A referral packet leaves your office at 9:14 on a Tuesday morning. By Friday, the same patient data has moved through your scheduling platform, an outbound fax gateway, an ambulatory monitoring service, a transcription vendor, a release-of-information contractor, and a clearinghouse. That is six organizations from one referral. Can your privacy officer name all six and produce a countersigned business associate agreement for each within an hour?

A psychogenic nonepileptic seizures pathway is a useful stress test for that question. Administratively, it is a long pathway: the workup typically involves outside monitoring, the diagnosis usually crosses from neurology into behavioral health, and the record therefore travels between organizations more often than it does for a routine office visit. This post maps the vendor touchpoints and tells you which ones require a signed BAA, which do not, and how to prove it during an audit.

Why this pathway generates more vendor touchpoints than a standard visit

Keep the clinical detail out of it. What matters to you as an operator is the shape of the workflow. Evaluation for psychogenic nonepileptic seizures commonly involves extended monitoring performed by or through an outside facility, review of event recordings, and referral to a behavioral health clinician who may sit in a separate legal entity with a separate record system.

Three structural consequences follow, and all three are administrative:

  • Records leave your four walls at least twice — outbound for the workup, inbound with results — and often a third time on referral.
  • Media files, not just documents, enter the chart. Video and long-form study data behave differently in your systems than a two-page consult note.
  • The behavioral health leg introduces record types with tighter disclosure rules, which changes who on your staff may release what.

Every one of those movements is a data flow. Every data flow has an owner. Your job is to write the list down.

Which vendors in a psychogenic nonepileptic seizures pathway need a BAA?

A vendor needs a business associate agreement when it creates, receives, maintains, or transmits protected health information on your behalf to perform a function or service for your practice. In a psychogenic nonepileptic seizures pathway, that typically covers:

  • Ambulatory or in-home monitoring services that collect study data and return reports under contract with you
  • Transcription and scribe services, including AI documentation tools that process encounter audio
  • Release-of-information contractors handling the referral packet and inbound records requests
  • Cloud hosting, backup, and file-transfer providers that store or move study files, even encrypted ones
  • Billing companies, coding vendors, and clearinghouses
  • Answering services, patient messaging platforms, and appointment reminder vendors
  • Telehealth platforms used for follow-up or behavioral health visits
  • Shredding, IT support, and managed service providers with access to systems containing PHI

A BAA is not required for disclosures to another provider for treatment purposes. When you send the referral packet to a neurologist or a behavioral health clinician who is treating the patient, that is a treatment disclosure, not a business associate relationship. It is also not required for your own workforce, or for a true conduit that only transports data without accessing it. HHS explains the boundary in its business associates guidance.

The conduit exception is narrower than your vendor claims

Expect at least one vendor in this pathway to tell you it is "just a pipe." The conduit exception is deliberately narrow — it covers entities like the postal service and telecommunications carriers that transmit information without persistent access to it. A cloud file-sharing service that stores study video for thirty days is not a conduit. Neither is a fax-to-email gateway that retains images.

The practical test we use: if the vendor's systems hold the data at rest for any period, or if a vendor employee could theoretically open it, get the BAA. Arguing the point costs more than executing the agreement.

The seven handoffs to inventory

Sit with a printout of one de-identified pathway and walk it forward. Here is the sequence most practices find, with the owner we recommend assigning to each.

1. Intake and scheduling

Owner: front desk supervisor. Vendors typically in scope: practice management system, online scheduling widget, eligibility verification service, and any SMS reminder tool. The reminder tool is the one people forget — appointment reminders are PHI.

2. Outbound referral packet

Owner: records coordinator. Vendors: fax gateway, secure email or direct messaging service, release-of-information contractor, courier. If your packet goes out through a health information exchange, confirm whether your participation agreement contains BAA terms or whether a separate agreement is needed. HealthIT.gov's overview of health information exchange is a reasonable orientation for staff who have never seen one.

3. Outside monitoring or study services

Owner: clinical operations manager. This is the touchpoint unique to a psychogenic nonepileptic seizures workup, and the one most likely to sit outside your standard vendor list because it was arranged clinically rather than through procurement. Ask three questions: who hosts the study data, for how long, and who else can log in.

4. Result return and interpretation

Owner: clinical operations manager. Vendors: interface engine, results portal, PDF generation service. If results arrive as a portal login rather than an interface message, someone in your office is downloading files to a workstation. Document where those files land and who deletes them.

