When a remote pharmacy vendor verifies an order for one of your patients, that pharmacist is reading protected health information your hospital is legally responsible for. A signed Business Associate Agreement does not transfer that responsibility — it distributes it. Before you sign, work through the five areas below. Every “yes” should come with documentation, not assurances.
The five areas of HIPAA diligence for a remote pharmacy partner.
1. The Business Associate Agreement
- Is the BAA current with the 2013 Omnibus Rule, including direct subcontractor liability?
- Does it require breach notification to you within 24 to 72 hours, not the HIPAA default of 60 days?
- Does it grant you the right to audit, or at minimum to receive their independent audit reports?
2. Workforce and training
- Where do their pharmacists physically work — secure office space, home offices, or both? If home-based, what are the documented workspace requirements?
- How often is HIPAA training delivered, and is completion tracked at the individual pharmacist level?
- What is the written sanctions policy when a pharmacist mishandles PHI?
3. Technical safeguards
- Is PHI encrypted at rest and in transit — AES-256 and TLS 1.2 or higher?
- Is access multi-factor, routed through a controlled environment such as a virtual desktop, rather than direct EHR login from personal devices?
- How long are access and activity logs retained? HIPAA requires six years for documentation, and serious investigations often look back further.
4. Subcontractors and geography
- Do they use any subcontractors — including IT, transcription, or after-hours overflow services — that touch PHI? Are signed BAAs in place with each?
- Is any PHI processed outside the United States? Some hospital policies prohibit offshore handling regardless of safeguards in place.
5. Breach response and contract end
- Who is their designated Privacy Officer and Security Officer, and how quickly are they reachable during an incident?
- At contract termination, will PHI be returned or destroyed, and will you receive a certificate of destruction?
Red flags worth taking seriously: a BAA template that has not been updated since 2013, vague answers about where pharmacists physically work, or an inability to produce recent training-completion records on request. Compliance failures are rarely a single missing control — they are usually a pattern of small gaps that line up on a bad day.
