Every IT vendor touching patient data needs a BAA
Under HIPAA, any organization that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity must sign a Business Associate Agreement. For Arizona medical practices, that includes your MSP, your cloud hosting provider, your EHR vendor, your billing service, your email provider, and potentially your shredding company.
If a vendor with access to PHI experiences a breach and there’s no BAA in place, your practice is liable under both HIPAA and Arizona’s ARS 18-552. The OCR has settled multiple cases specifically because practices failed to execute BAAs with their IT vendors.
What a BAA must include
- Description of the permitted uses and disclosures of PHI
- Requirement that the BA will not use or disclose PHI except as permitted
- Requirement to implement appropriate safeguards
- Requirement to report breaches of unsecured PHI
- Requirement to ensure any subcontractors also sign BAAs
- Requirement to make PHI available for patient access requests
- Requirement to make records available to HHS for compliance investigations
- Requirement to return or destroy PHI at contract termination
Red flags from IT vendors
Watch out for these warning signs:
- “We don’t sign BAAs” means they either don’t understand HIPAA or aren’t confident in their security. Either way, don’t give them access to PHI.
- Generic BAA templates that don’t reference your specific services are better than nothing but should be customized.
- No SOC 2 or HIPAA compliance documentation to back up their BAA commitments.
- Resistance to security questionnaires about how they protect your data.
Evaluating IT vendor compliance
Before signing a BAA with any IT vendor, ask:
- Do you have SOC 2 Type II certification?
- Can you provide documentation of your security controls?
- How do you encrypt PHI at rest and in transit?
- What is your breach notification timeline?
- Do your subcontractors also have BAAs in place?
- What happens to our data if we terminate the relationship?
A qualified HIPAA-compliant IT provider will answer all of these without hesitation and provide documentation to support their claims.
Getting your vendor agreements in order
Asteroid IT provides HIPAA-compliant IT support for Arizona medical practices, including BAA execution with all subcontractors. We serve practices across Chandler, Gilbert, and the East Valley.
Call us at 480-937-7021 or schedule a conversation.
