At 9:12 a.m. a patient calls your front desk and says her knee is paining after a weekend hike. By 10:40 that morning, before she has walked out of the building, her name, date of birth, chief complaint, insurance ID, and a set of imaging orders have passed through somewhere between six and fourteen separate companies. Most practice administrators can name four of them. This article is about finding the rest, and about which ones legally require a signed Business Associate Agreement before that first disclosure happens.

Nothing here is clinical guidance. The clinical detail matters only because it explains the routing: complaints like this one commonly involve imaging and an outside specialist, which means the record leaves your walls early and often.

The Data Flow Behind a Single "Knee Is Paining" Encounter

Write the pathway out as a line, not a list. A line forces you to see handoffs.

  1. Patient calls or books online. Scheduling platform receives name, phone, reason for visit.
  2. Automated appointment reminder fires by SMS or email.
  3. Front desk verifies eligibility through a clearinghouse or payer portal.
  4. Digital intake form collects history and consent.
  5. Clinician documents in the EHR; an ambient documentation or transcription tool may capture the audio.
  6. An imaging order routes to an outside radiology group or an in-house modality with a vendor-managed PACS.
  7. A referral packet goes to an orthopedic practice, sometimes through a health information exchange, sometimes through a fax-to-email gateway.
  8. Charges flow to a billing or RCM vendor, then to the clearinghouse, then to the payer.
  9. Results and instructions post to a patient portal or secure messaging tool.
  10. Everything sits on infrastructure: cloud hosting, offsite backup, an MSP with remote access to workstations.

That is ten stops. Each stop is either a covered entity operating under treatment, payment, and health care operations, a business associate that must sign an agreement, or something you have not classified yet. The third category is where your risk lives.

Which Vendors in a Knee Is Paining Pathway Actually Need a BAA?

Short answer: any person or company that creates, receives, maintains, or transmits protected health information on your behalf to perform a function or service for you needs a signed BAA before you disclose PHI to them. That covers your EHR host, billing and RCM vendor, clearinghouse, transcription or ambient scribe tool, patient messaging platform, digital intake vendor, offsite backup provider, cloud host, shredding company, IT managed service provider with system access, and any answering service that takes clinical messages.

You do not need a BAA with: the orthopedic specialist you refer to (a covered entity receiving PHI for treatment), the health plan you bill (a covered entity receiving it for payment), the patient, a courier or postal service acting purely as a conduit, or a janitorial contractor with no access to records. HHS explains the boundary in its business associate guidance.

The line people get wrong most often is the conduit exception. It is narrow. It covers entities that transport data without persistent access, like a phone carrier or the postal service. It does not cover a cloud storage provider, even one that never looks at the data and even one holding only encrypted PHI. If a vendor stores it, they are a business associate.

Vendor Categories Worth Auditing First

Intake and scheduling tools

The reason-for-visit field is the problem. "Knee is paining, left, three weeks" is PHI the moment it is associated with an identifiable person, and it is often entered into a scheduling widget bought by the practice manager on a credit card. Ask who signed the terms of service, whether a BAA was ever executed, and whether the vendor's standard commercial agreement explicitly disclaims HIPAA obligations. Many consumer-grade booking tools do exactly that.

Reminder and messaging platforms

A text saying "Your appointment with the sports medicine clinic is tomorrow at 2" carries PHI. Confirm the platform signs a BAA and that your message templates match what the BAA permits. Then confirm the phone numbers on file are verified, because misdirected reminders are a steady source of small breaches that still require analysis and, often, notification.

Imaging and PACS

When a knee is paining and imaging is ordered, images and reports move through an ordering interface, a modality, an archive, and sometimes a teleradiology reader. Map each. The imaging group reading the study is typically a covered entity providing treatment. The PACS vendor hosting the archive is a business associate. The interface engine sitting between them may be a third party you have never contracted with directly.

Ambient documentation and transcription

This is the fastest-growing gap on vendor lists in 2026. If a tool records or processes the encounter, it needs a BAA, and your agreement should address whether de-identified or aggregate data may be retained for model improvement. Read that clause specifically. "We may use data to improve our services" is not a de-identification standard. Ask for the method and who attests to it.

Billing, RCM, and clearinghouses

These almost always have BAAs, because they have been in the compliance conversation the longest. The failure mode here is not the missing agreement, it is the stale one — signed in 2015, never amended, listing a contact who left in 2019, and silent on breach notification timelines that your own policy now assumes.

