A patient walks out of your orthopedic clinic with a printed sheet of tennis elbow exercises, a text message containing a video link, a referral to a physical therapy group across town, and an invitation to enroll in a remote monitoring program. That is one twelve-minute encounter. It is also, depending on how your practice is wired, four or five separate disclosures of protected health information to organizations you do not control.

This post is about the vendor and business associate exposure that sits underneath routine patient education workflows. It is written for the person who signs those vendor contracts and answers for them during an audit — not for the patient doing the exercises. Nothing here is clinical guidance.

The Vendor Trail Behind a Single Tennis Elbow Exercises Handout

Lateral epicondylitis is a high-volume, low-acuity complaint that frequently moves between organizations: primary care sees it, orthopedics or sports medicine confirms it, physical therapy manages it, and the patient gets a home program. That referral pattern is exactly why the administrative footprint is larger than the clinical one.

Walk the path yourself. Pull one recent encounter and trace every system that touched it.

Content and document vendors

Most practices do not author their own patient education. The handout describing tennis elbow exercises comes from a licensed content library embedded in your EHR, a standalone education platform, or a print-and-mail service. If that platform logs which patient received which handout — and most do, because they sell engagement analytics back to you — it holds PHI. A content license agreement is not a BAA.

Messaging, reminders, and portal notifications

The SMS or email that says "Your exercise program is ready in the portal" moves through a communications vendor. The message body may be innocuous, but the metadata — phone number, clinic name, timestamp, link click — is identifiable and health-related. Your BAA needs to cover that vendor whether or not the message text names a diagnosis.

Scanning, transcription, and forms

If the patient signs an acknowledgment on a tablet, that form vendor is in scope. If a scribe service or ambient documentation tool captured the visit, add it to the list. If a third party indexes scanned PT progress notes back into the chart, add it too.

Analytics and website tools

The page on your site titled "tennis elbow exercises" may carry third-party tracking pixels. HHS issued guidance on online tracking technologies in 2022 and revised it in 2024, and a federal district court vacated part of that guidance the same year. The litigation history does not resolve the underlying risk — plaintiffs' firms and state attorneys general have continued to pursue tracking claims, and the FTC has enforced separately under its own authority. Inventory what runs on your patient-facing pages regardless of where the HHS guidance currently stands.

Which of These Vendors Actually Needs a BAA?

A vendor needs a business associate agreement if it creates, receives, maintains, or transmits protected health information on your behalf. Apply that test to the tennis elbow exercises workflow:

  • Yes — BAA required: patient education platforms that log recipients, appointment reminder and secure messaging services, EHR and portal vendors, transcription and scribe services, billing and clearinghouse vendors, cloud storage and backup providers, IT support with system access, document shredding and offsite storage, remote monitoring platforms.
  • No — BAA not required: the physical therapy practice you refer to (a covered entity receiving PHI for treatment), the patient's own fitness or wearable app that they connect independently, a landlord, a courier acting as a pure conduit, a janitorial service with no PHI access.
  • Depends — investigate: answering services, translation and interpretation vendors, marketing agencies, website hosts, analytics providers, and any "free" tool a clinician adopted without telling you.

The last category is where practices get hurt. HHS publishes guidance on who qualifies as a business associate, and the definition is functional, not contractual. Calling something a software license does not exempt it.

Treatment Referrals Are Not Business Associate Relationships

Administrators regularly send BAAs to referral partners and get confused when the partner declines. When you send a chart note to a physical therapy clinic so they can build a program of tennis elbow exercises, that is a disclosure for treatment between two covered entities. No BAA is needed. Both parties are independently obligated.

What you do need is documentation of the disclosure pathway: how the referral packet is transmitted, whether it goes by direct secure messaging, fax, or portal, and who verifies the receiving fax number or address. A misdirected referral packet is one of the most common small breaches in ambulatory care, and it does not require a vendor failure to happen.

The reverse direction matters more than you think

Progress notes come back from PT. Someone has to route them into the chart. If that routing goes through a third-party intake or document management service, that service is a business associate of yours even though the underlying referral relationship was not. Map inbound flows with the same rigor as outbound.

The Subcontractor Layer Your BAA Has to Reach

Your patient education vendor probably does not run its own data centers, send its own SMS, or staff its own support desk. Under the HIPAA Rules, a business associate's subcontractors that handle PHI are themselves business associates, and your BAA must obligate the vendor to bind them in writing.

Read the subcontractor clause in your executed agreements this week. You are looking for three things: an affirmative obligation to execute written agreements with subcontractors, a requirement that those agreements be at least as protective as yours, and either a list of current subcontractors or a duty to notify you of material changes.

If your agreement is a two-page form the vendor sent over in 2019, it likely fails at least one of those tests. The HHS sample business associate agreement provisions are the baseline, not the ceiling — they are drafting starting points, and HHS says so explicitly.

