- What is HIPAA vendor management?
- The set of things you have to do about every organization outside your own that creates, receives, maintains or transmits protected health information on your behalf. In practice it is four obligations: knowing which vendors those are, having a business associate agreement with each, checking none of them is federally excluded, and keeping both facts current as vendors and contracts change. It is not a single document — it is a register that stays true.
- Which vendors need a BAA?
- Any business associate: a person or entity that creates, receives, maintains or transmits protected health information to perform a function or activity on behalf of a covered entity. That catches the obvious ones — billing, EHR, cloud storage, transcription — and routinely misses the ones that matter: IT providers with administrative access, shredding companies, answering services, email and file-sharing platforms, and anyone doing analytics. The test is access, not intent. A vendor that could see the data needs an agreement even if it never looks.
- Do vendors of vendors need agreements too?
- Yes. A subcontractor that creates, receives, maintains or transmits protected health information on behalf of a business associate is itself a business associate, and 45 CFR 164.502(e)(1)(ii) requires the business associate to obtain satisfactory assurances from it. That is why a mature vendor register records not just your direct vendors but which subprocessors sit behind them — and why a client asking you for a subprocessor list is asking a reasonable question.
- How often should vendor agreements be reviewed?
- The rule sets no interval, which is why this is the control that decays quietly. Annual review of the whole register is the defensible convention, with three event triggers that do not wait for it: a new vendor, a vendor changing what it does for you, and a vendor's own breach notification. Exclusion screening is the exception with a real cadence attached — monthly is the widely applied standard, because the federal lists are republished monthly.
- What happens if a vendor has no BAA?
- Disclosing protected health information to a business associate without satisfactory assurances in place is itself an impermissible disclosure — the failure is yours, not only theirs, and it does not require the vendor to have done anything wrong. OCR has taken enforcement action over missing agreements alone. The practical remedy is to find them before someone else does: the gap is nearly always a vendor onboarded quickly by somebody who did not know the rule applied.