The agreements a practice holds are usually real ones, correctly signed. The harder question sits underneath them: which outside parties are touching patient information, and when that list was last true.

The signing is the half that goes well

When a practice thinks about business associate agreements, it thinks about the signing. A vendor sends its form, somebody countersigns, the PDF goes in a folder. That part tends to work. The copies I have seen are real agreements, properly signed, kept where a surveyor could find them.

What sits in the folder is a list of the vendors somebody thought of. The obligation runs to all of them. A correctly executed agreement says nothing about the vendor who has none, because that vendor was never in the room.

Vendors arrive sideways

A practice of about fifty people has no procurement function. A physician finds a tool that saves time and turns it on, the billing lead subscribes to something with a card, and a vendor gets swapped out during a week when three other things are breaking, the replacement picked because it can start on Monday.

Each is a reasonable decision by somebody doing their job, and none of them crosses a desk whose task is to ask whether patient information will be involved. The question comes up at implementation if it comes up at all, and that is the week nobody has a spare hour.

The ones that go missing have a shape

Nobody forgets the EHR vendor or the clearinghouse. Those relationships were negotiated, and the agreement was part of the negotiation. What tends to be absent is smaller and older: the answering service that takes calls overnight and writes down why the patient rang, the shredding company, the IT contractor holding remote access to every workstation, the fax line that now delivers into an email inbox, the storage unit the paper charts went to when the practice ran out of room.

Then the newer ones, missed for a different reason. A scheduling widget on the website. An ambient documentation tool a physician is trying out. A reputation service that was handed names and appointment dates so it could ask people for reviews.

That last kind goes unlisted most reliably, because it does not feel clinical to the person who set it up. It came in through marketing, and nobody involved thinks of themselves as working with patient records. A list of who was seen and when is patient information whatever the vendor's website calls it.

An executed agreement is a contract, not a security review

The agreement allocates obligations. It does not establish that the vendor can meet them. Reading an executed copy tells a practice nothing about where the data sits, who at the vendor can open it, or how that vendor would spend the first day of its own breach. Those get asked somewhere else, or nowhere, because a signed PDF feels like the end of a subject.

Subcontractors carry it further out of sight. The party that signed is frequently not the party physically holding anything, since there is a host underneath and sometimes a team doing part of the work from somewhere else. The obligations are meant to travel down that chain, and a practice is rarely positioned to see past the first link. What it can read is the incident language: who notifies whom and inside what window. Those clauses vary more between agreements than the rest of the document does, and they get opened for the first time on the day they are needed.

The money keeps a better list than the meeting does

These inventories usually get built from memory, in a room, by people naming the vendors they can think of. Memory is the exact mechanism that drops an answering service signed up for a decade ago. Accounts payable is the other route in. Almost every outside party is being paid something, so the vendor ledger and the card statements already hold a version of the list, assembled by a process that cannot forget.

Reading down it with one question against each line, does this vendor see, store, transmit or dispose of patient information, produces a list the meeting would not have. It also turns up line items nobody present recognizes, which in a practice open a couple of decades is a finding of its own. What the ledger cannot show is the free tool that never generated an invoice, and the free ones are the likeliest to have been switched on without a conversation.

Where the operating habit stops

The part I can speak to is operational. Knowing who is out there, keeping the list current, and having a route that catches the next arrival while it is being set up rather than a year afterward. In most practices that is somebody's fourth priority, so it happens in bursts and then goes quiet.

What a particular arrangement requires, whether a given vendor meets the definition at all, and what has to happen in a real incident are questions for a healthcare attorney or a privacy professional reading the actual contracts. Nothing above answers any of that. What it does is shorten the first conversation with them, because the first thing they ask for is the list.

Marina Davar, practice manager and author of Running a Private Medical Practice

About the author. Marina Davar has managed a private medical practice of about fifty people since 2020. She writes here about how the operational side of an independent practice fits together. More about Marina Davar, or her work in healthcare education.