A postpartum patient calls your after-hours line at 8:15 on a Tuesday night. By 11 a.m. Wednesday, her name, phone number, date of birth, and the words "possible mastitis" have passed through your answering service, your scheduling platform, your EHR, a lactation consultant who bills independently, a reference lab, an e-prescribing network, a pharmacy, and — two weeks later — a clearinghouse and a payer portal. That is nine organizations touching one encounter.

This article is a vendor-mapping exercise, not a clinical one. If your practice sees lactating patients, a mastitis treatment pathway is a useful stress test for your business associate agreement inventory, because it crosses more organizational boundaries in 72 hours than most routine visits cross in a year. Below: which of those nine vendors legally requires a signed BAA, which ones do not, and how to document the difference before someone from OCR asks.

Why This Particular Pathway Exposes Gaps

Most vendor inventories are built around the EHR and the billing system. Those are the loud vendors — the ones with contracts, renewal dates, and account reps who call. The quiet vendors are the ones that attach themselves to specific clinical workflows, and postpartum care attracts a lot of them.

Mastitis is commonly managed across settings: a primary care or OB practice, an outpatient lactation consultant, sometimes imaging when a clinician wants to rule out an abscess, and occasionally a surgical referral. That fragmentation is a clinical reality with an administrative consequence — protected health information moves between organizations quickly, often by phone, fax, portal message, and text, and often outside the EHR's audit log.

Your obligation does not change because the encounter is urgent or the referral is informal. If an outside entity creates, receives, maintains, or transmits PHI on your behalf, HIPAA requires satisfactory assurances in writing. HHS lays out that standard plainly in its business associate guidance.

The Nine-Vendor Trail: Mapping One Encounter

Walk the encounter chronologically. Assign an owner to each step. Then ask a single question at each stop: does this entity handle PHI on our behalf, or is it a separate covered entity acting for its own treatment purposes?

Intake and triage layer

Your after-hours answering service takes the call and records symptoms, callback number, and provider preference. That is PHI, handled on your behalf, by a vendor. BAA required. Answering services are one of the most commonly missed entries on a vendor list because the contract was often signed by a practice manager who left in 2019.

Your appointment reminder and two-way texting tool sends the confirmation. BAA required. The vendor's marketing page saying "HIPAA compliant" is not a BAA. Ask for the executed document by name and date.

Your scheduling widget on the website, if it collects a reason-for-visit field, is also in scope. BAA required. If it only collects a name and a requested time with no clinical context, it is still identifying information tied to a healthcare provider — treat it as in scope and stop arguing the edge case.

Encounter and documentation layer

The EHR vendor and any hosting provider underneath it. BAA required from the EHR; the EHR is responsible for its own subcontractor chain, but you should confirm in writing that the chain exists.

Ambient documentation or transcription tools, including AI scribes. BAA required, and this is the category that grew fastest in the last two years. If a clinician started using a note-drafting tool without telling you, the audio of a mastitis treatment visit — including everything the patient said about her infant, her partner, and her employer's pumping accommodations — left your building under no contract at all.

Telehealth platform, if the follow-up happened by video. BAA required. The pandemic-era enforcement discretion for non-public-facing video tools ended years ago; there is no residual grace period to rely on in 2026.

Diagnostic and referral layer

The reference lab running a culture is a covered entity in its own right, receiving PHI for treatment purposes. No BAA required for the treatment relationship itself. The disclosure is permitted under treatment. But if that same lab also provides you with a courier-managed specimen tracking portal or a results interface that stores your patients' data for your operational use, look at the specific service.

An imaging center receiving a referral is likewise a covered entity acting for treatment. No BAA required. What you do need is a defensible record of how the referral was transmitted — fax number verified, portal used, or direct secure messaging address confirmed.

Pharmacy, supply, and payer layer

The pharmacy is a covered entity. No BAA. Your e-prescribing network vendor, if it is a separate contract from your EHR, is a business associate. BAA required.

Durable medical equipment suppliers — including breast pump suppliers, which frequently enter the picture in postpartum care — are typically covered entities billing the payer directly. No BAA. But if your practice runs a pump-fitting arrangement where a supplier's staff work in your space using your patient list, you have a different relationship and probably need a written agreement covering it.

Clearinghouse: BAA required. Billing company or outsourced coder: BAA required. Payer: no BAA — payment is a permitted disclosure between covered entities.

