Skip to main content

Business Associates & Release of Information Workflows

Duration: 50 min · Level: Intermediate · Module: 5. HIPAA Privacy Rule · Focus: business-associate, BAA, ROI, authorization, release-of-information

Covered entities rarely operate alone. They hand PHI to billing companies, coding vendors, cloud providers, and transcription services every day — and HIPAA has a name and a legal framework for every one of those partners. They are Business Associates, and the contract that governs them is the gatekeeper for all that shared data. On the other side of the same coin sits the daily reality of CEHRS work: processing Release of Information (ROI) requests, each of which must rest on a valid authorization and meet a turnaround clock. This lesson covers both — who may legally touch PHI on the entity's behalf, and how a clean ROI request is built and delivered.

Business Associates and the BAA

A Business Associate (BA) is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. The common examples are worth memorizing because the exam names them: billing companies, coding vendors, EHR vendors, cloud storage providers, and transcription services. If an outside party touches PHI to do a job for the covered entity, it is almost certainly a BA.

Before any PHI can flow to that BA, a Business Associate Agreement (BAA) must be in place — it is a required contract, not optional paperwork. The exam expects you to know what the BAA must contain:

  • What PHI is shared and the permitted uses of it.
  • The security safeguards the BA must maintain.
  • Incident reporting obligations — how the BA notifies the entity of problems.
  • Return or destruction of the PHI when the contract ends.

Memory hook: no BAA, no PHI. The agreement comes first; the data flows second.

Anatomy of a valid HIPAA authorization

When a disclosure requires patient authorization, the authorization itself must be complete — an incomplete one is invalid, and acting on it creates liability. The exam tests the required elements, and all of them must be present:

  • A description of the PHI to be disclosed.
  • Who may disclose it.
  • Who may receive it.
  • The purpose of the disclosure.
  • An expiration date.
  • The patient's signature and date.
  • A statement of the patient's right to revoke the authorization.
  • A statement about potential re-disclosure of the information.

A useful way to remember the list is to ask, for any authorization in front of you: what, from whom, to whom, why, until when, signed when, revocable, and re-disclosure warned? If any of those is missing, the authorization is not valid and the disclosure should not proceed.

ROI turnaround standards

ROI is a timed activity, and tracking request-to-delivery time is part of the job. The standards to know:

  • Standard requests: 30 days.
  • Medical emergencies: within 24 hours.
  • Legal subpoenas: follow the court's timeline.

CEHRS staff are expected to track each request against its applicable clock. The contrast the exam tests is the gap between the routine 30-day window and the urgent 24-hour emergency window — knowing which clock applies to which request is the skill being measured.

Two distinctions in this lesson are favorite exam targets.

Workers' compensation is a recognized HIPAA exception. Information related to the work injury may be released without authorization for workers' comp purposes. But the exception is narrow: unrelated health information still requires authorization. So if a claim concerns a back injury, the back-injury records flow for workers' comp without a signature — but the patient's unrelated mental health history does not. Memory hook: the injury flows; everything else still needs a signature.

Authorization versus consent. These are not interchangeable under HIPAA, and the exam will try to make you treat them as synonyms. Authorization is specific written permission for a specific disclosure — the detailed document described above. Consent is a general agreement to treatment. One is about releasing information for a defined purpose; the other is about agreeing to be cared for. Keep them in separate mental boxes.

Putting it into practice

Turn the framework into two reusable checklists you can run on any real request.

  1. BA check: when an outside vendor will touch PHI, confirm it qualifies as a Business Associate, then verify a signed BAA is in place before any data moves. Mentally list the five required BAA contents — shared PHI/permitted uses, safeguards, incident reporting, and return/destruction at contract end.
  2. Authorization audit: take a sample ROI authorization and tick off all eight required elements (what, from whom, to whom, purpose, expiration, signature/date, right to revoke, re-disclosure statement). If any box is empty, mark the authorization invalid and stop.
  3. Clock assignment: for each request, assign the correct turnaround — 30 days standard, 24 hours for a medical emergency, court timeline for a subpoena — and start a request-to-delivery timer.
  4. Exception screen: flag any workers' comp request and split it — release only the injury-related records without authorization; require authorization for anything unrelated.
  5. Terminology drill: write one sentence distinguishing authorization (specific, written, for a disclosure) from consent (general, for treatment). If you can do all five without notes, you are ready for Domain 4's ROI questions.

Key takeaways

  • A Business Associate creates, receives, maintains, or transmits PHI on a covered entity's behalf — billing companies, coding/EHR vendors, cloud storage, transcription — and a signed BAA must exist before any PHI flows.
  • The BAA must specify shared PHI and permitted uses, security safeguards, incident reporting, and return or destruction of PHI at contract end.
  • A valid authorization requires all eight elements: PHI description, who discloses, who receives, purpose, expiration date, signature/date, right to revoke, and a re-disclosure statement.
  • ROI turnaround: 30 days for standard requests, within 24 hours for medical emergencies, and the court's timeline for subpoenas — and staff must track request-to-delivery time.
  • Workers' comp is a HIPAA exception (injury-related records flow without authorization; unrelated information still needs it), and authorization (specific written permission for a disclosure) is not the same as consent (general agreement to treatment).

← Previous: C5.3 Permitted Uses, Disclosures & the Minimum Necessary Standard

Part of Module 5: HIPAA Privacy Rule.