A patient comes in for tension headache therapy on a Tuesday. By Friday, some fragment of that encounter has passed through your digital intake vendor, your hosted EHR, your clearinghouse, a referral portal at a neurology group, a physical therapy practice across town, an ambient documentation tool, and your statement print-and-mail service. If the patient downloaded a headache-tracking app in the waiting room, add one more. This post maps that trail and tells you which links in it require a business associate agreement, which do not, and which ones quietly do not fit either category. It is written for the person who signs the vendor contracts.

Map the Tension Headache Therapy Data Trail Before You Map the Contracts

You cannot write accurate BAAs from a vendor list built out of your accounts payable file. Payables tell you who invoices you. They do not tell you who touches protected health information. Start from the encounter and walk forward.

A typical headache-management episode in a primary care or neurology practice generates disclosures in roughly this order:

  1. Pre-visit intake. A web form or kiosk vendor collects symptom history, medication list, and insurance card images before the patient sits down.
  2. Documentation. Your EHR host stores the note. If you use an ambient scribe or transcription service, an audio file and a draft note leave your network.
  3. Orders and referrals. Imaging centers, physical therapy, behavioral health, and specialist practices receive clinical summaries. These are provider-to-provider treatment disclosures, and they follow different rules.
  4. Claims. Diagnosis and procedure codes move to a clearinghouse, then to payers, then sometimes to a payer's own subcontractors.
  5. Revenue cycle. Denials go to an outsourced billing company. Balances go to a statement vendor and, eventually, possibly to a collections agency.
  6. Patient engagement. Appointment reminders, secure messaging, satisfaction surveys, and patient education libraries all carry at least a name plus an appointment type.
  7. Backend infrastructure. Backup, e-fax, e-signature, storage, and IT managed services sit underneath all of it.

Chronic and recurring conditions make this worse, not better. A single acute complaint produces one pass through the list. Ongoing tension headache therapy produces repeat imaging, repeat referrals, repeat prior authorizations, and a longer document tail across more organizations.

The three buckets that decide everything

Every entry on that trail lands in one of three categories: a business associate who needs a signed agreement, a covered entity receiving PHI for treatment or payment who does not, or a third party operating outside HIPAA entirely. Misfiling a vendor into the wrong bucket is the most common finding I see in a self-audit.

Which Tension Headache Therapy Vendors Actually Need a BAA?

A vendor needs a business associate agreement if it creates, receives, maintains, or transmits PHI on your behalf while performing a function or service for you. Applied to a headache-care workflow, that means:

  • BAA required: hosted EHR and practice management platforms, digital intake vendors, transcription and ambient documentation tools, clearinghouses, outsourced billing companies, statement and mailing services, patient messaging and reminder platforms, cloud storage and backup providers, e-fax services that retain content, managed IT and remote support, shredding and record-storage companies, and any analytics vendor that receives identifiable data.
  • BAA not required: another treating provider you refer to, the payer you bill, a patient's personal representative, a law enforcement or public health recipient under a permitted disclosure, and true conduits such as the postal service or an internet service provider that only transmits.
  • Outside HIPAA: an app the patient chose and directed you to send data to. That vendor is not yours, and its obligations run under other law.

The conduit exception is narrower than vendors like to claim. HHS has been explicit that a cloud service provider is a business associate even when it stores only encrypted PHI and holds no decryption key — persistent access to the data, not the ability to read it, is the trigger. Read the agency's cloud computing guidance before you accept a "we're just a pipe" argument from a storage or fax vendor.

The Referral Loop Is Not a Vendor Relationship

Front-desk staff frequently ask why the neurology group down the street does not need to sign anything. Because disclosures to another covered entity for treatment are permitted without authorization and without a BAA. The specialist is not performing a service for you; the specialist is treating the patient.

Two operational consequences follow. First, the minimum necessary standard does not apply to disclosures to a provider for treatment purposes, which is why sending a complete relevant record to a consulting specialist is appropriate rather than over-disclosure. Second, the absence of a contract means the absence of contractual breach-notice obligations. If PHI you sent is exposed inside the receiving practice, that is their reportable incident, not yours — but you will still field the patient calls.

Where the referral loop actually leaks

The leak is rarely the record itself. It is the access path. Practices accumulate credentials to specialist portals, imaging portals, and payer portals, and those credentials outlive the staff who requested them. Build a termination checklist that includes external portal accounts, not just your domain accounts, and reconcile it quarterly. A departed medical assistant with a live imaging-portal login is a finding waiting to happen.

The second leak is fax and email misdirection. If your referral coordinator sends a headache workup to the wrong specialist's fax line, that is an impermissible disclosure you must evaluate under the four-factor risk assessment in the Breach Notification Rule. Log every one. Patterns matter more than individual incidents when OCR asks how you manage risk.

