What this is, and who it is for
HIPAA requires a physician group to have a signed business associate agreement (BAA) with every outside company that creates, receives, keeps or sends patient information on its behalf: the EHR, the clearinghouse, the billing company, the IT firm, the shredding service, the answering service.
Most practices keep that list in a spreadsheet or a shared folder, if they keep it at all. BAAs get signed by whoever bought the software and are never filed. Nobody knows which vendors pass data on to their own subcontractors. The first time anyone looks is after a breach.
This register is for Marisol, the compliance officer who runs it, Owen, the practice manager who needs the picture, and Priya, the auditor who has to be shown it. Its one promise: every vendor that touches patient data has a signed, current BAA and a known risk tier.