Any vendor that handles PHI on your behalf is a business associate and needs a signed BAA. Work through this before you buy, and confirm specifics against current HHS/OCR guidance.
HIPAA Vendor & BAA Evaluation Checklist
- Will the vendor sign a Business Associate Agreement (BAA)?
- Is PHI encrypted in transit and at rest?
- Does the vendor limit access to the minimum necessary, with audit logs?
- Can it provide a recent independent security report (e.g. SOC 2 Type II)?
- Where is data hosted, and are subcontractors also covered by BAAs?
- How are breaches detected, and what is the notification process and timeline?
- How is your data returned or destroyed if you end the relationship?
- Does it integrate with your EHR/practice-management system securely?
- Is there a pilot to validate both savings and compliance first?
- Have you confirmed the requirements against current HHS/OCR guidance?
From Care Ops Guide · careopsguide.com