Now onboarding Open Dental practices. Apply for the betaApply

For office managers5 min read

Before you connect a phone or AI tool: the BAA questions to ask

When a phone or AI vendor needs a business associate agreement, what HIPAA says it must contain, and ten questions to ask before a patient call reaches it.

A new phone system, an answering service, a voice agent, a call-tracking tool: each one hears your patients say their names, their birthdays and why they are calling. Some of them also keep recordings and transcripts. Before any of that reaches a vendor, HIPAA asks one question of your practice: does this vendor need a business associate agreement, and if it does, is the one you are signing complete?

Who needs a BAA, and who does not

A business associate is a person or company that creates, receives, keeps or sends protected health information on your behalf. The HIPAA rules require the assurances you get from it to be in writing, which is the business associate agreement 1. There is one narrow exception, the “conduit”: a service that only transmits information and does not access it other than on a random or infrequent basis, like the postal service or a phone carrier 1, 2.

For phones, HHS has drawn the line in its guidance on audio-only telehealth. A telecommunications carrier that only connects the call has transient access and needs no BAA. A vendor that stores information from the call, such as recordings or transcripts, is a business associate and does 2. Storage is what moves a vendor across the line. HHS says the same about cloud services: a provider that stores protected health information is a business associate even when it holds the data encrypted and never has the key 3.

  • Usually a conduit: your phone carrier, when it only routes calls.
  • Usually a business associate: an answering service that takes messages, a voice agent that keeps transcripts, a call-recording or call-tracking tool, anything that reads your practice management system.
  • Ask, do not assume: a phone system with voicemail transcription, call recording or analytics switched on is storing call content.

What the agreement itself must contain

The HIPAA Privacy Rule lists what a business associate contract has to say 4. HHS publishes sample provisions that follow the same list 5. In plain terms, the agreement must:

  • Say what the vendor may and may not do with your patients’ information.
  • Require it to use appropriate safeguards and follow the HIPAA Security Rule for electronic information.
  • Require it to report any use or disclosure the contract does not allow, including breaches.
  • Require it to pass the same restrictions down to any subcontractor that handles the information.
  • Require it to help you meet patients’ rights, such as a request for access to their records.
  • Require it to return or destroy the information when the relationship ends, where that is feasible.
Six vendor questionsBefore you connectSigns a BAANames its subcontractorsEncrypts stored dataStates breach notice timingLimits staff accessReturns data at exit
Six things to see in writing before you connect a vendor. The full list of ten questions follows.

Ten questions to ask before any call reaches it

  1. Will you sign a BAA with us, and may we read it before we sign anything else? A vendor that stores call content and hesitates here has answered the question.
  2. Exactly what do you store, and for how long? Audio, transcripts, caller numbers, message text, data read from our practice management system. Ask for retention periods in writing.
  3. Which subcontractors touch our patients’ information, and do they each have a BAA with you? The chain matters as much as the first link 4.
  4. Where is the information stored? Ask for the country and the service, not a marketing phrase.
  5. Who at your company can see or hear our patients’ calls, and is that access logged? The minimum-necessary standard asks covered entities and their business associates to limit use to what the task needs 6.
  6. What do you read from our practice management system, and what do you never read? Scheduling needs appointments, operatories and providers. It does not need clinical notes, imaging or ledgers.
  7. What does the contract say about breach notice, and how fast? HIPAA’s outer limit for a business associate to tell you is 60 calendar days after discovery 7. A contract can set a shorter period. Read the number in the contract, not the brochure.
  8. How do we get our data back, or deleted, when we leave? Ask for the format and the timeline.
  9. Is the call announced to the caller? If the vendor records or transcribes, what does the caller hear first, and who wrote it?
  10. What independent security review have you completed? Ask for the report or the honest answer. A vendor that says “none yet” is telling you something useful; a badge on a website is not an agreement.

Your side of the agreement

A BAA does not move your obligations to the vendor. The HIPAA Security Rule requires your practice to carry out an accurate and thorough assessment of the risks to the electronic health information you hold 8. When you add a vendor that receives calls or connects to your practice management system, add it to that risk analysis: what it receives, where it goes, who can reach it and what happens if it is lost. Keep the signed BAA with the analysis, and set a date to review both.

The software you already use sets an example here. Open Dental’s own API documentation tells developers that they should have a business associate agreement in place with the practices they serve 9. If a vendor asks for an API key to your Open Dental database, that sentence is your first question.

Red flags worth a second meeting

  • The vendor sends a BAA only after you sign the main contract, or asks you to start with “test calls” from real patients before one is signed.
  • The BAA is silent on subcontractors, or the vendor cannot name them.
  • Retention is “as long as needed” with no number.
  • Access to recordings is described in adjectives rather than roles and logs.
  • The security page lists badges but the vendor cannot send the report behind them.

Sources

Every number and every rule in this post comes from one of these. Links open the source itself.

  1. Business associates. US Department of Health and Human Services, Office for Civil Rights.
  2. Guidance on how the HIPAA rules permit covered health care providers and health plans to use remote communication technologies for audio-only telehealth. US Department of Health and Human Services, Office for Civil Rights, 2022.
  3. Guidance on HIPAA and cloud computing. US Department of Health and Human Services, Office for Civil Rights.
  4. 45 CFR 164.504(e): business associate contracts. Electronic Code of Federal Regulations.
  5. Sample business associate agreement provisions. US Department of Health and Human Services, Office for Civil Rights, 2013.
  6. Minimum necessary requirement. US Department of Health and Human Services, Office for Civil Rights.
  7. 45 CFR 164.410: notification by a business associate. Electronic Code of Federal Regulations.
  8. Guidance on risk analysis. US Department of Health and Human Services, Office for Civil Rights.
  9. API specification. Open Dental Software.

← All posts