The vendors behind the service, and what binds them
No health service runs on its own infrastructure alone. Hosting, email delivery, scheduling and payment all involve third parties, and each one that touches protected health information has to be contractually bound before it does. That contract is the business associate agreement, and it is the least visible but most load-bearing part of the privacy story.
The chain
Who is in the picture, and what they see
Not every vendor sees clinical content. The design principle is that each one is given the narrowest slice needed to do its job — which is the minimum necessary rule applied to infrastructure rather than to disclosures.
Hosting and storage
Holds the record at rest. Sees encrypted data, operates under contract, and cannot use it for any purpose of its own.
Secure document delivery
Transmits the letter to the address you nominate. Handles the document but has no reason to retain clinical content.
Telehealth platform
Carries the consultation where one is needed. Bound to equivalent safeguards, including on recording.
Payment processing
Sees the transaction, not the reason for it. Card data is handled by the processor and is not stored alongside your intake.
Website analytics
Aggregate traffic patterns. Analytics tooling has no business inside authenticated clinical areas and is kept out of them.
What a BAA actually requires
- Use the information only for the contracted purpose
- Apply safeguards equivalent to the covered entity’s own
- Report security incidents and breaches promptly
- Bind any subcontractors to the same terms
- Return or destroy the data when the contract ends
- Make records available for compliance review
Why it matters to you
A vendor without a BAA is not merely an administrative gap. It means health information has been handed to a party under no obligation to protect it, and that disclosure is itself a violation regardless of whether anything subsequently goes wrong.
Since 2013 business associates have been directly liable under the Security Rule, so the obligation does not stop at the contract — a vendor can be penalised in its own right.
You are entitled to ask
You can ask any health provider which categories of vendor handle your information and whether business associate agreements are in place. A provider that cannot answer that question clearly has told you something useful. A reasonable answer names the categories — hosting, delivery, telehealth — and confirms the agreements exist, without necessarily naming every commercial supplier.
Frequently asked
What is a business associate?
Any third party that creates, receives, maintains or transmits protected health information on behalf of a covered entity — hosting providers, secure delivery services and telehealth platforms are typical examples.
Does my payment processor see my health information?
No. Payment records cover the transaction and are held separately from clinical content. The processor knows a payment occurred, not what the evaluation concluded.
Are business associates liable if they cause a breach?
Yes. Since the 2013 Omnibus Rule they are directly liable under the Security Rule and can face penalties independently of the covered entity.
Can I find out which vendors hold my data?
You can ask, and a reasonable answer identifies the categories of vendor and confirms that agreements are in place. Naming every commercial supplier is not usually required.
What happens to my data when a vendor contract ends?
A compliant BAA requires the data to be returned or destroyed at termination, and requires subcontractors to be bound by the same obligation.
Is website analytics a HIPAA problem?
It can be, if analytics tooling is placed inside authenticated areas where it can observe health information. Keeping it out of those areas is the standard mitigation.
Your privacy is not an afterthought here
Start a free evaluation and see exactly what your landlord will — and will not — receive.
Start free evaluation All privacy topics