear in accounting.

Days 8–14. Build the register. Columns: vendor, service, PHI categories touched, systems accessed, BAA on file yes/no, execution date, notification window, subcontractors disclosed, internal owner, renewal date.

Days 15–21. Triage the gaps. Rank by volume of PHI and depth of system access. The MSP with domain admin outranks the survey tool. Send agreements to the top tier first.

Days 22–30. Close what closes. Document what doesn't, including the vendor's response and your risk decision — a written decision by a named person is defensible; silence is not. Assign each remaining vendor an owner and a review date, and fold the register into your risk analysis so the two documents stop contradicting each other.

Start With the Gaps You Already Know About

You almost certainly have two or three vendors in mind right now with no agreement on file. Start there. You can build a signature-ready BAA in six steps and have it out for signature this afternoon, and if your broader documentation set — risk analysis, policies, workforce training records — is also thin, automated HIPAA compliance documentation covers the rest of the file an investigator would ask for. No product is government-certified, and no vendor can sign your obligations away. But a complete vendor register and current agreements are the two artifacts that make every subsequent conversation shorter.