5. Documentation of the encounter

Owner: compliance lead. Vendors: transcription, ambient documentation tools, dictation apps. Ambient AI documentation deserves a fresh look at the BAA's subcontractor clause — the vendor may route audio to a third-party model provider. Ask, in writing, for the subcontractor list.

6. Behavioral health referral and record sharing

Owner: privacy officer. This leg has different rules. HIPAA gives psychotherapy notes special treatment: with narrow exceptions, they require patient authorization for disclosure, and they must be kept separate from the rest of the designated record set to qualify. If the referral destination is a federally assisted substance use disorder program, 42 CFR Part 2 adds its own consent requirements on top of HIPAA. Your front desk should never be the group deciding which of these applies.

7. Billing and revenue cycle

Owner: billing manager. Vendors: billing company, coding auditor, clearinghouse, patient statement printer, payment processor, collections agency. Statement printers and collections agencies are business associates and are routinely missing from vendor lists.

Patient-recorded event video: the flow nobody contracts for

Families sometimes bring phone video of an event to the appointment. The moment your staff copies that file into the chart, it is PHI in your custody, subject to your retention schedule and your access controls. The administrative questions are mundane and important: which staff role performs the transfer, on which device, and does the original get deleted from the intermediate device?

Write a one-paragraph procedure. Ours says the file is transferred by a designated clinical staff member using the practice-managed device only, uploaded into the record, and removed from local storage the same day, with the transfer logged. If patients ask about consumer apps they use to track events, note that many such apps are not covered entities at all — they may instead fall under the FTC's Health Breach Notification Rule. That distinction matters when a patient asks your staff whether an app is "HIPAA compliant." The honest answer is that your practice cannot vouch for tools it does not contract with.

What your BAA actually has to say

An agreement that only recites "the parties will comply with HIPAA" is not a BAA. The required elements sit at 45 CFR 164.504(e), and HHS publishes sample business associate agreement provisions you can compare against. At minimum the document must establish permitted uses and disclosures, require appropriate safeguards, bind subcontractors to the same terms, obligate the business associate to report security incidents and breaches, address access and amendment obligations, make records available to HHS, and specify what happens to PHI at termination.

Two clauses to negotiate rather than accept as drafted:

  1. Breach notification timing. The regulation gives a business associate up to 60 calendar days from discovery to notify you. That leaves you almost no runway for your own 60-day clock. Contract for a shorter window — many practices use five business days for confirmed breaches and 24 hours for suspected security incidents.
  2. Return or destruction at termination. Vendors frequently insert "if feasible" and then declare it infeasible. Specify a format, a deadline, and a certification of destruction.

If you are papering a monitoring service, a transcription vendor, and a statement printer this quarter and do not want to run each one through outside counsel, a signature-ready business associate agreement built through a six-step wizard gets you a defensible document in PDF and DOCX for a one-time purchase — no subscription attached. Use it for the routine vendors and save counsel for the contracts with real negotiation leverage on the other side.

Proving the map exists

An inventory that lives in one person's head fails the first audit question. Build a single spreadsheet with these columns: vendor name, service, data elements touched, direction of flow, system of record, BAA executed date, BAA expiration or renewal date, subcontractor list received, security questionnaire date, internal owner.

Then set a cadence:

  • At contract signature: BAA executed before any PHI moves. No exceptions for pilots or trials.
  • Quarterly: privacy officer reviews new vendors added by any department. Clinical operations is the usual source of unlogged additions.
  • Annually: re-request subcontractor lists and confirm the security contact is still employed there.
  • At termination: obtain destruction certification and close the row with a date.

Tie the map to your risk analysis rather than keeping it as a standalone file. The proposed Security Rule update HHS published in early 2025 would push covered entities toward written asset inventories and network maps as an explicit requirement; whatever the final rule looks like, the direction of travel is clear, and a maintained vendor map is a head start. If you are rebuilding the underlying documentation set, automated risk analysis and policy generation will keep the vendor inventory and the risk register pointed at the same facts.

For calibration on what goes wrong, spend twenty minutes in the OCR breach portal filtering for business associate involvement. The recurring pattern is not exotic: a vendor two layers down held data nobody remembered giving it.

Start with one pathway, not the whole practice

Do not try to map every service line at once. Take a single psychogenic nonepileptic seizures pathway, walk the seven handoffs above with the staff who actually perform them, and count the organizations. Most practices find two or three vendors with no agreement on file and at least one where the signed copy cannot be located.

Fix those this month. Then run the same exercise on your next pathway. If the gap you find is a missing agreement rather than a missing process, generate the BAA and get it countersigned before the next referral packet goes out the door.