Count the outside organizations that touched the last tonsil stone removal encounter your practice documented. Not the ones on your BAA binder tab — the actual ones. For most primary care and ENT practices the honest number lands between nine and fourteen: the EHR host, the e-fax provider, the referral recipient, the ambulatory surgery center, the transcription or ambient scribe tool, the clearinghouse, the patient texting platform, the review-request service, the IT managed service provider, the shredding vendor, and whatever ad pixel is sitting on your website's procedure page. This article is a workflow map for privacy officers and practice administrators: who gets a business associate agreement, who does not, and where the gaps usually are.

Why This Particular Encounter Is a Useful Stress Test

Tonsilloliths are common, frequently self-managed, and occasionally escalated to an ENT for in-office or surgical intervention. That escalation pattern is what makes the record interesting administratively: it starts in one organization, generates images and video in a second, may get billed through a third, and produces patient-facing follow-up through a fourth. Nothing about the clinical picture matters here. What matters is that the chart fragments and travels.

Search volume matters too. People who suspect they have tonsil stones look them up, land on your procedure page, and fill out a form. That page is often the most heavily tracked, most heavily marketed URL on an ENT website — and it is a page where a visitor's presence is itself a health signal.

Mapping Where a Tonsil Stone Removal Record Actually Goes

Do this as a whiteboard exercise with your billing lead and your front-desk supervisor in the room. Pick one real encounter from last quarter, de-identify it, and trace every hop.

The referral leg

Primary care sends records to ENT. ENT sends an operative or procedure note back. If the ENT group operates at an outside surgery center, scheduling and clinical documents move there as well. None of these organizations are business associates of each other when the disclosure is for treatment. They are covered entities exchanging PHI under the treatment permission. You do not need a BAA with the ENT you refer to.

What you do need is a documented transmission method. If your referral packet goes out by e-fax, the e-fax vendor is a conduit only in the narrowest circumstances — most cloud fax services store copies, which means they are business associates and need an agreement.

The image and video leg

Scope photos, intraoral images, and short video clips get captured on department cameras, tablets, and sometimes a clinician's personal phone. Ask where those files land. In many practices they land in three places at once: the EHR media tab, a camera's SD card that nobody wipes, and a cloud photo library synced to a personal account.

Each of those is a distinct exposure. The synced personal library is the one that generates the awkward incident report, because the cloud provider holding it has no agreement with your practice and no obligation to you.

The revenue cycle leg

Coding vendor, clearinghouse, statement printing and mailing service, patient payment processor, and any outsourced A/R follow-up shop. All business associates. All handling a data set that includes procedure codes, which are diagnostic disclosures on their own.

The patient-facing leg

Appointment reminder texting, post-procedure instruction delivery, satisfaction surveys, and review solicitation. This is where practices most often discover an unsigned agreement, because marketing signed up for the tool, not compliance.

Do You Need a BAA for Every Vendor Touching Tonsil Stone Removal Records?

No. You need a business associate agreement with any outside organization that creates, receives, maintains, or transmits PHI while performing a function or service on your behalf. You do not need one with another provider receiving records for treatment, with a health plan for payment, with a patient, or with an entity acting under a valid authorization.

Applied to a tonsil stone removal workflow:

  • BAA required: EHR host, cloud storage, transcription or ambient documentation vendor, clearinghouse, billing company, patient texting platform, e-fax with retention, IT MSP with system access, offsite shredding, answering service, translation vendor with recorded calls.
  • No BAA required: the ENT you refer to, the surgery center providing treatment, the payer, the patient's own personal cloud account, a courier that only transports sealed packages.
  • Depends: analytics and advertising vendors on your website, review platforms, and any AI tool that processes visit content. Read what the tool actually does with the data before deciding.

HHS maintains plain-language guidance on business associates that settles most edge cases in a paragraph. Print it and keep it with your vendor file.

The Procedure Page Problem: Tracking Technology on High-Intent Content

Your website almost certainly has a page describing tonsil stone removal. It exists because people search for it. It converts because it answers a question people are embarrassed to ask out loud.

Now open that page's source and look at what fires. Advertising pixels, session replay scripts, chat widgets, and heat mapping tools all transmit some combination of IP address, device identifier, and page URL to third parties. OCR published guidance on online tracking technologies that drew litigation and was partially vacated in 2024 as to unauthenticated pages. The legal contours moved. The practical risk did not.

