Count the organizations that touch a single Winlevi prescription between the exam room and the pharmacy counter. Your EHR vendor. The e-prescribing network that routes the script. The payer or PBM that rejects it. The prior authorization vendor your medical assistant logs into. The pharmacy. The manufacturer's copay assistance program, if your front desk helps the patient enroll. That is six outside entities, and your practice has a written agreement with maybe three of them.

This post is about that gap. It is not about the drug, the diagnosis, or whether any patient should be on it. It is about who holds the record afterward, which of those relationships legally requires a Business Associate Agreement, which requires a signed patient authorization instead, and what your office manager needs to do in the next 90 days.

Six Organizations Touch a Winlevi Prescription Before the Patient Opens the Tube

Branded topical prescriptions with no generic equivalent tend to generate administrative traffic. They frequently sit off-formulary or in a high tier, which triggers prior authorization. They often route through specialty or mail-order channels. Manufacturers run savings and enrollment programs to close the affordability gap. None of that is clinical guidance — it is simply why the paperwork moves the way it does.

Every one of those steps generates a data disclosure from your practice. Map them:

  • Your EHR and e-prescribing route. The script leaves your system through an intermediary network that touches patient name, date of birth, drug, and prescriber.
  • The prior authorization submission. Your staff enters diagnosis codes, prior therapies, and clinical justification into a payer portal or a third-party PA platform.
  • The payer or PBM adjudication. Standard payment activity.
  • The dispensing pharmacy. Treatment disclosure.
  • The manufacturer copay or hub program. An enrollment form, sometimes faxed by your staff, sometimes containing the patient's insurance details and prescription information.
  • Your patient communication vendor. The text message telling the patient the PA was approved.

Four of those six require something in writing from you. The requirements are not the same document.

Which Winlevi Data Recipients Are Business Associates and Which Are Not

The distinction matters because a BAA does not fix a relationship that never qualified as a business associate relationship in the first place. Sending a BAA to a party that is not a business associate does not make the disclosure lawful. HHS keeps the definitional guidance at its business associates page, and the sample contract provisions at the sample BAA provisions page.

Business associates — BAA required before any PHI moves

  • Your EHR vendor and any hosting or backup provider holding the chart
  • The e-prescribing intermediary, unless it is functioning purely as a conduit — most are not, because they retain data
  • Third-party prior authorization platforms and clearinghouses
  • Your billing company, coding contractor, and transcription service
  • Your outsourced IT provider, if it can access systems containing PHI
  • Patient texting, reminder, recall, and portal vendors
  • Document shredding, scanning, and release-of-information vendors

Not business associates — no BAA, different rules apply

  • The health plan or PBM. A covered entity in its own right. Disclosure for payment is permitted without a BAA.
  • The dispensing pharmacy. Also a covered entity. Treatment disclosures are permitted.
  • The drug manufacturer's copay or savings program. Generally neither a covered entity nor your business associate. It is not performing a function on your behalf. It is a commercial third party.
  • The patient's own phone, personal email, or consumer app, when the patient directs the disclosure.

Do you need a BAA with a drug manufacturer's copay assistance program?

Usually no. A manufacturer savings or hub program is not performing a covered function on your behalf, so it is not a business associate. If your staff transmits patient information to that program, you need a valid HIPAA authorization signed by the patient under 45 CFR 164.508 — or the patient must submit the enrollment themselves. A BAA is the wrong instrument here and offers you no defense.

The Enrollment Form Problem: When Your Front Desk Becomes the Discloser

Here is the failure mode I see most often in dermatology and primary care offices handling branded topicals like Winlevi. A patient says the copay is too high. Your medical assistant, being helpful, pulls up the manufacturer's enrollment page, fills in the patient's name, DOB, insurance ID, and prescription details, and submits it. The patient never signs anything.

That is a disclosure of PHI by your practice to a non-covered third party for a purpose that is not treatment, payment, or health care operations. It requires a written authorization. Your staff did not obtain one, and your practice — not the manufacturer — owns the violation.

The fix is procedural and cheap. Build a one-page authorization into the workflow and require it before any staff member transmits data to a manufacturer, foundation, or assistance program. A valid authorization must include:

  1. A specific description of the information to be disclosed
  2. The name of the person or class of persons authorized to make the disclosure (your practice)
  3. The name of the recipient (the specific program, not "assistance programs")
  4. The purpose of the disclosure
  5. An expiration date or event
  6. The patient's signature and date
  7. A statement of the right to revoke, and how
  8. A statement that information disclosed may be redisclosed by the recipient and no longer protected by HIPAA

That last element is not boilerplate. It is the honest disclosure that once the data reaches a manufacturer program, HIPAA no longer governs it. Marketing use, data brokerage, and downstream sharing become contract and FTC questions, not HIPAA questions.

