<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
     xmlns:georss="http://www.georss.org/georss"
     xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
     xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[BAA - Szura & Delonis, PLC]]></title>
        <atom:link href="https://www.szuradelonis.com/blog/tags/baa/feed/" rel="self" type="application/rss+xml" />
        <link>https://www.szuradelonis.com/blog/tags/baa/</link>
        <description><![CDATA[Szura & Delonis, PLC's Website]]></description>
        <lastBuildDate>Mon, 11 May 2026 19:07:51 GMT</lastBuildDate>
        
        <language>en-us</language>
        
            <item>
                <title><![CDATA[Do I Need a Business Associate Agreement for This Vendor? A HIPAA Guide for Michigan Healthcare Providers]]></title>
                <link>https://www.szuradelonis.com/blog/do-i-need-a-business-associate-agreement-for-this-vendor-a-hipaa-guide-for-michigan-healthcare-providers/</link>
                <guid isPermaLink="true">https://www.szuradelonis.com/blog/do-i-need-a-business-associate-agreement-for-this-vendor-a-hipaa-guide-for-michigan-healthcare-providers/</guid>
                <dc:creator><![CDATA[Szura & Delonis, PLC]]></dc:creator>
                <pubDate>Mon, 11 May 2026 19:07:50 GMT</pubDate>
                
                    <category><![CDATA[Uncategorized]]></category>
                
                
                    <category><![CDATA[BAA]]></category>
                
                    <category><![CDATA[compliance]]></category>
                
                    <category><![CDATA[HIPAA]]></category>
                
                    <category><![CDATA[phi]]></category>
                
                    <category><![CDATA[private health information]]></category>
                
                
                
                    <media:thumbnail url="https://szuradelonis-com.justia.site/wp-content/uploads/sites/1370/2026/05/Healthcare-IT-photo.jpg" />
                
                <description><![CDATA[<p>Navigating HIPAA compliance doesn’t have to be overwhelming. At Szura & Delonis, PLC, we help Michigan healthcare practices determine when a Business Associate Agreement (BAA) is required to protect PHI and avoid penalties. What Triggers a BAA Requirement? Covered entities—such as health plans, clearinghouses, and providers transmitting health info electronically—must execute a BAA before sharing&hellip;</p>
]]></description>
                <content:encoded><![CDATA[
<p></p>



<p>Navigating HIPAA compliance doesn’t have to be overwhelming. At Szura & Delonis, PLC, we help Michigan healthcare practices determine when a Business Associate Agreement (BAA) is required to protect PHI and avoid penalties.</p>



<p><strong>What Triggers a BAA Requirement?</strong></p>



<p>Covered entities—such as health plans, clearinghouses, and providers transmitting health info electronically—must execute a BAA before sharing protected health information (PHI) with vendors who create, receive, maintain, or transmit it on their behalf. This may apply to technical suppliers accessing PHI databases, record storage facilities, lawyers, accountants, consultants, and temporary agencies placing staff near PHI.</p>



<p><strong>Key Examples: BAA Needed vs. Not Needed</strong></p>



<p>Use this table to quickly assess your vendor.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Vendor Type</strong></td><td><strong>BAA Required?</strong></td><td><strong>Reason&nbsp;</strong></td></tr></thead><tbody><tr><td>Cloud storage for patient records</td><td>Yes</td><td>Maintains PHI</td></tr><tr><td>IT support accessing ePHI systems</td><td>Yes</td><td>Transmits/creates PHI</td></tr><tr><td>Billing service handling claims</td><td>Yes</td><td>Processes PHI</td></tr><tr><td>Janitorial staff</td><td>No</td><td>No PHI access</td></tr><tr><td>Orthotics manufacturer (non-provider)</td><td>Sometimes</td><td>If accessing PHI&nbsp;</td></tr><tr><td>Accreditation organization</td><td>Yes</td><td>Accesses PHI&nbsp;</td></tr></tbody></table></figure>



<p>Business associates must also secure BAAs from their subcontractors handling PHI.</p>



<p><strong>Essential BAA Components</strong></p>



<p>A compliant BAA defines permitted PHI uses, mandates HIPAA Security Rule safeguards (encryption, access controls), requires breach reporting, and ensures PHI destruction upon termination. Limit PHI to the minimum necessary and review annually or with service changes.</p>



<p><strong>Risks of Skipping a BAA</strong></p>



<p>Failing to obtain a required BAA risks OCR fines up to $1,919,173 per violation, plus breach liability. Even vendors without PHI access don’t need one, but over-applying BAAs isn’t harmful—though due diligence on compliance is key.</p>



<p>Government guidance on HIPAA rules and BAAs is available at:</p>



<ul class="wp-block-list">
<li><strong>HHS HIPAA Portal</strong>: <a href="https://www.hhs.gov/hipaa/index.html" target="_blank" rel="noreferrer noopener">https://www.hhs.gov/hipaa/index.html</a>.</li>



<li><strong>HHS OCR BAA Guidance</strong>: <a href="https://www.hhs.gov/hipaa/for-professionals/covered-entities/hipaa-business-associate-agreements/index.html" target="_blank" rel="noreferrer noopener">https://www.hhs.gov/hipaa/for-professionals/covered-entities/hipaa-business-associate-agreements/index.html</a>.</li>
</ul>



<p><strong>Next Steps for Compliance</strong></p>



<p>Inventory vendors handling PHI, execute tailored BAAs, and conduct due diligence. Szura & Delonis, PLC, in Oakland County, Michigan, specializes in HIPAA audits and BAA drafting for healthcare practices.&nbsp;</p>



<p><a href="https://szura.com/contact/" target="_blank" rel="noreferrer noopener">Contact us</a>&nbsp;for a free consultation to safeguard your operations under HIPAA as of 2026.</p>
]]></content:encoded>
            </item>
        
    </channel>
</rss>