Insights · Medical & Dental

Your practice has more business associates than you think — and each one is a door

Practice management, imaging, billing, transcription, IT, shredding. Every vendor touching patient data is a business associate, and their weakest control becomes yours.

By Andrew · NextGen Strategy PartnersAugust 10, 20265 min read

Ask a practice owner to name their business associates and you'll usually get two answers: the practice management software and the billing company. Then we start walking the building. The imaging vendor with remote access to the sensor workstation. The transcription service. The answering service taking messages with patient names in them. The shredding company. The IT provider. The cloud backup nobody has thought about since it was set up.

Every one of those is a business associate under HIPAA, because every one of them creates, receives, maintains, or transmits protected health information on your behalf. And every one of them is a door into your practice — one you don't personally control, secured by a company whose security you've likely never evaluated.

Why this is the risk that catches practices off guard

Attackers have learned it's easier to compromise one vendor serving two hundred practices than to attack two hundred practices individually. When that vendor has remote access into your systems — as imaging and practice management vendors typically do — their breach becomes your incident, with your patients' names on the notification letters.

The regulatory position is uncomfortable but clear: delegating the work does not delegate the responsibility. You remain accountable for the PHI you handed over, and OCR expects you to have exercised due diligence in choosing and documenting those relationships.

You can outsource the function. You cannot outsource the obligation — or the breach notification letters that carry your practice's name.

Build the list, then close the gaps

This is a one-afternoon exercise that most practices have never done end to end:

Where this shows up later

A current vendor inventory with signed BAAs feeds directly into your annual security risk assessment and answers a question that now appears on nearly every cyber-insurance questionnaire: do you evaluate the security of third parties with access to your data? Doing the work once produces the documentation three different reviewers will ask for.

The practical takeaway

Block ninety minutes this month and build the list — every vendor, what data they touch, whether a BAA is signed, and what access they hold. The gaps will be obvious once it's on one page. Our free practice IT assessment includes this vendor and access review, and the findings are yours either way.

Your practice's security is only as strong as the least careful company you've handed patient data to. Knowing who those companies are is the first control — and most practices are one afternoon away from having it.

Andrew, founder of NextGen Strategy Partners

Andrew — Founder, NextGen Strategy Partners

Veteran-owned managed IT for the nonprofits, schools, behavioral health providers, and medical & dental practices of McHenry & Lake Counties. Request a free security assessment →

Find out where you stand — before someone else does.

Our free IT security assessment gives your leadership a plain-English report on your risks, your compliance gaps, and exactly what it would cost to fix them. No obligation, no jargon.

Request the free assessment