Pick one encounter from last Tuesday. A patient came in for tension headache treatment, described three months of symptoms, and left with a referral and a prescription. That single visit — maybe eighteen minutes of clinician time — moved protected health information through somewhere between nine and fifteen outside organizations before the claim was paid. If you can't name all of them, you can't confirm you have a Business Associate Agreement with all of them. This post walks the pathway vendor by vendor so you can build an accurate map, identify which relationships legally require a BAA, and find the ones your practice has been running unpapered.

Why a Headache Encounter Makes a Good Vendor-Mapping Exercise

You don't map data flows by staring at your vendor list. You map them by walking a real patient path and writing down every place the record stops.

A headache workup is useful for this because it is administratively ordinary and administratively wide. There is no procedure suite, no implant registry, no specialty pharmacy hub — but there is intake, documentation, a likely referral to neurology or physical therapy, sometimes imaging, sometimes a prescription, and always a claim. That covers the six data channels most small and mid-size practices actually operate.

Use a high-volume, low-complexity encounter to build the template. Then stress-test it against your unusual pathways later.

Walking the Pathway: Where the Record Actually Stops

1. Pre-visit and intake

Before the patient sits down, PHI has usually already left your building. The online scheduling widget, the digital intake form platform, the insurance eligibility verification service, and the appointment reminder system each receive identifiable information. So does your answering service if the patient called after hours to describe symptoms.

Every one of those is a business associate. The scheduling vendor is not "just software" — it creates, receives, maintains, or transmits PHI on your behalf, which is the operative test under 45 CFR 160.103.

2. Clinical documentation

Your EHR host is the obvious one, and it is almost certainly papered. The ones that slip are adjacent: the ambient documentation or transcription service, the template library that syncs with your chart, the e-signature platform used for consent forms, and any dictation app a clinician installed independently.

That last category is where I find gaps most often. A clinician who adopts a note-drafting tool on a personal subscription has created a business associate relationship your compliance file knows nothing about.

3. Referral and care coordination

Because tension headache treatment commonly involves referral to a specialist, physical therapy, or behavioral health, the record leaves your organization in a structured way. The receiving provider is a covered entity in their own right — no BAA needed for treatment-purpose disclosures between providers.

But the pipe between you might not be a covered entity. Referral management platforms, HIE onramps, secure messaging services, and third-party fax-to-email gateways all handle the payload. Those need agreements.

4. Pharmacy and orders

E-prescribing routes through an intermediary network. Imaging orders route through a scheduling or order-entry vendor. The dispensing pharmacy is a covered entity; the network in between generally is not.

5. Revenue cycle

Clearinghouse, billing service, coding audit vendor, denial management consultant, patient statement printer, payment processor, and collections agency. That is seven potential business associates in one billing chain, and the printer and the collections agency are the two most frequently missing from vendor files.

6. Post-visit communication

Patient satisfaction surveys, secure messaging, recall campaigns, and any marketing automation platform that pulls from the patient list. If the vendor can see who the patient is and that they were seen by you, it is PHI.

Which Vendors Need a Signed BAA — and Which Don't

A vendor needs a BAA if it creates, receives, maintains, or transmits protected health information to perform a function or service on your practice's behalf. That includes cloud hosting, billing, transcription, IT support with access to systems containing PHI, offsite backup, document destruction, and third-party analytics on authenticated patient portals.

A BAA is not required for:

  • Another provider receiving PHI for treatment purposes — a neurologist you refer to, for example
  • Health plans receiving claims, which are covered entities acting in their own right
  • True conduits that only transport and do not store — the postal service, and telecommunications carriers in a transmission-only role
  • Vendors with no PHI access at all — landscaping, the office coffee service, a marketing firm working only on aggregate non-identifiable material
  • Members of your own workforce, including contracted staff under your direct control

The conduit exception is narrow. HHS has been consistent that it applies to entities that transport information without accessing it other than randomly or infrequently. A cloud storage provider that holds encrypted PHI is a business associate even if it never looks at the data — persistence of storage is what matters, not whether the vendor can decrypt. HHS lays this out plainly in its guidance on business associates.

