When a remote pharmacy vendor verifies an order for one of your patients, that pharmacist is reading protected health information your hospital is legally responsible for. A signed Business Associate Agreement does not transfer that responsibility — it distributes it. Before you sign, work through the five areas below. Every “yes” should come with documentation, not assurances.

HIPAA 1. BAA 2. Workforce 3. Technical 4. Geography 5. Breach
The five areas of HIPAA diligence for a remote pharmacy partner.

1. The Business Associate Agreement

  • Is the BAA current with the 2013 Omnibus Rule, including direct subcontractor liability?
  • Does it require breach notification to you within 24 to 72 hours, not the HIPAA default of 60 days?
  • Does it grant you the right to audit, or at minimum to receive their independent audit reports?

2. Workforce and training

  • Where do their pharmacists physically work — secure office space, home offices, or both? If home-based, what are the documented workspace requirements?
  • How often is HIPAA training delivered, and is completion tracked at the individual pharmacist level?
  • What is the written sanctions policy when a pharmacist mishandles PHI?

3. Technical safeguards

  • Is PHI encrypted at rest and in transit — AES-256 and TLS 1.2 or higher?
  • Is access multi-factor, routed through a controlled environment such as a virtual desktop, rather than direct EHR login from personal devices?
  • How long are access and activity logs retained? HIPAA requires six years for documentation, and serious investigations often look back further.

4. Subcontractors and geography

  • Do they use any subcontractors — including IT, transcription, or after-hours overflow services — that touch PHI? Are signed BAAs in place with each?
  • Is any PHI processed outside the United States? Some hospital policies prohibit offshore handling regardless of safeguards in place.

5. Breach response and contract end

  • Who is their designated Privacy Officer and Security Officer, and how quickly are they reachable during an incident?
  • At contract termination, will PHI be returned or destroyed, and will you receive a certificate of destruction?
Red flags worth taking seriously: a BAA template that has not been updated since 2013, vague answers about where pharmacists physically work, or an inability to produce recent training-completion records on request. Compliance failures are rarely a single missing control — they are usually a pattern of small gaps that line up on a bad day.