← Artifact 21 — Vendor & Contract Disposition Matrix Detail Page · Day 1 Gate Register · how to read this suite

Business Associate Agreement Register

Download Word

Sixteen vendors handle protected health information for Cumberland Valley Health Plan. At closing, the covered entity ceases to exist and ACME Health becomes responsible for that information. This register tracks each agreement to executed status as a Day 1 go/no-go gate condition. Owned by L. Braithwaite, Chief Privacy Officer. Status as at September 15, 2023, two weeks before closing.

This is a tracking register, not a contract. The agreements themselves are drafted by counsel against required elements set out in the HIPAA Privacy Rule, and they look substantially alike because the regulation prescribes what they must contain. What the program owns is not the drafting — it is knowing which sixteen exist, which are scoped correctly, and whether every one is executed before the entity changes. That is a program management problem with a compliance failure mode, and it is why this sits on the Day 1 gate rather than in a legal file.

Contents

  1. Why This Is a Gate and Not a Task
  2. What a BAA Must Contain
  3. The Register
  4. Scope Confirmation — Existence Is Not Coverage
  5. Subcontractor Flow-Down
  6. Gate Criteria and Sign-Off

1. Why This Is a Gate and Not a Task

Every item here is administratively trivial: a document, a signature, a countersignature, a tracking row. There is no analysis, no negotiation of substance, no technical difficulty. It is precisely that triviality that makes it dangerous — work with no intellectual content attracts no attention, and gets delegated downward until nobody senior is looking at the completeness of the set.

The failure mode is asymmetric in the worst way. Doing thirteen of sixteen is not 93% of the job; it is a reportable privacy exposure. On the first business day, a vendor is processing member health information for a covered entity it has no agreement with — and the discovery route is an auditor or a breach notification, not a status report. No amount of good work elsewhere on the program offsets it, and the failure is entirely preventable by a checklist.

2. What a BAA Must Contain

The required elements are set by regulation, not by preference. The program does not draft them, but it must be able to confirm they are present, because a BAA missing a required element is not a compliant BAA.

Required elementWhat the program checks for
Permitted uses and disclosuresThe agreement states what the vendor may do with the information — and that it may not do more
Safeguards obligationAppropriate administrative, physical and technical safeguards, including Security Rule obligations for electronic information
Reporting of unauthorized use or disclosureObligation to report, with a defined notification period the program can actually meet downstream
Breach notificationNotification to the covered entity, with timing that leaves room for the covered entity's own obligations
Subcontractor flow-downThe vendor must bind its own subcontractors to equivalent terms — see §5
Access, amendment and accountingVendor must support the covered entity in meeting individual rights requests
Availability to the regulatorRecords made available to the Secretary for compliance review
Return or destruction at terminationWhat happens to the information when the relationship ends — and what happens if return is infeasible
Termination for breachThe covered entity's right to terminate where the vendor breaches a material term
Two of these matter more than the rest for an integration program specifically. Return or destruction at termination becomes live immediately — six vendors in this register are being consolidated away, so the disposition of the information they hold is a real question with a date on it, not a boilerplate clause. And breach notification timing has to be read as a chain: if a vendor has sixty days to tell you, and you have sixty days to tell the individual, you have no time at all. The program checks that the vendor's clock is materially shorter than the covered entity's.

3. The Register

New = a fresh agreement with ACME as covered entity. Amended = existing agreement amended to name the surviving entity. Scope = scope confirmation required beyond mere existence (see §4). Sub = subcontractors in scope.

