EXPLOREINDUSTRIESGUIDESLEARNGLOSSARYBOOKSWHITEPAPERTOOLSRESOURCESPIONEERMARKETSCOUNTRIESFEESMISSION FUNDPASSPORT
SUPPORTLOGINJOIN THE PROTOCOL →
GETREADYANDJUMP.COM · BUILT IN DETROIT

HIPAA
ON PROTOCOL.

Hipaa on the GRAJ protocol. One fee. 195 countries. Join the protocol.

JOIN THE PROTOCOL →
Compliance

HIPAA FOR
SUPPLIERS.

Reference

HIPAA applies to covered entities and, critically, to the vendors that handle protected health information on their behalf. A supplier who never intended to be in scope becomes a business associate the moment they touch patient data — including in a shipping label.

Business associate is a legal status

If you create, receive, maintain or transmit protected health information for a covered entity, you are a business associate with direct obligations and direct liability. It is not conferred by signing an agreement; the agreement documents a status the activity already created.

The agreement is a prerequisite, not paperwork

A covered entity may not share PHI with you without a business associate agreement in place. It specifies permitted uses, safeguards, breach notification timing and what happens to data when the relationship ends.

The minimum necessary rule

Use and disclose only the smallest amount of PHI needed for the purpose. For a supplier this usually means questioning why patient identifiers are in a dataset at all — the safest PHI is PHI you never received.

Where suppliers get caught

Rarely in the clinical system. Usually in the ordinary edges: a shipping manifest with patient names, a returns process that photographs a label, a support inbox that receives a chart because somebody replied with one.

Where to go next
/guides/healthcare/guides/data-privacy/compliance
JOIN THE PROTOCOL