IT, hosting, and backup

Your MSP with remote desktop access is a business associate. Your offsite backup vendor is a business associate. Your cloud infrastructure provider is a business associate. So is the subcontractor your MSP uses for after-hours monitoring, though that BAA runs between them and their subcontractor, not between you and the subcontractor.

The 90-Minute Vendor Mapping Exercise

Block ninety minutes. Bring your practice manager, your billing lead, and whoever holds the IT relationship. Do not invite everyone.

Minutes 0–20: Pull the money. Export twelve months of accounts payable and the corporate card statement. Every recurring software charge is a candidate. Shadow IT surfaces here faster than in any interview.

Minutes 20–45: Walk the pathway. Take one real encounter — the knee is paining call from last Tuesday — and trace it stop by stop. Ask at each stop: who received data, what fields, through what mechanism. Write vendor names on a whiteboard.

Minutes 45–70: Classify. Three columns. Business associate. Covered entity receiving PHI for treatment, payment, or operations. No PHI access. Anything you argue about for more than two minutes goes in the business associate column pending legal review; the cost of an unnecessary BAA is a signature, and the cost of a missing one is an enforcement finding.

Minutes 70–90: Assign owners and dates. Each business associate gets a named owner, a contract status (executed / expired / missing / unknown), and a due date. Unknown is a legitimate status for exactly thirty days.

When you finish, you will typically have between four and nine vendors with no executed agreement on file. If drafting those from scratch is what has stalled this project before, a guided BAA generator that produces a signature-ready agreement in six steps with PDF and DOCX export removes the excuse. It is a one-time purchase, so you are not adding another subscription to the list you just audited.

Subcontractors: The Layer Below Your Contract

Since the 2013 Omnibus Rule, business associates must obtain satisfactory assurances from their own subcontractors, and those subcontractors are directly liable under HIPAA. You do not sign with them. You do verify the obligation flows down.

Practical test: send your three highest-volume business associates a short email asking for a current list of subcontractors that handle your PHI and confirmation that BAAs are in place with each. A vendor that answers within a week is well-run. A vendor that cannot answer in a month has told you something important about how your data is governed.

What Breaks When the Agreement Is Missing

Two things, and they compound.

First, the disclosure itself becomes impermissible. Sending PHI to a business associate without an executed agreement is a Privacy Rule violation independent of whether anything was ever exposed. There is no harm requirement.

Second, when that vendor has an incident, you have no contractual timeline. Your obligation to notify affected individuals runs without unreasonable delay and no later than 60 days from discovery, per the HHS Breach Notification Rule. If your vendor takes eleven weeks to tell you, you are explaining that gap to OCR. A well-drafted BAA gives you a contractual reporting window — many practices negotiate to five business days — and a duty to cooperate on notification content and cost.

Browse the HHS breach portal and filter by business associate involvement. The pattern is consistent: the vendor's incident becomes the covered entity's headline, its notification cost, and its patient phone calls.

Building the Register You Can Hand to an Auditor

A vendor list is not a register. A register has, for each entry:

  • Vendor legal name and the entity that actually signed
  • Service description in one sentence
  • PHI elements touched, and whether they are stored or only transmitted
  • BAA execution date, effective date, and renewal or review date
  • Internal owner by role, not by person
  • Breach notification window from the contract
  • Termination and data return or destruction terms
  • Date of last review, with initials

Review it twice a year and after every EHR change, ownership change, or new service line. The register feeds directly into your risk analysis, which the Security Rule requires you to conduct and update; NIST's SP 800-66 Revision 2 maps the implementation specifications to concrete practices if you want a structure to follow. Practices that want the risk analysis, policies, and supporting documentation generated together rather than assembled piecemeal can automate the full compliance document set and keep the vendor register as the input.

Three Questions to Ask Before Friday

Do not wait for a formal project. Ask these now.

  1. Which vendor touched PHI most recently that is not on our register? Ask the front desk, not leadership.
  2. Of our executed BAAs, how many were signed more than five years ago and never revisited?
  3. If our transcription vendor called tomorrow reporting a compromise, what does our contract say they owe us and by when?

If a patient calling to say her knee is paining triggers ten downstream data flows, and you can only account for six of them contractually, the fix is not complicated — it is just unassigned. Pull the AP report, walk one encounter end to end, and generate the agreements you are missing before the next records request makes the gap somebody else's discovery.