Alternatively — and this is the cleaner answer — hand the patient the enrollment link and let them submit it. No disclosure by your practice, no authorization needed, no exposure. Document that you provided the resource.

Photo Intake, Teledermatology, and the Vendor You Forgot to Paper

Conditions treated with topical prescriptions are visually assessed, which means images. Images taken on a staff phone, uploaded to a photo intake app, attached to a teledermatology consult, or emailed by the patient to a front-desk address.

Every one of those paths involves a vendor. Ask three questions about each:

  • Does the vendor retain a copy? If yes, it is almost certainly a business associate.
  • Do you have a current, signed BAA on file? Not an emailed PDF someone remembers seeing. A signed document your privacy officer can produce in under five minutes.
  • Does the image sit on a device you do not control? A photo in a staff member's camera roll is unencrypted PHI on personal hardware.

Consumer apps that patients use on their own are outside HIPAA, but they are not outside regulation. The FTC's Health Breach Notification Rule reaches health apps and connected devices that are not HIPAA-covered. If your practice recommends or white-labels such a tool, understand which regime applies before you put your logo on it.

If your BAA file has holes — and most practices that actually audit find at least three — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription, which matters when you need to paper four vendors this month and none next month.

Many practices publish a patient-resources page listing manufacturer savings programs. Reasonable. But if that page carries third-party analytics or advertising pixels, and a visitor's activity on a page tied to a specific condition or medication is transmitted to an ad platform along with an IP address, you have a disclosure question.

OCR issued guidance on online tracking technologies, portions of which were vacated by a federal court in Texas in 2024. The legal boundary for unauthenticated public pages is genuinely contested. The operational answer is not: inventory the tags running on your site, know what each one transmits, and get a BAA from any analytics vendor that receives identifiable data — or remove the tag from condition-specific pages.

A 90-Day Cleanup Plan With Names Attached

Vague intentions do not survive contact with a busy schedule. Assign these.

Days 1–14: Inventory (Practice Manager)

Pull every vendor that could touch PHI. Sources: the accounts payable ledger, the browser bookmarks bar on every workstation, the list of systems your MA logs into during a prior authorization, and the shredding pickup schedule. Expect the AP ledger alone to surface vendors nobody on the compliance side knew about.

Days 15–30: Classify (Privacy Officer)

Sort each vendor into business associate, covered entity, or third party requiring authorization. Note who retains data and for how long. For anything ambiguous, the deciding question is whether the vendor creates, receives, maintains, or transmits PHI on your behalf.

Days 31–60: Paper the gaps (Privacy Officer + Practice Manager)

Execute BAAs for every business associate lacking one. Confirm each agreement addresses subcontractors, breach notification timing, return or destruction at termination, and the vendor's own safeguard obligations. Store signed copies in one location with an expiration and review date. NIST's SP 800-66 Revision 2 is a practical reference for mapping Security Rule requirements to actual controls, including the ones your vendors are supposed to hold up.

Days 61–75: Fix the authorization workflow (Front Desk Lead)

Build the assistance-program authorization form. Train every person who touches enrollment paperwork. Add a hard stop: no submission to a manufacturer program without either a signed authorization scanned to the chart or documentation that the patient submitted it themselves.

Days 76–90: Test and document (Privacy Officer)

Walk one real prescription end to end. At each handoff, ask: what left, to whom, under what authority, and where is the paper? Then update your risk analysis to reflect the vendors you found. If your risk analysis is a spreadsheet somebody built in 2021, tooling that automates the risk analysis and supporting policy set will get you current faster than a weekend of copy-paste.

Why This Costs More Than the Time It Takes to Fix

Browse the HHS breach portal and filter for business associate involvement. The pattern is consistent: a vendor breach becomes the covered entity's notification obligation, the covered entity's press coverage, and the covered entity's OCR correspondence. Your patients do not know the name of your prior authorization platform. They know yours.

OCR investigations of vendor-linked breaches routinely ask two questions early: produce the BAA, and produce the risk analysis that accounted for that vendor. A practice that can answer both in a day is in a different posture than one that spends three weeks reconstructing who signed what.

A branded topical acne prescription is an ordinary, low-drama encounter. That is exactly why it is a good audit subject — if the data trail behind something routine is undocumented, the trail behind everything else is worse.

Start With the Vendors You Cannot Paper Today

Pull your vendor list this week. Mark every row where you cannot produce a signed BAA in five minutes. For those rows, build and export a signature-ready agreement and get it in front of the vendor before the next prior authorization goes out. For the manufacturer programs, build the authorization form instead — the BAA was never the right tool there, and using it will not protect you.