HIPAA BAA Checklist: Questions to Ask Before Outsourcing Medical Coding to an Offshore Team

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA BAA Checklist: Questions to Ask Before Outsourcing Medical Coding to an Offshore Team

Kevin Henry

HIPAA

September 03, 2026

7 minutes read
Share this article
HIPAA BAA Checklist: Questions to Ask Before Outsourcing Medical Coding to an Offshore Team

BAA Requirement Overview

What a Business Associate Agreement Covers

A Business Associate Agreement (BAA) defines how an offshore coding vendor will create, receive, maintain, or transmit Protected Health Information (PHI) on your behalf. It sets permitted uses and disclosures, required safeguards, breach duties, subcontractor “flow‑down” terms, and how PHI is returned or destroyed at the end of the engagement.

Key Questions to Ask

  • Does the BAA clearly identify the vendor as a Business Associate and you as the Covered Entity, including the specific services (medical coding, auditing, denials support)?
  • Are permitted and prohibited uses of PHI explicit, with a “minimum necessary” standard?
  • Which Security Rule safeguards are contractually required (administrative, physical, technical)?
  • Are Breach Notification Timelines defined for discovery, escalation, and notices to your organization?
  • Does the BAA mandate Subcontractor Compliance with the same restrictions and safeguards?
  • Do you have audit/assessment rights and obligations to remediate findings?
  • Are data return, destruction, and Data Retention Policy requirements unambiguous?

Proof to Request

  • Final BAA text with exhibits (security controls, reporting templates, contact points).
  • Named privacy and security officers with roles and escalation paths.
  • Evidence of HIPAA training and acknowledgment for workforce members handling PHI.

Defining Scope of PHI Access

Map Access and Data Flows

Document which PHI elements coders need, where they access them (EHR, coding platform, VDI), and how data travels between systems. Apply role‑based access and the minimum necessary principle to reduce exposure while enabling productivity.

Key Questions to Ask

  • Which PHI categories are required for coding (diagnoses, procedures, demographics) and which can be masked or de‑identified?
  • How are user roles defined, approved, and periodically reviewed?
  • Is access limited to managed, monitored environments (no PHI on personal devices, no local downloads, no screenshots or printing)?
  • Are session logging, keystroke monitoring, and screen watermarking used to deter exfiltration?
  • Where is PHI stored at rest, and what is the documented Data Retention Policy?

Deliverables to Obtain

  • Data flow diagram and system inventory showing all PHI touchpoints.
  • Access control matrix (who can view/edit/export) and approval workflow.
  • Retention schedule for work items, logs, backups, and email.

Implementing Security Safeguards

Technical Controls

  • Multifactor Authentication (MFA) for all PHI systems, VPN, and remote access.
  • Endpoint Protection with EDR, full‑disk encryption, and policy‑based USB blocking.
  • VDI or secure jump hosts; no PHI stored locally; data loss prevention for uploads and email.
  • Network segmentation, IP allowlists, enforced TLS, and strong identity lifecycle management.
  • Patch management, vulnerability scanning, and periodic penetration testing.

Administrative and Physical Controls

  • Security awareness and HIPAA training tailored to offshore medical coding workflows.
  • Background checks, least‑privilege access, and timely offboarding.
  • Controlled facilities with visitor logs, CCTV, restricted mobile devices, and clean‑desk rules.
  • Documented incident response, disaster recovery, and business continuity plans tested at least annually.

Questions to Ask

  • Which safeguards are enforced by technology versus policy, and how is compliance monitored?
  • Are screenshots, printing, and copy/paste technically blocked in coding workspaces?
  • How are encryption keys managed and rotated?
  • What are the recovery point/time objectives for PHI systems supporting coding?

Evidence to Request

  • Security policies and SOPs, with last review dates and approval records.
  • Training logs, access review reports, and sample audit trails.
  • Independent assurance (e.g., SOC 2 Type II, ISO 27001 scope statements) covering coding operations.
  • Recent vulnerability scan and remediation reports.

Managing Subcontractor Obligations

Flow‑Down and Oversight

If the vendor uses downstream providers (staffing firms, hosting, transcription), the BAA must require equivalent protections and monitoring. Subcontractor Compliance includes due diligence, signed BAAs, access restrictions, and continuous oversight.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Key Questions to Ask

  • Who are current and planned subprocessors, and how are they vetted?
  • Do downstream BAAs mirror your security, breach, and retention requirements?
  • Will you receive advance notice of changes to the subcontractor list and a right to object?
  • How are data transfers limited, logged, and reviewed across borders?
  • Are termination, offboarding, and PHI destruction by subcontractors verified?