Which Mastitis Treatment Vendors Need a BAA? The Short Answer

If you need one paragraph to hand a physician-owner who asked in the hallway:

A signed BAA is required for any vendor performing a function for your practice that involves PHI — answering service, texting and reminder platform, telehealth software, AI scribe or transcription, EHR, cloud storage, IT support with system access, clearinghouse, billing company, shredding and secure-disposal vendor, and release-of-information services. A signed BAA is not required when you disclose PHI to another covered entity for that entity's own treatment or payment activities — the reference lab, the imaging center, the pharmacy, the DME supplier billing independently, the surgeon you referred to, and the health plan. The test is not sensitivity of the data. It is who is performing the function and on whose behalf.

Two frequent traps. First, an entity can be a covered entity and your business associate at the same time, in different service lines — a hospital system that also sells you a shared IT platform, for example. Second, the "conduit exception" is narrow. It covers entities that transport data without accessing it other than randomly or incidentally: the postal service, a telecommunications carrier. A cloud vendor that stores your data persistently is not a conduit, regardless of whether it claims it cannot decrypt the contents.

The Lactation Consultant Question

This is the entry most practices get wrong, and the answer depends entirely on employment structure.

Employed by your practice

Workforce member. No BAA. Standard workforce training, sanctions policy, and access controls apply.

Independent contractor providing services to your patients on your behalf

Business associate. BAA required, and it should be executed before the first patient is scheduled, not after the first invoice.

Independent provider you refer to, who bills separately

Separate covered entity if they bill electronically. No BAA — the referral is a treatment disclosure. Note that some independent lactation consultants do not bill insurance electronically and therefore may not be covered entities at all. That does not create a HIPAA problem for your outbound treatment disclosure, but it does mean the records you send land in an environment with no HIPAA obligations attached. Document what you sent and why.

If you just discovered two or three contractors in this pathway with no agreement on file, the fix is a document, not a project. You can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same afternoon — one-time purchase, no subscription — which is generally faster than waiting for a contractor's own template to arrive.

Where These Records Actually Leak

The breach reports on the OCR breach portal are dominated by hacking and IT incidents at large entities, but the small-practice entries tell a different story: misdirected faxes, email to the wrong recipient, lost devices, and unauthorized access by staff.

In a postpartum pathway specifically, watch three behaviors:

  • Photographs. Patients send images to clinicians. Clinicians receive them on personal phones. If your policy does not say where those images go and how they are deleted, write it this quarter.
  • Group texts with lactation contractors. Convenient, undocumented, and outside every log you maintain.
  • Consumer health apps. Feeding and pumping trackers are not covered entities. Data a patient exports into one is outside HIPAA, but the FTC's Health Breach Notification Rule reaches many of them. If your practice recommends an app, know whether you are recommending it or integrating with it — integration changes your obligations.

A 45-Minute Exercise for Your Next Ops Meeting

  1. Minutes 0–10. Pull one closed postpartum encounter from the last quarter. Redact it. Put it on the screen.
  2. Minutes 10–25. Front desk, clinical lead, and biller each name every external system they touched for that encounter. Write them all down, including the ones that feel too small to count.
  3. Minutes 25–35. Sort into three columns: BAA on file, BAA needed, covered entity (no BAA). Do not resolve disputes in the room — flag them.
  4. Minutes 35–45. Assign an owner and a date to every row in the "BAA needed" column. Owner is a person, not a department.

Run the same exercise against a different pathway next quarter. The vendor lists overlap by about 70 percent, and the 30 percent that does not overlap is where your gaps live.

What to Keep in the File

For each business associate: the executed agreement with both signatures and dates, the effective date, the services described, the subcontractor acknowledgment, breach notification timelines, and termination-and-return-of-data terms. HHS publishes sample business associate agreement provisions you can measure your templates against.

For each covered-entity relationship where you concluded no BAA was needed — the lab, the imaging center, the referral practice — keep a one-line memo recording that determination and its date. Auditors do not object to a defensible "no." They object to a shrug.

Also record the review cadence. An agreement signed in 2021 for an appointment reminder tool that has since added an AI feature and a new subprocessor is not the same agreement in substance. Annual review, or review on material service change, whichever comes first.

Next Step

Pick one clinical pathway that crosses organizational lines — a mastitis treatment episode is a good candidate precisely because it is fast, phone-heavy, and multi-vendor — and map it end to end this week. Every vendor that turns up in the "BAA needed" column can be papered quickly: build the agreement, export it, and send it for signature rather than letting it sit on a to-do list until renewal season. If the exercise surfaces broader policy gaps, the same approach applies to your risk analysis and core compliance document set. Map first, paper second, and keep the memo that explains both.