Two things remain true regardless of how that dispute resolves. First, anything behind your patient portal login is unambiguously PHI, and a tracker there requires either a BAA or an authorization. Second, the FTC has enforced against health-adjacent companies for disclosing sensitive browsing data to advertisers under its own authority and the Health Breach Notification Rule, which reaches entities HIPAA does not. A practice that assumes only OCR is watching has misread the enforcement landscape.

What to do this month

Have your web developer produce a written list of every third-party script on the site, with the vendor name and stated data use. Kill anything nobody can justify. For what remains, decide: BAA, or removal from PHI-adjacent pages. Document the decision with a date and a name.

Patient-Submitted Photos Arriving Through the Wrong Door

Patients text photos of their throats. They do it constantly, to whatever number they have, including the direct cell line of a nurse who gave it out in a good-faith moment three years ago.

The patient has every right to send unencrypted information to you. You do not have a corresponding right to store it wherever it lands. Once that image reaches a device you control or a system your practice uses, it is PHI in your custody, subject to your safeguards and your retention schedule.

Write a two-sentence rule and train to it: patient-submitted images are uploaded to the chart and deleted from the receiving device within one business day, and staff direct patients to the portal for future submissions. Assign the deletion verification to a named role — usually the clinical supervisor — and spot-check it quarterly.

A 45-Day BAA Cleanup Sprint

Most practices do not have a vendor problem so much as a documentation problem. The agreements were signed, somewhere, by someone, in a format nobody can locate. Here is a sequence that finishes.

Days 1–7 — Inventory. Privacy officer pulls the last twelve months of accounts payable and flags every line item that could plausibly touch data. Vendors hide in the AP ledger far better than they hide in the IT asset list. Add website scripts and any app installed on a practice device.

Days 8–14 — Classify. Each vendor gets one of three labels: BA, not a BA with a written reason, or unknown pending vendor response. Send a short questionnaire to the unknowns asking exactly one thing — does your service store, transmit, or process our patient information.

Days 15–25 — Paper the gaps. For every confirmed BA without a current signed agreement, issue one. This is the step where practices stall, because pulling a template out of a 2014 folder and adapting it eats an afternoon per vendor. A six-step wizard that produces a signature-ready business associate agreement with PDF and DOCX export moves that afternoon to about ten minutes, and it is a one-time purchase rather than another subscription line on your budget.

Days 26–35 — Subcontractor flow-down. Ask each material BA to identify subcontractors that touch your data and confirm agreements exist downstream. Your transcription vendor's offshore reviewers are your exposure too.

Days 36–45 — File and calendar. One folder, one naming convention, one renewal date per vendor in a shared calendar. Assign the review to a role, not a person, so it survives turnover.

When the Vendor Is the One Who Breaches

A billing vendor's mailbox gets compromised. Three hundred of your patients are in the exposed data set, including the procedure notes from a run of ENT cases.

Your obligations start at discovery. Under the Breach Notification Rule you notify affected individuals without unreasonable delay and no later than 60 days from discovery. Incidents affecting 500 or more individuals go to HHS within that same window and to prominent media in the affected state or jurisdiction; smaller incidents are logged and submitted within 60 days after the end of the calendar year. Every one of those reports becomes visible on the OCR breach portal, which your patients, your referral partners, and plaintiffs' counsel all read.

The default HIPAA deadline for a business associate to notify you is also 60 days. That is far too long. Negotiate a contractual notification window measured in days — 5 or 10 business days is common and achievable — plus an obligation to provide the affected individual list in a usable format and to cooperate with your investigation at their cost. OCR's stronger vendor-verification expectations, signaled in the Security Rule rulemaking that opened in early 2025, point the same direction: assume you will need documented proof of your vendors' safeguards, not assurances.

The detail most templates omit

Specify what happens to the images. A generic BAA covers "protected health information" but says nothing about return or destruction of clinical media at termination. Add a clause requiring certified deletion of image and video files, with written confirmation, within 30 days of contract end.

Start With the Vendor List, Not the Policy Binder

Every tonsil stone removal encounter your practice documents is a small test of whether your vendor paperwork matches your vendor reality. Run the AP ledger this week, classify what you find, and close the agreements that are missing. If your broader risk analysis and policy set are also overdue, automated HIPAA risk analysis and compliance documentation covers that ground without a consulting engagement. Either way, the vendor inventory is the piece that makes the rest of it defensible.