Apps, Trackers, and the Vendors Patients Bring With Them

Headache management generates unusually rich patient-collected data: symptom diaries, sleep logs, stress ratings, trigger journals. Patients arrive with apps already installed and ask you to connect.

When a patient exercises their right of access and directs you to transmit data to an app of their choosing, that app does not become your business associate, and you are not liable for what happens to the data afterward. Document the request, verify identity, and send. What you must not do is recommend a specific app, receive any remuneration from it, or embed it in your workflow — at that point you have arguably engaged a vendor, and the analysis flips.

Apps outside HIPAA are not unregulated. The FTC's Health Breach Notification Rule reaches health apps and connected devices that are not covered by HIPAA, and the Commission has brought enforcement over unauthorized disclosure of health data to advertising platforms. If your practice is evaluating a symptom-tracking tool to offer patients as part of a tension headache therapy program, treat it as a vendor and paper it accordingly.

Your own website counts

Third-party tracking code on a page about tension headache therapy can transmit an IP address alongside a condition-specific URL. OCR's position on tracking technologies has been contested in litigation, and portions of its guidance were narrowed by a federal court in 2024. The safe operational answer has not changed: inventory the scripts on your site, remove what you cannot justify, and get a signed agreement with any analytics vendor that receives data from authenticated patient portal pages.

Five Clauses That Do Real Work in a BAA

Most agreements in circulation are copies of the HHS sample business associate agreement provisions with a signature block added. That satisfies the minimum. It does not protect you operationally. Add or tighten these:

  • A hard breach-notice deadline. The regulation permits up to 60 days from discovery. Negotiate 5 business days for confirmed incidents and 24 hours for suspected ransomware. Your own clock runs on the same 60 days, and a vendor that burns 55 of them leaves you nothing.
  • Subcontractor flow-down with notice. Require the vendor to name material subcontractors and notify you before adding one. The 2024 clearinghouse disruption taught most practices that they had no idea how deep their dependency chain ran.
  • Secondary use prohibition. State plainly that PHI may not be used to train models, build benchmarks, or create de-identified data products without written consent. Ambient documentation vendors are the pressure point here.
  • Return or destruction at termination. Specify format, deadline, and a written certificate of destruction. Add data-export pricing now, while you still have leverage.
  • Evidence of safeguards. Ask for a current risk analysis attestation or third-party audit report. No federal agency certifies vendors as HIPAA compliant, so treat any "HIPAA certified" badge as marketing rather than assurance.

If your gap is simply that a dozen vendors are operating without a signed agreement at all, close that first. You can build a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which matters when you need eleven of them this month rather than one.

The 60-Day Clock When the Breach Starts at the Vendor

A business associate must notify you of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. If that business associate is acting as your agent under common law, its discovery date is imputed to you — meaning your notification clock started when the vendor found out, not when the vendor got around to telling you.

Assign these roles before you need them:

  1. Privacy officer receives the vendor notice, logs date and time of receipt, and opens the incident file.
  2. Practice manager pulls the affected record set and produces the patient list with current addresses.
  3. Privacy officer runs the four-factor risk assessment and documents the conclusion in writing, including a decision not to notify.
  4. Designated backup drafts patient letters against a pre-approved template so day 45 is not spent on wording.
  5. Privacy officer files with HHS through the breach portal and, for incidents affecting 500 or more residents of a state or jurisdiction, coordinates media notice.

Before you renew any contract, search the vendor's name on the OCR breach reporting portal. It takes two minutes and occasionally changes the conversation entirely.

A Quarterly Vendor Review That Takes 90 Minutes

Annual reviews drift. Quarterly reviews with a fixed agenda hold. Put four items on it.

New vendors since last quarter. Ask the practice manager and the IT contact directly — new tools enter through department budgets, not through you. Any tool that touched a tension headache therapy encounter and has no signed agreement goes on the remediation list that day.

Expiring or unsigned agreements. Keep one spreadsheet with vendor name, service, PHI touched, BAA execution date, notice deadline in days, subcontractors named, and renewal date. Six columns. That is your entire third-party risk program at a small practice.

Departed staff and external portal access. Reconcile against the termination checklist.

Terminated vendors. Confirm the destruction certificate arrived. If it did not, that vendor still holds your patients' data and you still own the exposure.

Practices that also need the underlying documentation — risk analysis, policies, workforce training records — can automate the full compliance document set rather than rebuilding it from templates every audit cycle.

What to Do This Week

Pick one recent tension headache therapy encounter. Trace every system that received any part of it, from the intake form to the statement envelope. Put each recipient into one of the three buckets. You will almost certainly find at least one vendor with no agreement on file and one with an agreement so old it predates the subcontractors now handling your data.

Fix the unsigned ones first — generate the agreements you are missing, send them for signature, and file the executed copies where your next auditor will find them without asking.