RefVendor / serviceInstrumentScopeSubStatusNote
BAA-01Pharmacy benefit managementNewYYExecutedMail-order and specialty subcontractors flowed down.
BAA-02Clearinghouse (target)AmendedYExecutedExecuted alongside the run-out consent.
BAA-03Print, mail & member communicationsNewYYExecutedVolume scope raised for the combined mailing population.
BAA-04Care management platform (target)NewYExecuted⚠ This platform is the survivor — scope raised from 420,000 to 2,220,000 members.
BAA-05Care management platform (ACME)ExistingExecutedBeing terminated; return-or-destruction obligation is the live clause.
BAA-06Fraud, waste & abuse analyticsNewYExecutedCombined claim history materially enlarges the data set held.
BAA-07TelehealthNewYExecutedClinician network is subcontracted; flow-down confirmed.
BAA-08Member ID card productionNewYExecutedDay 1 critical — reissue cannot begin without it.
BAA-09Benefits administration (employee)AmendedExecutedEmployee health data, distinct from member data.
BAA-10Language services / translationNewYExecutedInterpreters are subcontracted individuals; flow-down confirmed.
BAA-11Core administration platform vendor (target)AmendedYYExecutedSupport staff access production data through cutover.
BAA-12Quality / HEDIS certified vendorAmendedExecutedRetained through measurement year end.
BAA-13Appeals external review organizationNewYExecutedReviewing physicians are subcontracted; flow-down confirmed.
BAA-14Microsoft AzureExisting — scope confirmedYScope amended⚠ The one that looked finished. See §4.
BAA-15Cheatham Mutual Holdings — TSA providerNew — executed at closingYYExecuted⚠⚠ The divesting parent is a business associate. Under the TSA it hosts the target’s systems and supports its core administration platform — which is PHI handling by a third party. Most easily missed of the sixteen, because nobody files the seller under “vendors.”
BAA-16Rutherford Cloud Operations — co-managed cloud MSPNew — executed with the MSP agreementYYExecuted⚠ Holds administrative access to systems processing PHI. Privileged access is broader than application access, so subcontractor flow-down and audit rights matter more here than for a typical vendor.

Sixteen of sixteen executed. Gate condition satisfied for Day 1.

4. Scope Confirmation — Existence Is Not Coverage

Six agreements required more than a change of party name. A Business Associate Agreement is scoped to the information and the processing it contemplates, and an acquisition changes both.

What changedWhy the existing agreement did not cover it
Population sizeAn agreement contemplating 420,000 members may specify volumes, service levels or liability caps calibrated to that scale
Processing locationWorkloads move to a cloud region the original agreement never named
Data categoriesConsolidated analytics brings together claim, clinical and enrollment data that previously sat apart
RetentionCombined record retention obligations may exceed what the original agreement specified
BAA-14 is the one that looked finished and was not, and it is the most instructive row in the register. ACME held an existing enterprise agreement with an executed BAA, so the platform relationship appeared settled and was very nearly signed off on that basis. But the agreement was scoped to ACME's own membership and its original region footprint — not to a 23% larger population, and not to the paired region the disaster recovery design now writes backups into. An inherited agreement that exists is not the same as an inherited agreement that covers what you are about to do with it, and the only way to find that out is to read it against the target state rather than tick it against a vendor list.

5. Subcontractor Flow-Down

Six vendors in the register use subcontractors who themselves touch protected health information — a mail-order pharmacy, a network of interpreters, a panel of reviewing physicians. Each vendor must bind those subcontractors to terms at least as protective as its own agreement.

The chain is where assurance quietly stops. ACME has a direct agreement with each vendor and no privity at all with the vendor's subcontractors — so the only mechanism holding the far end of the chain is a clause obliging the vendor to pass the terms down. The program's check is therefore not "does the vendor have a BAA with us" but "has the vendor attested that its subcontractors are bound, and can it identify them". A vendor that cannot name its own PHI-handling subcontractors is telling you something about how well it is managing them.

6. Gate Criteria and Sign-Off

CriterionStatus at September 15, 2023
All sixteen executed and countersignedComplete
Scope confirmed against target state, not merely existenceComplete — six amended, including Azure
Subcontractor flow-down attested where applicableComplete — six vendors
Breach notification periods reviewed as a chainComplete
Return or destruction terms confirmed for vendors being terminatedComplete — six vendors
Independent reconciliation against the PHI vendor inventoryComplete — performed by a reviewer other than the register owner
The last row is the control that makes the rest of the register trustworthy. Every other criterion is checked by the person who compiled the list, which means a vendor omitted from the list is also omitted from every check performed against it. Reconciling independently against the PHI vendor inventory is the only step that can catch the failure nobody else can see — a missing row rather than an incomplete one. It costs an hour and it is the difference between a register that proves something and a register that documents an assumption.

Related: 21 — Vendor & Contract Disposition Matrix (parent) · 7 — Due Diligence Findings (DD-04) · 29 — Day 1 Readiness Plan · 30 — Day 1 Go/No-Go