HIPAA BAA for a Satellite Radio Vendor Used by Village Health Aides

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA BAA for a Satellite Radio Vendor Used by Village Health Aides

Kevin Henry

HIPAA

August 05, 2026

6 minutes read
Share this article
HIPAA BAA for a Satellite Radio Vendor Used by Village Health Aides

HIPAA BAA Requirement

A Business Associate Agreement (BAA) is required when a vendor creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a Covered Entity. If village health aides use satellite radios for patient care, assess whether the vendor’s service involves more than transient transmission of PHI.

You must execute a BAA if the vendor stores content (e.g., call recordings, voice messages, transcripts), can access PHI during support, or operates portals that archive communications. The BAA should define permitted uses, security safeguards, breach notification timelines, subcontractor “flow-down” requirements, termination and return/destruction of PHI, and documentation retention expectations.

If the vendor functions solely as a transmission conduit with no access to content and no persistent storage, a BAA may not be required. Because this determination is fact-specific, document your rationale and revisit it when services or features change.

Satellite Radio Vendor's Role

Understand precisely what the satellite radio vendor provides. Hardware-only resellers that do not operate networks or store data are less likely to be business associates. Network operators offering airtime, managed talkgroups, dispatch consoles, or recording features are more likely to handle PHI and require a BAA.

Risk drivers that influence BAA status

  • Persistent storage of audio, messages, or transcripts—even if encrypted.
  • Vendor support practices that allow viewing or playback of communications.
  • Cloud portals, mobile apps, or device management that retain contact lists or content.
  • Subcontracted network operations centers handling transmissions or archives.

Practical considerations for remote care

  • Prefer private or encrypted talkgroups and headsets to reduce incidental disclosures.
  • Confirm who is listening before sharing identifiable details; move to a private channel when feasible.
  • Avoid vendor support tickets that include PHI; route sensitive diagnostics through approved, secure channels.

Conduit Exception

The conduit exception is narrow. It applies to entities that merely transmit PHI without storing it other than temporarily in the normal course of transmission and without accessing content. Traditional examples are postal services and common carriers.

Applying the exception to satellite radio vendors

  • Likely within the exception: real-time push-to-talk or voice relays with no recording, no server-side caching, and no vendor ability to access content.
  • Not within the exception: any service that records or archives audio, uses store-and-forward messaging, generates searchable transcripts, or retains content accessible to the vendor or its subcontractors.

Document the determination with a short memo describing the service, data flows, storage, access, and encryption. Reassess if the vendor enables new features like call recording or AI transcription.

Vendor Compliance Verification

Before treating a satellite radio vendor as a Business Associate—or confirming conduit status—perform structured due diligence. The goal is to validate Vendor Compliance against HIPAA’s administrative, physical, and technical safeguard expectations.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Step-by-step verification

  • Map data flows: identify where PHI might be created, transmitted, stored, or accessed.
  • Classify the service: conduit-only versus BA; draft the determination summary.
  • Security review: request security policies, encryption details, access controls, logging, and incident response procedures.
  • Technical testing: confirm encryption in transit, role-based access to any portals, and remote disable/wipe for lost devices.
  • Breach readiness: verify incident detection, notification timelines, and escalation paths.
  • Subcontractor management: ensure BA obligations flow down to all subcontractors.
  • Contracting: execute the BAA if required; include audit rights and minimum necessary commitments.
  • Operational checks: define support channels that avoid unnecessary PHI exposure.
  • Risk rating: record residual risks and mitigation actions.
  • Approval and onboarding: capture final sign-off and go-live controls.

Vendor Compliance Documentation Retention

Maintain all vendor compliance records for at least six years from the date of creation or the date last in effect, whichever is later. This includes contracts and determinations tied to the Business Associate Agreement and Documentation Retention policies.

What to retain

  • Executed BAA and amendments, plus the conduit-versus-BA determination memo.
  • Security questionnaires, SOC/independent assessments if available, and risk analyses.
  • Onboarding checklists, access approvals, device inventories, and configuration baselines.
  • Training rosters, materials, and acknowledgments related to satellite radio use.
  • Incident reports, breach notifications, corrective actions, and post-incident reviews.
  • Exclusion screening logs and attestations.

Good recordkeeping practices

  • Use a restricted, searchable repository with version control and clear ownership.
  • Apply retention schedules consistently; review annually for accuracy and completeness.
  • Protect records containing PHI or security details with appropriate access controls.

Vendor Compliance Training

Train village health aides and relevant staff on appropriate satellite radio use. Emphasize recognizing PHI, selecting private or encrypted channels when feasible, and verifying the intended recipients before speaking.

Core training topics

  • What counts as PHI and when it may be transmitted for treatment purposes.
  • Channel discipline: identify open community channels versus restricted talkgroups.
  • Device hygiene: PINs, lock timeouts, no personal recordings, and lost-device reporting.
  • Minimum necessary: while it does not apply to treatment, keep transmissions focused and avoid unnecessary identifiers when not essential to care.
  • Support interactions: never include PHI in vendor tickets; use approved secure processes.
  • Event reporting: misdirected transmissions and suspected eavesdropping must be reported immediately.

Deliver training at onboarding and at least annually, reinforced with brief drills and scenario-based refreshers relevant to remote and emergency settings.

Vendor Compliance Exclusion Screening

Screen for Office of Inspector General Exclusion risks as part of vendor oversight. While satellite radio vendors typically do not bill federal health programs, exclusions can still create compliance exposure when a Business Associate provides items or services related to patient care operations.

Who and how to screen

  • Screen the vendor’s legal entity and key executives against federal exclusion lists during onboarding and monthly thereafter.
  • Require the vendor to screen its workforce routinely and to certify that no excluded individuals access PHI or support your environment.
  • Capture results, potential matches, resolutions, and any corrective actions in your repository.

Conclusion

Decide early whether your satellite radio vendor is a conduit or a Business Associate, document the basis, and align controls accordingly. When a BAA is needed, pair strong contractual terms with practical safeguards, training, exclusion screening, and disciplined documentation retention to protect PHI and support compliant care in remote settings.

FAQs.

When is a BAA required for a satellite radio vendor?

A BAA is required when the vendor creates, receives, maintains, or transmits PHI on your behalf beyond transient carriage. If the service records or stores audio, provides searchable archives or transcripts, or allows vendor personnel to access content for support, treat the vendor as a Business Associate and execute a BAA.

How does the conduit exception apply to satellite radio vendors?

The conduit exception applies only when the vendor merely transmits PHI in real time, stores nothing beyond temporary buffering, and has no access to content. Any persistent storage, playback, dispatch recording, or store-and-forward messaging typically disqualifies the vendor from the exception.

What are the vendor compliance verification steps for village health aides?

Map data flows, classify the service (conduit versus BA), review security controls and breach readiness, verify subcontractor management, execute a BAA if required, define support channels that avoid PHI, record the risk rating and approvals, and retain all artifacts for audit purposes.

How long must village health aides retain vendor compliance documentation?

Retain vendor compliance records—such as BAAs, determinations, risk analyses, training logs, screening results, and incident files—for at least six years from creation or last effective date, whichever is later.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles