Practice management, imaging, billing, transcription, IT, shredding. Every vendor touching patient data is a business associate, and their weakest control becomes yours.
Ask a practice owner to name their business associates and you'll usually get two answers: the practice management software and the billing company. Then we start walking the building. The imaging vendor with remote access to the sensor workstation. The transcription service. The answering service taking messages with patient names in them. The shredding company. The IT provider. The cloud backup nobody has thought about since it was set up.
Every one of those is a business associate under HIPAA, because every one of them creates, receives, maintains, or transmits protected health information on your behalf. And every one of them is a door into your practice — one you don't personally control, secured by a company whose security you've likely never evaluated.
Attackers have learned it's easier to compromise one vendor serving two hundred practices than to attack two hundred practices individually. When that vendor has remote access into your systems — as imaging and practice management vendors typically do — their breach becomes your incident, with your patients' names on the notification letters.
The regulatory position is uncomfortable but clear: delegating the work does not delegate the responsibility. You remain accountable for the PHI you handed over, and OCR expects you to have exercised due diligence in choosing and documenting those relationships.
This is a one-afternoon exercise that most practices have never done end to end:
A current vendor inventory with signed BAAs feeds directly into your annual security risk assessment and answers a question that now appears on nearly every cyber-insurance questionnaire: do you evaluate the security of third parties with access to your data? Doing the work once produces the documentation three different reviewers will ask for.
Block ninety minutes this month and build the list — every vendor, what data they touch, whether a BAA is signed, and what access they hold. The gaps will be obvious once it's on one page. Our free practice IT assessment includes this vendor and access review, and the findings are yours either way.
Your practice's security is only as strong as the least careful company you've handed patient data to. Knowing who those companies are is the first control — and most practices are one afternoon away from having it.
Our free IT security assessment gives your leadership a plain-English report on your risks, your compliance gaps, and exactly what it would cost to fix them. No obligation, no jargon.