CompyMax

HIPAA vendor management

Four obligations, not one. Most organizations do the second — get the agreements signed — and treat that as the programme. The other three are where the findings come from: not knowing who the vendors are, never screening them, and letting the register go quietly out of date until somebody asks to see it.

Last reviewed .

The four obligations, in order

01

Identify who is actually a business associate

45 CFR 160.103

The definition turns on whether the vendor creates, receives, maintains or transmits protected health information on your behalf — including anyone who merely maintains it, which is what brings in cloud hosting and IT providers with administrative access. Start from your systems inventory rather than your accounts-payable list: the question is who can reach the data, and the answer is rarely the same as who invoices you.

02

Get an agreement with the required provisions

45 CFR 164.504(e) and 164.314(a)

A business associate agreement is not a formality with a signature block. The Privacy Rule specifies the provisions it must contain — permitted uses, safeguards, reporting, subcontractor flow-down, return or destruction at termination — and the Security Rule adds its own required terms for electronic information. A vendor's standard addendum usually covers these; an agreement drafted from a template found online frequently does not.

03

Check nobody in the chain is excluded

42 USC 1320a-7 and 42 CFR 1001.1901

Federal health care programmes will not pay for items or services furnished, ordered or prescribed by an excluded person or entity, and that prohibition reaches contractors and vendors, not only employees. The OIG List of Excluded Individuals and Entities is published monthly and free. This is the obligation most small organizations have never heard of, and it is the one with money attached rather than a penalty.

04

Keep it current, and keep the evidence

45 CFR 164.316(b)(2)(i)

Agreements expire, vendors get acquired, services change scope, and the person who signed leaves. Documentation must be retained for six years from creation or from when it was last in effect, whichever is later — so a superseded agreement is not rubbish, it is a record you are required to still have in 2032. A register that only holds the current version has already destroyed part of what it exists to prove.

What a vendor register has to record

A list of company names is not a register. The columns below are the ones that get asked for — by a client’s security questionnaire, and by anyone reviewing you after an incident.

  • What data they touch, and how

    Which systems, which categories of information, and whether they store it or merely pass it through. This is the column that decides how much the rest matters.

  • Agreement status and dates

    Signed by whom, on what date, effective until when, and where the executed copy lives. Plus every superseded version, for six years.

  • Subprocessors behind them

    Who your vendor's vendors are, because 45 CFR 164.502(e)(1)(ii) pushes the obligation down the chain and your client will ask you for this list.

  • Last exclusion check

    The date screened and the result, per vendor. A screening programme with no dated results is indistinguishable from no screening programme.

  • Owner and review date

    The named person responsible, and when it is next looked at. Registers do not rot for lack of a template — they rot for lack of an owner.

A spreadsheet holds all of those columns perfectly well, and for a handful of vendors it is the right tool. What it does not do is tell you that three agreements lapsed last month — which is where registers usually fail.

If you are a business associate yourself

Billing companies, MSPs and healthcare software vendors sit in the middle of the chain and carry both halves of this: you owe your clients the assurances in your own agreements, and you owe the same diligence to everything you subcontract. The register that satisfies your obligation is also the artefact your clients keep asking you to produce — so building it once for both purposes is the only version of this work that is not done twice.

For billing and RCM companies →For MSPs →

Common questions

What is HIPAA vendor management?
The set of things you have to do about every organization outside your own that creates, receives, maintains or transmits protected health information on your behalf. In practice it is four obligations: knowing which vendors those are, having a business associate agreement with each, checking none of them is federally excluded, and keeping both facts current as vendors and contracts change. It is not a single document — it is a register that stays true.
Which vendors need a BAA?
Any business associate: a person or entity that creates, receives, maintains or transmits protected health information to perform a function or activity on behalf of a covered entity. That catches the obvious ones — billing, EHR, cloud storage, transcription — and routinely misses the ones that matter: IT providers with administrative access, shredding companies, answering services, email and file-sharing platforms, and anyone doing analytics. The test is access, not intent. A vendor that could see the data needs an agreement even if it never looks.
Do vendors of vendors need agreements too?
Yes. A subcontractor that creates, receives, maintains or transmits protected health information on behalf of a business associate is itself a business associate, and 45 CFR 164.502(e)(1)(ii) requires the business associate to obtain satisfactory assurances from it. That is why a mature vendor register records not just your direct vendors but which subprocessors sit behind them — and why a client asking you for a subprocessor list is asking a reasonable question.
How often should vendor agreements be reviewed?
The rule sets no interval, which is why this is the control that decays quietly. Annual review of the whole register is the defensible convention, with three event triggers that do not wait for it: a new vendor, a vendor changing what it does for you, and a vendor's own breach notification. Exclusion screening is the exception with a real cadence attached — monthly is the widely applied standard, because the federal lists are republished monthly.
What happens if a vendor has no BAA?
Disclosing protected health information to a business associate without satisfactory assurances in place is itself an impermissible disclosure — the failure is yours, not only theirs, and it does not require the vendor to have done anything wrong. OCR has taken enforcement action over missing agreements alone. The practical remedy is to find them before someone else does: the gap is nearly always a vendor onboarded quickly by somebody who did not know the rule applied.

A register that stays true without anyone remembering.

Track who touches patient data, what is signed and when it expires, screen every vendor against the OIG list monthly, and keep the superseded versions the retention rule requires. 14 days free, no credit card, no sales call.

Need an agreement to start from? Free BAA template generator →

Informational only, based on the published text of 45 CFR Parts 160 and 164 and the exclusion authorities at 42 USC 1320a-7 and 42 CFR Part 1001. This is not legal advice — a business associate agreement is a contract, and the version you sign should be reviewed by counsel. No organization or product can be “HIPAA certified” — no such designation exists. See our editorial standards.