The Vendors Practices Miss Most Often

After walking dozens of pathways like this one, the same names come up as unpapered:

  1. The IT managed service provider. They have domain admin. They have every record. Many practices signed a service contract in 2019 and never attached a BAA.
  2. The shredding company. They handle paper intake forms and printed superbills. Required.
  3. The answering service. Takes symptom descriptions and callback numbers. Required.
  4. Interpretation and translation services. Live interpreters hear the entire encounter. Required.
  5. The offsite backup vendor. Often subcontracted by the MSP, so it never appears in your file directly.
  6. Website analytics and advertising pixels. OCR's guidance on online tracking technologies has been revised and litigated since it was first issued, and the boundaries around unauthenticated pages have shifted. The operationally safe posture has not: if a tool sits on an authenticated portal page or a page where a user is scheduling care, treat the data as PHI and paper the relationship or remove the tool. HHS maintains its current position in its bulletin on tracking technologies.
  7. The patient survey platform, especially when the marketing coordinator signed up for it directly.
  8. The collections agency. Payment is a covered function; the agency performs it on your behalf.

When you finish the walk and find three or four vendors with no agreement on file, the fix is paper, not panic. Send an agreement, get it executed, and document the date. If you don't have counsel-reviewed template language on hand, a six-step BAA generator that exports a signature-ready PDF or DOCX gets you from gap to executed document in an afternoon — one-time purchase, no subscription to manage.

What the Agreement Has to Contain

A BAA is not a formality you satisfy with a one-page letter. Under 45 CFR 164.504(e), the agreement must:

  • Describe the permitted and required uses of PHI by the business associate
  • Prohibit uses or disclosures beyond what the contract or law allows
  • Require appropriate safeguards, including Security Rule compliance for ePHI
  • Require reporting of any use or disclosure not provided for by the contract, including security incidents and breaches
  • Require the business associate to make PHI available for access, amendment, and accounting of disclosures
  • Require the associate to make internal practices and records available to HHS
  • Require return or destruction of PHI at termination, where feasible
  • Require the associate to bind its subcontractors to equivalent terms

HHS publishes sample business associate agreement provisions covering each of these. Read them against whatever your vendor sends you — vendor-drafted BAAs routinely water down the breach notification timeline and the indemnification posture.

Negotiate the notification clock

The single term worth fighting for is breach notification timing. HIPAA gives a covered entity 60 days from discovery to notify affected individuals. If your BAA lets the vendor take 60 days to tell you, you have zero days left. Push for notice without unreasonable delay and no later than 10 calendar days, with preliminary notice within 72 hours.

Assigning the Work: Who Does What, and When

Week one — inventory

Your privacy officer walks three encounter types end to end, including one tension headache treatment visit or equivalent primary-care pathway. Output is a spreadsheet with columns for vendor name, function, data elements touched, entry point into your systems, contract owner, BAA status, and BAA execution date.

Pull a second list from accounts payable. Any recurring payment to a software or service company that does not appear on the pathway map gets investigated. This catches shadow subscriptions faster than asking staff.

Week two — classify

Sort every entry into three buckets: BAA required and on file, BAA required and missing, BAA not required with a documented reason. That third bucket matters. Write one sentence explaining why the vendor is out of scope, and date it. Auditors accept reasoned exclusions; they do not accept silence.

Weeks three and four — remediate

Send agreements to the missing bucket. Set a follow-up at 10 business days and escalate to the contract owner at 20. For any vendor that refuses to sign, you have a decision to make at the practice-owner level: stop sending them PHI, or accept documented risk with a written rationale. Most refusals come from vendors who genuinely don't handle PHI — which means your classification was wrong, not their answer.

Ongoing — quarterly review

Re-run the AP report quarterly. Review the full map annually as part of your security risk analysis. Practices that automate the risk analysis and policy documentation set tend to keep the vendor inventory current simply because the annual review forces the question.

Termination Is Where the Paper Trail Breaks

When you switch billing services or drop a survey platform, your BAA obligations don't end — they trigger. The agreement requires return or destruction of PHI. Get a written certificate of destruction with a date and a scope description, and file it with the terminated agreement.

Keep both for six years from the date the contract ended. The retention clock on BAAs runs from termination, not from signature.

Scan the OCR breach portal once a quarter for your active vendors' names. If a business associate you use appears there, you want to learn it from your own review, not from a patient.

Start With One Encounter

You do not need a consultant to build this map. You need one afternoon, one real patient pathway, and the discipline to write down every stop the record makes. The headache visit is a good starting point precisely because nothing about it is exotic.

When the map turns up vendors without agreements — and it will — generate and execute the BAAs you're missing before the next records request forces the issue. Paper first, then process.