Count the outside organizations that touch a single sialorrhea referral. In a pathway we mapped for a pediatric neurology practice, the answer was eleven: the referring primary care office, a transcription vendor, an ambient documentation tool, the clearinghouse, two payer portals, an imaging center, a courier, a records-release service, a school district's special education team, and a patient-texting platform. Only six of those eleven had a signed business associate agreement on file. Three did not need one. Two did, and nobody had noticed.

This article is a vendor-mapping exercise, not clinical guidance. If you run a practice that receives or sends sialorrhea referrals — neurology, ENT, dentistry, developmental pediatrics, speech-language pathology, physical medicine — you are the person who has to know where the chart goes and who signed what. That is the whole subject here.

Why a Sialorrhea Pathway Generates More Vendor Touchpoints Than a Routine Visit

Sialorrhea is managed across disciplines. A single patient may be seen by a neurologist, an ENT, a dentist, and a speech-language pathologist, and the underlying condition is frequently chronic, which means the record accumulates for years rather than closing after one episode. That combination — multiple specialties plus longitudinal documentation — is what multiplies your vendor exposure.

Three structural features drive the count:

  • Cross-organizational care. Records move between separate covered entities repeatedly, and each transfer uses some transport mechanism you contracted for.
  • Prior authorization volume. Pathways that involve specialty-administered treatment or durable equipment generate authorization traffic, and authorization traffic generates vendor traffic.
  • Pediatric and school overlap. Many sialorrhea patients are minors receiving services in a school setting, which pulls a non-HIPAA entity into a workflow your staff treats as routine.

None of that is exotic. It is simply more surface area than a same-day sick visit, and surface area is where BAA gaps live.

Which Sialorrhea Pathway Vendors Require a BAA?

A business associate is any person or entity that creates, receives, maintains, or transmits protected health information on your behalf to perform a function or service for you. Treatment disclosures to another provider are not "on your behalf," and that single distinction resolves most of the confusion. HHS explains the test in its guidance on business associates.

BAA required

  • Transcription and ambient documentation vendors, including AI scribes
  • Cloud storage and hosting providers, even if the data is encrypted and the vendor claims it never looks at it
  • Your billing service and any clearinghouse acting as your agent
  • Release-of-information and records-request fulfillment vendors
  • Patient texting, appointment reminder, and secure messaging platforms
  • Answering services and after-hours triage services
  • Telehealth platform vendors
  • Interpreter and translation services handling clinical detail
  • Document shredding and media destruction vendors
  • Couriers who transport charts or imaging media under contract with you
  • IT support, managed service providers, and remote backup vendors
  • Registry or quality-reporting vendors submitting data on your behalf

No BAA required

  • The referring or receiving physician, dentist, or therapist — that is a provider-to-provider treatment disclosure
  • The imaging center performing the study as its own covered entity
  • The pharmacy or specialty pharmacy dispensing under its own license
  • The DME supplier billing the payer directly for equipment
  • Health plans receiving claims — they are covered entities, not your business associates
  • The postal service and most internet service providers, under the conduit exception
  • A school district receiving records with a signed parental authorization
  • Your own W-2 employees and workforce members, who are covered by policy and training instead

Print that list. Then compare it against your actual signed-agreement folder, not your memory of it.

Build the Data Flow Map Before You Build the Contract List

Most practices work the problem backward: they start with the vendor list from accounts payable and try to guess which ones see PHI. That misses free tools, shadow IT, and anything a clinician signed up for personally. Start with the patient journey instead.

Step 1: Walk the encounter, station by station

Sit at the front desk for one morning with a legal pad. Write down every system that receives a name, a date of birth, a diagnosis code, or a note — including the fax service, the eligibility check, the wait-list text, and the tablet that collects intake forms. Do the same in the clinical area and again in billing.

Step 2: Mark direction and content for each flow

For every entry, record whether PHI goes out, comes in, or both; what data elements move; and whether the vendor stores anything. Storage matters more than transmission. A vendor that retains a copy of a sialorrhea consult note for ninety days is holding your record, and your breach exposure runs with it.

Step 3: Classify, then assign an owner

Tag each flow as business associate, covered-entity-to-covered-entity, conduit, or patient-directed. Assign a named person to each classification decision — not "compliance," a person. Your privacy officer owns the call; your practice manager owns collecting the paperwork; your IT contact owns confirming technical safeguards.

Step 4: Trace the subcontractors

Ask each business associate, in writing, which subcontractors touch your data. A transcription vendor that routes overflow to an offshore partner has created a downstream chain that your BAA must require them to paper. HHS's cloud computing guidance is explicit that a subcontractor holding PHI is itself a business associate, regardless of whether it can read the data.