If you are rebuilding a stack of expired or thin agreements, generating them one at a time from a template file is how gaps survive for years. A six-step wizard that produces a signature-ready Business Associate Agreement with PDF and DOCX export gets a consistent document in front of every vendor in an afternoon, as a one-time purchase rather than another subscription line item.

Remote Therapeutic Monitoring Turns a Handout Into a Data Stream

The moment your practice bills remote therapeutic monitoring for musculoskeletal adherence, the tennis elbow exercises handout becomes a longitudinal data feed. The vendor now holds adherence timestamps, self-reported pain scores, device telemetry, and clinician review logs — for months.

That changes your risk profile in four ways:

  1. Volume. A breach at that vendor exposes a continuous record, not a single document.
  2. Retention. The vendor's default retention period may exceed your state's medical record retention requirement, or fall short of it.
  3. Access requests. Data held by your business associate is part of your designated record set if you use it to make decisions about the patient. A right-of-access request reaches it, and the response clock does not pause while you email the vendor. Review the HHS individual right of access guidance against your vendor's export capabilities before a request arrives, not after.
  4. Secondary use. Check whether the contract permits de-identified data use, product improvement, or research. If it does, confirm the de-identification method is documented and defensible.

Five Questions to Ask Before You Sign

Vendor security questionnaires balloon to 200 items and nobody reads the answers. These five separate serious vendors from the rest:

  • Where does PHI physically live, and is any of it offshore? Offshore processing is not prohibited, but it changes your risk analysis and may conflict with payer contracts.
  • How fast will you notify us of a security incident, in hours? The regulatory floor lets a business associate take up to 60 days. That is useless to you. Negotiate for notification within 5 business days of discovery, with preliminary notice within 24 hours for confirmed unauthorized access.
  • Who at your company can view our patients' records, and is that access logged? Ask for a sample access log, not a policy PDF.
  • What happens to our data on termination, and can you produce a deletion certificate?
  • Name your subcontractors that touch PHI. A vendor that cannot answer this in writing has not done the work.

Document the answers in your vendor file. When OCR asks how you evaluated a business associate, "we sent a questionnaire" is weaker than a dated memo with the vendor's written responses attached.

A 30-Day Vendor Inventory Sprint

Most practices do not have a current vendor list. Build one on a fixed schedule rather than as an open-ended project.

Days 1–7: Extract, don't brainstorm

Pull twelve months of accounts payable and every recurring credit card charge. Have your practice manager flag anything software, storage, communication, staffing, or records related. Separately, ask each department lead to list every tool they log into. The AP list and the login list will not match — the gap is your shadow IT.

Days 8–14: Classify

Sort each vendor into BAA required, not required, or investigate. Assign an owner to each investigate item with a named deadline. Your privacy officer signs off on the classification, not the vendor.

Days 15–25: Paper the gaps

Send agreements to every unpapered vendor. Expect resistance from small vendors and from any vendor whose product predates their compliance function. A vendor that refuses to sign a BAA while handling PHI is a vendor you replace, not a risk you accept.

Days 26–30: Calendar the renewals

Set annual review dates. Tie the review to your risk analysis cycle so it happens whether or not anyone remembers. Vendor risk documentation feeds directly into the required Security Rule risk analysis, and platforms that automate risk analysis reports and the supporting policy set can keep the vendor register and the analysis pointing at the same facts.

When the Vendor Breaches

Assume it will be your education or messaging vendor, not your EHR. Small vendors get compromised more often and disclose more slowly.

Your 60-day breach notification clock as a covered entity generally starts when your business associate discovers the breach, if the vendor is acting as your agent. That is a legal determination driven by how much control your contract gives you — which is one more reason to read the agreement before the incident.

Run a 45-minute tabletop this quarter with a scenario your staff will recognize: your patient education vendor emails on a Friday to say an employee account was compromised and 4,200 patient records including handout delivery logs may have been accessed. Who calls the vendor? Who pulls the BAA? Who determines the affected population? Who drafts the notice? Scan the OCR breach portal for recent business associate incidents in your specialty and use a real one as your script.

Watch the non-HIPAA exposure too

If your practice recommends a consumer app that the patient connects directly, that app may fall outside HIPAA but inside the FTC's Health Breach Notification Rule. That is the app developer's obligation, not yours — but the patient will call your front desk first. Decide now what your staff says.

Start With the Handout on Your Desk

Take whatever patient education material your practice handed out this morning and trace it backward through every system and vendor that produced, delivered, or logged it. That single trace will surface more unpapered relationships than a generic vendor survey.

When you find the gaps — and you will — close them with a current, complete agreement rather than the two-page form someone downloaded years ago. You can build a signature-ready BAA in six steps, export it as PDF or DOCX, and send it out the same day. One purchase, no subscription, and one fewer vendor sitting in your file with nothing behind their name.