Evidence to Request

  • Subcontractor register with services, locations, and PHI exposure levels.
  • Sample downstream BAA and latest risk assessment results.
  • Quarterly attestations confirming adherence to requirements.

Establishing Breach Notification Procedures

Define Incidents, Breaches, and Timelines

Clarify what constitutes a security incident versus a reportable breach of unsecured PHI, how risk assessments are performed, and how Breach Notification Timelines start at discovery. Specify who investigates, who communicates, and the required content of notices.

Key Questions to Ask

  • What triggers internal escalation and when do clocks start for notification?
  • What is the vendor’s initial notification target to you (e.g., 24–72 hours) and formal report deadline?
  • Who handles forensics, containment, and documentation, and how are subcontractors coordinated?
  • How are lessons learned captured and controls improved after an incident?

Deliverables and Expectations

  • Incident response plan, playbooks, and contact tree with 24/7 availability.
  • Tabletop exercise results and evidence of staff training.
  • Templates for incident reports and breach notices for rapid use.

Outlining Data Return or Destruction Policies

Data Lifecycle and End‑of‑Contract

Specify how PHI is returned in usable formats, when destruction occurs, and how backups, caches, and logs are purged. Align the vendor’s Data Retention Policy with yours and legal holds, and require certificates of sanitization consistent with recognized methods.

Key Questions to Ask

  • What formats will data and coding artifacts be returned in, and what are the timelines and fees?
  • How are media sanitized, and how is destruction verified for primary and backup systems?
  • How long will access logs be retained after termination, and who can retrieve them?
  • How are subcontractors required to return or destroy PHI and confirm completion?

Evidence to Request

  • Documented return/destruction procedures and chain‑of‑custody steps.
  • Sample certificates of destruction and sample export packages.
  • Schedule for backup expiration and validation of purge processes.

Verifying Compliance Documentation

What to Collect and Review

  • Enterprise risk analysis, risk treatment plan, and HIPAA policy set.
  • Training curriculum, workforce acknowledgments, and sanction policies.
  • Assurance reports (e.g., SOC 2 Type II) and any ISO 27001/27701 certificates covering coding operations.
  • Access reviews, change management records, and incident logs.
  • Cyber insurance declarations relevant to PHI handling.

Due Diligence Questions

  • How recent are the assessments, and do findings map to HIPAA safeguards?
  • What remediation owners and deadlines are in place for open risks?
  • What metrics and SLAs track security performance over time?

Ongoing Oversight

  • Right to audit with agreed cadence and scope (remote and onsite).
  • Quarterly compliance attestations and annual refresh of training and risk analysis.
  • Periodic revalidation of Multifactor Authentication, Endpoint Protection, and access controls.

Conclusion

Use this HIPAA BAA checklist to precisely define PHI scope, harden safeguards, control subcontractors, and codify incident and data lifecycle duties. Clear requirements plus verifiable evidence will help you select an offshore medical coding partner that protects patients and your organization.

FAQs.

What is a Business Associate Agreement and why is it required?

A Business Associate Agreement is a contract that binds a vendor handling PHI to HIPAA’s privacy and security requirements. It details permissible PHI uses, required safeguards, breach duties, subcontractor flow‑down, and data return or destruction, creating enforceable accountability.

How should PHI access be scoped in a BAA?

Define the minimum necessary PHI elements coders need, where they access them, and how long data is retained. Include role‑based access, restrictions on local storage, screenshots, and printing, plus logging and periodic access reviews.

What security safeguards are essential for offshore medical coding teams?

Require Multifactor Authentication, Endpoint Protection with encryption and EDR, secure VDI or jump hosts, DLP, patching, and network controls. Pair these with training, vetted facilities, incident response, and tested business continuity and disaster recovery.

When must breach notifications be reported?

Set clear Breach Notification Timelines: immediate internal escalation on discovery, rapid notice to you (often within 24–72 hours), and formal reporting as your policies and HIPAA require. The BAA should define responsibilities, content of notices, and coordination steps.

How should PHI be handled after contract termination?

Specify return formats, deadlines, and secure destruction for all copies, including backups and logs, aligned to your Data Retention Policy. Require certificates of destruction and confirmation that all subcontractors completed the same steps.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles