Hipaa on the GRAJ protocol. One fee. 195 countries. Join the protocol.
HIPAA applies to covered entities and, critically, to the vendors that handle protected health information on their behalf. A supplier who never intended to be in scope becomes a business associate the moment they touch patient data — including in a shipping label.
If you create, receive, maintain or transmit protected health information for a covered entity, you are a business associate with direct obligations and direct liability. It is not conferred by signing an agreement; the agreement documents a status the activity already created.
A covered entity may not share PHI with you without a business associate agreement in place. It specifies permitted uses, safeguards, breach notification timing and what happens to data when the relationship ends.
Use and disclose only the smallest amount of PHI needed for the purpose. For a supplier this usually means questioning why patient identifiers are in a dataset at all — the safest PHI is PHI you never received.
Rarely in the clinical system. Usually in the ordinary edges: a shipping manifest with patient names, a returns process that photographs a label, a support inbox that receives a chart because somebody replied with one.