Blog · Compliance

Vendor breaches and why your fax and form tools are business associates

Healthcare has a high rate of third-party incidents. If a vendor holds your PHI, their breach becomes your notification problem.

Covered entities spend years locking down the office network, then send every referral through a fax vendor and every intake through a form tool they never listed as a business associate. Third-party incidents are now a standard headline for a reason.

Inventory the obvious vendors

Email host, cloud fax, online forms, file share, patient chat, billing clearinghouse, transcription, and anyone who remote-supports your EHR. If they can see PHI, they belong on the BA list with a signed agreement and a contact for incident notice.

Fewer pipes, fewer surprises

You cannot eliminate vendors. You can stop adding a new one for every communication type. HIPAA Companion combines healthcare email, secure fax, personalized forms, and encrypted files under one BAA so a privacy officer can answer "who has our PHI?" without a scavenger hunt.

Ask each vendor how they will notify you, how fast, and what evidence they will provide. Put the answers in the same folder as the BAA.