Count the outside organizations that touched the last orthostatic hypotension postural hypotension workup your practice ordered. Most administrators guess three. When you actually trace it — referral packet, imaging or cardiology group, home blood pressure monitoring platform, transcription, fax gateway, patient portal vendor, the analytics tool your MSO pulls quality metrics into — the number is closer to seven. This post is a vendor-exposure walkthrough for practice administrators and privacy officers: which of those handoffs need a business associate agreement, which don't, what your contract should say about breach timelines, and how to close the gaps in 30 days.

Nothing here is clinical guidance. The clinical detail matters only as the reason the paperwork moves.

Why Orthostatic Hypotension Postural Hypotension Encounters Generate So Many Handoffs

These encounters tend to be multi-site by nature. A primary care visit produces positional vital signs and a medication list. That often generates a referral to cardiology or neurology, sometimes autonomic testing at a facility you do not own, sometimes a home monitoring arrangement, sometimes a fall-risk or home-health evaluation.

Every one of those steps is a records event. The chart note goes out. Medication history goes out. Contact information, insurance data, and often a diagnosis code go out. Each step is a place where your practice either has a signed agreement covering the recipient or it does not.

Compare that to a rash or a routine physical, where the record may never leave your four walls. The vendor surface for orthostatic hypotension postural hypotension documentation is wide, and it is wide on a routine, high-volume basis — which is exactly the profile that turns into a reportable incident eventually.

Which Recipients Need a BAA and Which Don't

This is where most practices get it backwards. They paper the wrong relationships and leave the real ones uncovered.

The specialist you refer to is not your business associate

Disclosures between covered entities for treatment purposes do not require a business associate agreement. When your office sends a referral packet to a cardiology group, that is a treatment disclosure. No BAA. What it does require is a minimum-necessary judgment on what goes in the packet and a defensible transmission method.

Practices routinely over-send here. The referral coordinator exports the full chart because it is one click, and eight years of unrelated encounters land at another organization. HHS guidance on the minimum necessary requirement does not exempt treatment disclosures from good judgment — it exempts them from the standard, but your policy should still define a standard referral packet. Write it down: relevant encounter notes, active medication list, relevant results, demographics, insurance. Not everything.

The remote monitoring or device platform almost always is

If a vendor creates, receives, maintains, or transmits PHI on your behalf, it is a business associate. A home blood pressure or ambulatory monitoring platform that stores readings tied to your patients, under your practice's account, is squarely inside that definition. So is the company that hosts the readings even if a device manufacturer sells the hardware.

Ask a specific question during procurement: who holds the data at rest, and under whose account? If the answer is "our cloud, your practice's tenant," you need an agreement with that entity, and you need to know who their subcontractors are.

The DME supplier is usually a covered entity — the portal in between may not be

A durable medical equipment supplier that bills insurance is generally a covered entity in its own right, and your disclosure to them for treatment or payment is not a business associate relationship. But the ordering portal, the e-fax gateway, or the referral-routing network sitting between you and that supplier is a different animal. Those intermediaries handle PHI on your behalf and belong on your BAA list.

The conduit exception is narrower than your vendor claims

Vendors love to say they are "just a pipe." The conduit exception covers entities that transport PHI without accessing it other than randomly or incidentally — think the postal service or a telecom carrier. A cloud service that stores your referral PDFs for 90 days is not a conduit, even if it never opens them. Storage plus persistence equals business associate. HHS's sample business associate agreement provisions are the baseline to measure a vendor's paper against.

If that inventory exercise turns up three or four vendors handling orthostatic hypotension postural hypotension data with no signed agreement on file, you can build a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. One-time purchase, no subscription — which matters when you are papering a backlog rather than starting a program.

Does a Remote Blood Pressure Monitoring Vendor Need a BAA?

Yes, in almost every configuration. A remote blood pressure or home monitoring vendor needs a business associate agreement with your practice if it creates, receives, maintains, or transmits protected health information on your behalf. That includes storing readings linked to patient identifiers, hosting a clinician dashboard, routing alerts to your staff, or generating reports your practice bills from. The exception is narrow: a vendor that sells hardware directly to the patient, never receives identifiable data under your practice's account, and has no access to your systems is not your business associate. If you cannot state in one sentence which of those two situations you are in, treat it as the first and get the agreement signed.

