When an infusion center or DME provider sends patient referral documents to a cloud-based processing tool, they are sharing protected health information with a third party. Under HIPAA, the covered entity (the provider) is responsible for ensuring that any vendor handling PHI has appropriate safeguards in place and has agreed to a Business Associate Agreement. The questions you ask during vendor evaluation determine whether you are appropriately transferring compliance responsibilities or unknowingly retaining risks you assumed you were offloading.
This article covers seven questions that provide meaningful signal about a vendor's actual HIPAA posture, not just their marketing claims. These are questions Coral gets asked regularly, and questions we think are fair and important for any vendor in this space to answer clearly.
Question One: Will You Sign a BAA?
A Business Associate Agreement is a contract required by HIPAA whenever a covered entity shares PHI with a third party that processes or stores it on the covered entity's behalf. Without a signed BAA, you are not compliant with HIPAA, regardless of what other controls the vendor has in place.
A BAA-willing vendor is a minimum threshold, not a differentiator. Any vendor processing referral documents for healthcare providers should sign a BAA without hesitation. If a vendor is reluctant, adds fees to provide a BAA, or routes around the question, that is a disqualifying signal. The BAA commitment is a legal obligation on their part, not a favor they are doing you.
The follow-up question: does the BAA include your subprocessors? Cloud document processing vendors often use third-party infrastructure (cloud providers, OCR services, storage vendors). Each of those subprocessors may also handle your PHI. The BAA should either cover their use of BAA-contracted subprocessors or they should provide a list of their subprocessors and confirm BAA coverage for each.
Question Two: Where Is My Data Stored and Processed?
HIPAA does not prohibit cloud storage or processing of PHI, but it does require that PHI storage and processing meet the security requirements of the HIPAA Security Rule. For providers subject to additional state-level privacy requirements (which vary by state), the geography of data storage can create additional obligations.
For most small infusion centers and DME providers, the practical question is: is my data staying in US-based infrastructure? Vendor answers that reference "global infrastructure" without committing to US-only storage deserve follow-up. Data residency in US-based facilities does not automatically mean compliance, but non-US storage creates a different set of risk considerations.
Coral processes and stores all PHI in US-based cloud infrastructure. That is a design decision we made early, not a feature we added later.
Question Three: How Long Do You Retain My Documents?
Document processing vendors retain data for varying periods, and the retention policy is one of the more important compliance variables. PHI that exists in a vendor's system is PHI you are responsible for. Indefinite retention of referral documents and extracted clinical fields increases your exposure surface.
Ask specifically: how long do you retain the original document after processing? How long do you retain the extracted data? Is the retention period configurable? What is your data deletion process and how do you confirm deletion?
Reasonable retention for an intake automation tool is long enough to support the audit and tracking needs of the authorization workflow, but not indefinite. A vendor that retains referral documents for several years without a clear rationale is adding risk to your operation without adding value.
Question Four: What Access Controls Are in Place?
Access control is one of the core HIPAA Security Rule administrative safeguards. For a cloud document processing tool, the relevant access control questions are: who at the vendor can access your PHI, under what circumstances, and with what logging?
Vendor support staff access to production data containing PHI should be limited, logged, and auditable. A vendor where any employee can browse customer document data without constraint is not meeting the minimum necessary principle that HIPAA requires.
Ask whether your documents are logically isolated from other customers' data. Ask whether vendor employee access to your data is logged. Ask whether you can request an access log for your data. These questions are reasonable and answerable by any vendor that has actually implemented access controls. Vague answers about security processes without specifics on logging and isolation are a signal that the controls may not be as concrete as the marketing suggests.
Question Five: What Happens in a Breach?
Under HIPAA, a breach involving PHI requires notification to affected individuals and, depending on the number of affected individuals, to HHS. Your BAA with a vendor should specify how the vendor will notify you in the event of a breach involving your data, and within what timeframe.
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery. If a vendor discovers a breach of your data, their BAA obligation is typically to notify you promptly so you can begin your own notification obligations. A vendor that has not thought through their breach notification commitment is leaving a gap in the legal arrangement you need to be aware of.
Ask: what is your breach notification timeline to covered entities? How do you define a breach under your BAA? Do you have breach response procedures documented? These questions should have concrete answers.
Question Six: What Encryption Do You Use?
Encryption at rest and in transit is a standard HIPAA Security Rule safeguard. The specific question is not just whether the vendor uses encryption, but what encryption standards they use and whether the implementation covers all PHI storage locations.
In transit: transport layer security (TLS) for all data in transit is the baseline. Ask about the TLS version in use (TLS 1.2 or higher is current standard; older versions have known vulnerabilities). Ask whether fax document uploads are transmitted over encrypted channels.
At rest: encryption of PHI stored in the vendor's systems using AES-256 or equivalent is standard. Ask whether extracted data (the structured fields pulled from documents) is encrypted at rest separately from the document files themselves, since both contain PHI.
Question Seven: How Do You Handle Minimum Necessary Use?
HIPAA's minimum necessary standard requires that access to and use of PHI be limited to what is necessary to accomplish the intended purpose. For a document processing vendor, this means they should be processing your referral documents for the specific purpose you contracted them for, not using the extracted clinical data for other purposes.
Ask directly: do you use the PHI you process from my documents for any purpose other than providing the contracted service? Do you use extracted clinical data for model training, benchmarking, product improvement, or any other secondary purpose? If yes, what are the specifics and what opt-out mechanisms exist?
Secondary use of PHI for model training without patient consent raises HIPAA concerns that the covered entity may share. A vendor that is thoughtful about this question will have a clear policy. A vendor that is evasive about it is leaving a question open that has legal implications for your compliance posture.
What This Means for Evaluating Coral
We include ourselves in the scope of this evaluation framework. Coral signs BAAs. We process and store PHI in US-based cloud infrastructure. We have configurable data retention with deletion processes. We log access to customer data. We have a documented breach notification commitment in our BAA. We use TLS in transit and AES-256 at rest. We do not use customer PHI for model training or any secondary purpose without explicit customer agreement.
We say this not to check boxes, but because we think the seven questions above are the right questions and providers should get clear answers from any vendor they are considering. If you are evaluating Coral and want specifics on any of these areas, our team can walk through the details. Contact us at [email protected].