Four Flows That Routinely Break BAA Coverage in a Sialorrhea Pathway

The school district

When a pediatric patient's sialorrhea affects their day at school, your staff will be asked for records by a teacher, a school nurse, or a special education coordinator. School records are generally governed by FERPA, not HIPAA, and the district is not performing a service for you. That means no BAA and no treatment-disclosure shortcut — you need a valid authorization from the parent or guardian, scoped and dated, and you need to log the disclosure. Train the front desk to route these requests to one person. "The school called" is how unauthorized disclosures happen.

The ambient documentation tool

AI scribes are now common in specialty clinics, and a BAA alone does not settle the question. Read the secondary-use terms. If the vendor reserves the right to use your encounter audio or notes to improve its models, you need to know whether that use is permitted under your agreement, whether de-identification meets the Privacy Rule standard, and what happens to the recordings at contract termination. A signed BAA that sits next to a permissive terms-of-service document is not coverage; it is a conflict.

The equipment and supply portal

Suppliers of adaptive or supportive equipment often provide a web portal where your staff uploads documentation. The supplier itself is usually a covered entity — no BAA needed. But the software company running the portal may be a business associate of the supplier, not of you, and your uploads may be stored in a system you never assessed. Ask who operates the portal and where the data lands before your staff makes it a habit.

The vendor you inherited

Every practice has one: a fax-to-email service, a legacy backup drive, or a scanning contractor set up in 2017 by someone who no longer works there. Verify the agreement exists, verify it names the current corporate entity after any acquisition, and verify it addresses breach notification timing. If you cannot produce the signed document within ten minutes, treat it as missing.

The BAA Clauses That Matter When Records Move Between Organizations

A minimal BAA satisfies the regulation and leaves you exposed operationally. HHS publishes sample business associate agreement provisions as a floor. Build four things on top of it:

  1. Breach notification in days, not "promptly." You have a 60-day outer limit for notifying individuals. If your vendor takes 45 days to tell you, your investigation is already compromised. Name a number — many practices use five business days for suspected incidents.
  2. Subcontractor disclosure and flow-down. Require a current list on request and require written agreements at every downstream tier.
  3. Return or destruction at termination. Specify format, timeline, and written certification. Longitudinal records like a multi-year sialorrhea chart are exactly what gets orphaned in a decommissioned system.
  4. Cooperation with records requests. If a vendor holds part of the designated record set, your 30-day response clock does not pause while you wait for them. Make that obligation contractual.

If your audit turns up flows without a current agreement — and it will — the fastest path is to generate one per vendor rather than editing a decade-old template. A six-step wizard that produces a signature-ready Business Associate Agreement with PDF and DOCX export handles the paperwork in an afternoon, one-time purchase, no subscription. Send them out in a single batch so your follow-up is one tracked list instead of twelve email threads.

A Four-Week Vendor Audit You Can Run With Two People

Week 1 — Inventory. Journal-walk the encounter as described above. Pull the AP vendor list, the browser bookmarks on clinical workstations, and the app list on any practice-owned tablet. Merge into one spreadsheet with columns for vendor, flow direction, data elements, storage, and classification.

Week 2 — Classify and reconcile. Privacy officer makes the business-associate call on each row and initials it. Pull every signed agreement and match it to a row. Flag three categories: missing, expired or misnamed entity, and present but thin.

Week 3 — Paper the gaps. Generate and send agreements for the missing rows. Request subcontractor lists from the vendors that store data. Ask for a current security attestation or third-party audit summary from anyone hosting your records.

Week 4 — Document and schedule. Write a two-page memo describing the map, the decisions, and the open items with dates. File it with your risk analysis. Set a calendar reminder to repeat the walk annually and immediately after any new system goes live. If your broader documentation set — risk analysis, policies, training records — is out of date, automated HIPAA risk analysis and policy generation shortens that side of the work too.

The proposed Security Rule overhaul HHS published in January 2025 would formalize much of this: written asset inventories, network maps, and periodic verification that business associates actually maintain the safeguards they promised. Whatever the final text says, a practice that already maintains a vendor map and a matched agreement file is not scrambling.

Where These Failures Actually Surface

Browse the OCR breach portal and filter for incidents attributed to business associates. The pattern is consistent: the exposure happens at a vendor, and the covered entity's name is the one in the headline. Ransomware at a billing service, a misconfigured storage bucket at a transcription company, an email compromise at a records-release firm — the practice still notifies the patients, still answers the state attorney general, and still explains what it knew about the vendor's safeguards.

That last question is the one your map answers. "We identified this flow, classified it, papered it, and verified it annually" is a defensible posture. "We assumed they were compliant" is not.

Start With One Pathway

Do not try to map your entire practice at once. Pick the sialorrhea pathway — or any cross-specialty, chronic, high-referral pathway — and follow one patient's data end to end. It is a small enough scope to finish and a broad enough scope to expose most of your vendor categories. What you learn on that one map applies to every other pathway you run.

When the gaps show up, close them the same week you find them. Generate the agreements you need with the BAA wizard, get signatures on file, and put the map in your compliance binder where an investigator can find it.