What Your Contract Must Say About Timelines

The regulation gives a business associate up to 60 days to notify you of a breach. That default is operationally useless. Your own 60-day clock to notify patients starts at discovery, and if your vendor burns 55 days, you have five.

Negotiate the reporting window down. Common, defensible language:

  • Notice of any suspected security incident involving your PHI within five business days of the vendor's discovery.
  • Full written incident detail — patients affected, data elements, cause, containment steps — within 15 calendar days.
  • Vendor cooperation with your risk assessment, at their cost, including patient-level lists in a usable format.
  • Named subcontractors, with notice before any new one touches your data.
  • Return or destruction of PHI at termination, with written certification.

Then read the HHS breach notification rule against your own runbook. Breaches affecting 500 or more individuals go to HHS without unreasonable delay and no later than 60 days. Smaller breaches are logged and submitted within 60 days of the end of the calendar year. If your vendor tells you in March about an incident from January, your December filing has to reflect it — which means someone at your practice owns a running breach log, not a memory.

The Records Request That Lands on Vendor-Held Data

A patient asks for "all my blood pressure readings." Half of them live in your chart. The other half live in a monitoring vendor's platform.

The right of access clock does not care about that split. You have 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. If data the vendor holds is part of your designated record set — and readings you use to make care decisions generally are — you are obligated to produce it.

Two operational consequences:

  1. Your BAA needs an access-support clause. The vendor must provide records in a readable electronic format within a window that lets you meet 30 days — say, ten business days from your request.
  2. Your release-of-information staff need a list of which vendors hold which data types, so the request does not sit for three weeks while someone figures out who to email.

OCR has pursued right-of-access cases steadily for years, and the fact pattern is almost always the same: an ordinary request, a slow internal handoff, no malice, a penalty anyway. You can review the pattern of reported incidents on the HHS breach portal to see how often third-party involvement appears in the narratives.

A 30-Day Cleanup Plan With Names Attached

Do this once and it becomes maintenance rather than archaeology.

Week 1 — Inventory (Privacy Officer)

Pull the last 20 encounters that generated a specialist referral or a monitoring order. Trace every outbound transmission. Build a single spreadsheet: vendor name, what data they receive, how they receive it, who at your practice initiated the relationship, BAA on file yes/no, date signed.

Include the ones nobody thinks of — the answering service that takes symptom calls after hours, the transportation coordinator, the fax number that is actually a cloud service, the scheduling widget on your website.

Week 2 — Classify (Privacy Officer + Practice Manager)

Sort each row: covered entity receiving a treatment or payment disclosure (no BAA), business associate (BAA required), or true conduit (rare — document your reasoning). Anything you argue is a conduit, write two sentences explaining why, and keep it.

Week 3 — Paper the gaps (Practice Manager)

Send agreements to every unsigned business associate. Set a two-week response deadline. For vendors who push back with their own form, check three things: breach notification timeline, subcontractor flow-down, and return-or-destroy at termination. Those three clauses carry most of the operational weight.

Week 4 — Wire it into intake (Front Desk Lead + IT)

No new vendor touches PHI without a signed agreement. That means a one-page intake form, a named approver, and a recurring calendar reminder to re-review the vendor list every six months. Tie the vendor inventory to your security risk analysis so the two documents reference each other — if you are rebuilding that documentation set, automated risk analysis and policy generation will get you a defensible baseline faster than a blank template.

The Standard Auditors Are Moving Toward

HHS proposed significant Security Rule updates in a January 2025 notice of proposed rulemaking, with a clear theme: more explicit vendor verification, asset inventories, and documented technical safeguards rather than "addressable" judgment calls. Track the final text when it lands. Regardless of the outcome, the direction of travel is unambiguous — a signed PDF in a folder is no longer treated as evidence that a vendor is actually protecting anything.

The practical version for a mid-size practice: know your vendors, know what data each one holds, know how fast they will tell you when something goes wrong, and be able to produce that list in under an hour.

Start With the Agreements You Are Missing

The inventory is the hard part. Once you know which vendors handle orthostatic hypotension postural hypotension records without a signed agreement, closing the gap is a paperwork exercise you can finish this week. Generate the business associate agreements you're missing, get them signed, and file them where your next auditor can find them without asking you twice.