Swelling and Pitting Edema: Mapping Your Vendor BAAs
A patient checks in Tuesday at 9:15 with bilateral leg swelling. By Friday afternoon, the record of that single visit has passed through your EHR host, an ambient documentation vendor, a lab interface, an outbound fax service, a referral portal, a clearinghouse, and a cloud backup target. That is seven third parties before anyone bills anything. A swelling and pitting edema workup is unremarkable clinically and unusually revealing administratively — it is a high-referral, high-imaging, multi-department pathway, which makes it an excellent stress test for your Business Associate Agreement inventory.
This post is a vendor-mapping exercise for practice administrators and privacy officers. It does not tell you anything about how to evaluate or treat edema. It tells you where the chart goes, who has to sign what, and how to find the gaps before a breach notification letter finds them for you.
Why a Swelling and Pitting Edema Pathway Touches So Many Vendors
The administratively relevant fact is simple: this presentation frequently generates a referral. Cardiology, nephrology, vascular, or a hospital-based imaging department — the specific destination varies, but the pattern holds. Records leave your building, and results come back.
Layer on the routine supporting cast. Labs get ordered. Imaging gets scheduled at an outside facility. Serial measurements sometimes get captured on a device or app. Compression supplies may route through a durable medical equipment supplier. Prior authorization gets faxed. A patient calls the after-hours line about the swelling and pitting edema getting worse and reaches your answering service.
Each of those steps is a disclosure. Each disclosure lands in one of three buckets: a treatment or payment disclosure to another covered entity (no BAA), a disclosure to a business associate performing a function on your behalf (BAA required), or a disclosure that shouldn't be happening at all.
Which Vendors in This Pathway Need a Signed BAA?
Short answer: a BAA is required when a third party creates, receives, maintains, or transmits protected health information on your behalf to perform a function or service for your practice. It is not required when you disclose PHI to another covered entity for that entity's own treatment, payment, or health care operations purposes.
In a typical edema referral workflow, these commonly require a BAA:
- EHR vendor and any hosting or database provider behind it
- Patient portal and secure messaging platform
- Transcription or ambient documentation service
- Cloud fax and e-fax providers that store transmitted documents
- Billing company, coding contractor, and revenue cycle outsourcer
- Clearinghouse (a business associate when acting on your behalf)
- Managed IT provider, backup vendor, and remote-support tooling
- Release-of-information vendor handling records requests
- Appointment reminder, recall, and survey platforms
- Answering service and after-hours triage call center
- Document shredding and media destruction vendor
- Remote monitoring or connected-device vendor holding patient-generated data on your behalf
These generally do not require a BAA:
- The cardiology, nephrology, or vascular practice you refer to — that is a covered-entity-to-covered-entity treatment disclosure
- The hospital imaging department performing its own service and billing under its own number
- The health plan you submit a claim to
- Couriers and postal services acting as pure conduits with only transient access
- The patient, and anyone the patient directs the record to
HHS's guidance on business associates is the controlling reference here, and it is short enough to read in one sitting. Print it and keep it with your vendor file.
The Conduit Exception Is Narrower Than Your Vendors Claim
Expect at least one vendor in this pathway to tell you they are "just a pipe." The conduit exception covers entities that transport PHI with only random or incidental access — think a courier or a telecom carrier. It does not cover a service that stores your documents, indexes them, retains copies for troubleshooting, or holds encryption keys.
The practical test: ask whether the vendor could produce a copy of a specific fax, message, or file from ninety days ago. If yes, they maintain PHI, and they are a business associate. Get the agreement.
Where Practices Get This Wrong Most Often
Three recurring mistakes show up in gap analyses of referral-heavy pathways.
First, the referral portal gets confused with the referral recipient. The specialist is a covered entity. The third-party platform brokering the referral, storing the packet, and tracking status is a business associate of somebody — often both sides. Read the platform's contract to see who it claims to serve.
Second, website and portal analytics. OCR's tracking-technology guidance has been contested in federal court, and a 2024 decision vacated a portion of it relating to unauthenticated pages. That litigation did not change the underlying analysis for authenticated environments. If a patient logs into your portal to view results from an edema workup and a third-party script is capturing that session, you have a disclosure that needs a BAA or it needs to stop.
Third, the marketing and reputation vendors nobody told the privacy officer about. Post-visit survey tools and review-request platforms routinely receive patient names, contact information, visit dates, and department. That is PHI.
Build the Map: A Four-Column Inventory Anyone Can Maintain
You do not need a platform for this. You need a table your privacy officer updates quarterly and can produce on demand during an audit or after an incident.
Columns:
- Vendor and function. Name, what they actually do, and the internal owner who signs their invoices.
