Red Flag: The Vendor Requested Far More PHI Than the Service Required
A vendor deal that looked routine — clean MSA, sensible pricing, BAA already in place — almost moved forward in minutes. Then the SOW revealed a PHI request far beyond what was actually needed. Robyn D. Marino on why HIPAA compliance doesn’t stop at the BAA, and how SOW-level review changes the risk calculus on healthcare vendor agreements.