• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Business Associate

Define Your Relationship- Vendor or Business Associate?

March 31, 2016/in Blog, Business Associate, General Compliance

Healthcare organizations have many relationships to manage, including patients, providers, payers, and vendors.  On top of this, some relationships require a Business Associate Agreement (BAA) to comply with HIPAA. In order to determine if such an agreement is necessary, it is crucial to look at each relationship individually in order to provide proper treatment and to act appropriately. The following definitions and examples will simplify the decision making process.

How is a vendor defined and why is this important? All vendors must be screened against the OIG’s List of Excluded Individuals and Entities (LEIE) database in order to determine if the business relationship is legal or whether it must be terminated immediately based on their exclusion from participation in Medicare, Medicaid, and other Federal health care programs.

Your organization may have business relationships with patients, providers, payers and vendors as defined below:

  • Patients refer to individuals who receive medical care from healthcare providers.
  • Providers refer to health care providers that provide services to patients billed to payers.
  • Payers refer to insurance providers that pay providers for patient care.
  • Vendors refer to any entity that provides services and/or products in exchange for a fee, which includes contractors and suppliers.

Obviously, providers and payers are not vendors. However, many organizations find it challenging to determine which vendor relationships require a BAA.

What is a “Business Associate?” A “Business Associate” is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity. A member of the covered entity’s workforce is not a business associate. A covered health care provider, health plan, or health care clearinghouse can be a business associate of another covered entity. The HIPAA Privacy Rule lists some of the functions or activities, as well as the particular services, that make a person or entity a business associate, if the activity or service involves the use or disclosure of protected health information. The types of functions or activities that may make a person or entity a Business Associate include payment or health care operations activities, as well as other functions or activities regulated by the Administrative Simplification Rules.  

Business Associate functions and activities include: claims processing or administration; data analysis, processing or administration; utilization review; quality assurance; billing; benefit management; practice management; and repricing. Business Associate services are: legal; actuarial; accounting; consulting; data aggregation; management; administrative; accreditation; and financial. The definition of a Business Associate is provided in 45 CFR § 160.103 and other helpful information can be found at HHS.gov.

Examples of Business Associates:

  • A third party administrator that assists a health plan with claims processing. 
  • A CPA firm whose accounting services to a health care provider involve access to protected health information. 
  • An attorney whose legal services to a health plan involve access to protected health information. 
  • A consultant that performs utilization reviews for a hospital. 
  • A health care clearinghouse that translates a claim from a non-standard format into a standard transaction on behalf of a health care provider and forwards the processed transaction to a payer. 
  • An independent medical transcriptionist that provides transcription services to a physician. 
  • A pharmacy benefits manager that manages a health plan’s pharmacist network.  

http://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/

 

Making the determination of which entities are Business Associates is not always straightforward and can be confusing. Below are a few good questions we’ve heard repeatedly.

What about the phone company or the internet provider? They could access my patient information, so we need a BAA with them, right?

BAAs are not necessary with certain organizations considered to be mere conduits. Examples are the U.S. Postal Service, some private couriers, telephone companies, and Internet Service Providers. This is because a conduit transports the information, but does not access it.  No disclosure is intended by the covered entity (healthcare provider) and there is low likelihood of disclosure of PHI in these situations.

What about the landlord or the cleaning service? They have access to the office where we keep PHI.

It is unnecessary to have a BAA with the cleaning service because they are not contracted to perform services involving use or disclosure of PHI.  However, you need to have reasonable safeguards in place to protect PHI.  Ideally, you should store paper PHI in a locked cabinet.

Do I need to have a BAA with my accountant? She’s been working with us for years, but isn’t an employee.

It is common to overlook a business associate who has been working with your organization for a long period of time.  However, if an independent contractor is providing services such as accounting or anything that involves PHI, then you must have a BAA in place.

Managing all of the relationships within a healthcare organization can be a daunting task.  If you have additional questions about your obligations related to vendors or business associates please schedule a complimentary demo with our team!

Tags: 1st HCC, business associate, covered entity, First Healthcare Compliance, vendor
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2016/03/iStock_000034130896.jpg 253 380 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2016-03-31 11:00:002025-04-15 12:58:02Define Your Relationship- Vendor or Business Associate?
You might also like
Payment Are You Familiar With the New CMS Payment Model?
pop quiz Compliance with the Hazard Communication Standard
Q&A: HIPAA: A Timely Overview & Update
Business Associate Who are your Business Associates?
pop quiz Does The Sunshine Act Apply To You?
pop quiz Healthcare Compliance Pop Quiz: Test Your Knowledge

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only