- PHI touched. Specific data elements and direction of flow — inbound, outbound, or bidirectional. "Demographics, visit date, diagnosis codes, clinical notes, outbound only" is useful. "Patient data" is not.
- BAA status. Signed date, effective date, execution method, and where the countersigned copy lives. If you cannot retrieve the countersigned PDF in under five minutes, treat the status as unknown.
- Subcontractors and breach terms. Known downstream vendors, plus the notification window written into your agreement.
Run one pathway through it as a pilot. The edema workflow is a good candidate precisely because it crosses front desk, clinical, imaging coordination, referral management, and billing. If your map survives that pathway intact, it will survive most others.
The Subcontractor Layer You Probably Skipped
Since the 2013 Omnibus Rule, subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves business associates, directly liable under the Security Rule and portions of the Privacy Rule. Your billing company's offshore coding partner is in scope. Your EHR vendor's cloud infrastructure provider is in scope.
You are not required to hold agreements with those subcontractors — your business associate is. But you are entitled to ask, and your BAA should obligate them to flow down equivalent terms. Add a line to your annual vendor questionnaire: list every subcontractor with access to our PHI, and confirm each has executed a written agreement. Vague answers are a finding.
Closing the Gaps: A 30-Day Sprint With Named Owners
Most practices that run this exercise find three to eight vendors with no agreement, an expired agreement, or an agreement signed by someone who left in 2021. Here is a workable schedule.
Days 1–5 — Inventory. Practice administrator pulls the accounts payable ledger for the trailing twelve months and flags every vendor that could plausibly touch PHI. AP is more honest than the IT asset list because it captures shadow subscriptions.
Days 6–12 — Classify. Privacy officer sorts each vendor into business associate, covered entity, conduit, or no-PHI. Document the reasoning in one sentence per vendor. That sentence is your defense if the classification is ever questioned.
Days 13–20 — Retrieve. Locate countersigned agreements. Anything you cannot produce counts as missing. Build the gap list.
Days 21–27 — Execute. Send agreements to every gap vendor. This is where practices stall, usually because drafting feels like a legal project. It is not — HHS publishes sample business associate agreement provisions, and if you need clean paper fast you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, one-time purchase, no subscription. Six vendors, one afternoon.
Days 28–30 — File and calendar. Store countersigned copies in one location. Set renewal and review reminders. Schedule the next full review for twelve months out.
Terms Worth Negotiating, Not Just Signing
The regulatory minimums are a floor. Four terms are worth pushing on:
- Breach notification window. The rule gives covered entities 60 days from discovery to notify individuals. If your BAA lets the vendor take 60 days to tell you, your clock is already gone. Ask for 5 business days, settle for 10.
- Return or destruction at termination. Specify the format and the deadline. "Commercially reasonable" means nothing at 2 a.m. during an offboarding.
- Cooperation with individual rights requests. If a vendor holds the only copy of imaging results from a referral, your 30-day access clock depends on their responsiveness.
- Audit and evidence rights. At minimum, an annual attestation and the right to request risk analysis documentation.
HHS has proposed significant updates to the Security Rule, including tighter expectations around written assurances from business associates. That rulemaking was still pending as of this writing, so build to today's requirements — but write agreements flexible enough to absorb tighter obligations without a full renegotiation.
What Failure Looks Like in Practice
Scan the OCR breach portal and filter for incidents attributed to business associates. The pattern is consistent: the breach happens at a vendor, and the covered entity's name is the one on the public list. Patients do not distinguish between your practice and your transcription contractor.
The secondary failure is slower. When OCR opens an investigation, the first document request almost always includes your risk analysis and your executed business associate agreements. A practice that produces a current vendor map, signed agreements, and dated review records is in a materially different conversation than one that produces a shrug. NIST SP 800-66r2 remains the most practical free walkthrough of how those pieces connect.
One more boundary worth knowing: not every health app in the edema monitoring space falls under HIPAA. Consumer-facing tools a patient downloads on their own may instead sit under the FTC's Health Breach Notification Rule. If your staff recommends an app, know which regime governs it before the recommendation becomes a policy.
Start With One Pathway This Week
Pick the swelling and pitting edema workflow, or any pathway that generates referrals and outside imaging, and trace one real chart end to end. Write down every system, service, and human organization that touched it. That list is your vendor map, and it will be longer than you expected.
Then close the gaps. Build the agreements you're missing with a purpose-built BAA generator, and if your broader documentation set — risk analysis, policies, workforce training records — is equally overdue, automating the full compliance document set is a reasonable next step. Neither is a certification, because no such government credential exists. Both are evidence, and evidence is what you'll be asked for.