Cyber Wire’s eAssist piece covers what Georgia dental offices should do this week on credentials and access. This post is the next layer: how you stop getting surprised by the next billing, imaging, or cloud vendor that suddenly owns a piece of your patient risk.
Most practices can name their EHR. Fewer can name every company that can touch claims data, insurance portals, archived charts, imaging, or transcription — and produce a signed Business Associate Agreement for each one in under an hour. That gap is where Friday’s headline becomes Monday’s patient letter.
You do not need a Fortune 500 vendor-risk program. You need a list you can read, update, and act on.
Who counts as a business associate here
In plain English: if an outside company creates, receives, maintains, or transmits PHI for your practice, they are in your HIPAA perimeter — billing and revenue-cycle firms, clearinghouses, cloud EHR hosts, data-migration and archive vendors, imaging/PACS partners, transcription, patient-comms platforms, and IT providers with admin access to systems that hold PHI.
Patients signed up with you. Regulators and patients still look to you when a BA has a bad week. Notification duty often still lands on the covered entity even when the failure was upstream.
A 45-minute inventory that fits a real clinic
Block one short meeting with the office manager and whoever owns IT. Build a simple spreadsheet — vendor name, what PHI they touch, BAA on file (Y/N + date), primary contact, how they access your systems (portal, RDP, API, SFTP), MFA status if you know it, and last time you reviewed them.
- Start with money and charts — billing/RCM, clearinghouse, payer portals, EHR host, backup/archive, imaging.
- Add anyone with a login — IT support, temp staffing systems, e-fax, forms, review sites that store clinical details.
- Match each row to a BAA — if you cannot find the agreement, that is the finding. Fix the paperwork or fix the access.
- Mark shared credentials — any account a vendor can use is an incident-response priority (as the eAssist guidance underlined).
- Set a quarterly 20-minute refresh — new vendor, new integration, or someone left the practice = update the list the same week.
If the list takes longer than an afternoon to draft, you have already learned something useful about shadow IT and forgotten portals.
Four questions every BA should answer in writing
- How is access controlled (MFA, least privilege, logging), and how fast do you notify us of a suspected incident — hours, not weeks of silence?
- Where does our PHI live (regions, subprocessors, cloud services), and who else can reach it?
- What does our BAA say about forensics cooperation, patient notice costs, and credit monitoring if PHI is involved?
- How do we cut off access the day we terminate — accounts, tokens, API keys, and retained copies?
Keep the answers next to the inventory. A binder nobody opens does not help; a one-page vendor card per critical BA does.
Takeaway for IT decision-makers
Treat every vendor that touches PHI like an extension of your own network — because patients and HIPAA already do.
Use this week’s billing-vendor noise as the forcing function: finish the inventory, rotate shared access where it still exists, and put quarterly BA review on the calendar next to payroll and supply orders. Rome and Northwest Georgia practices do not need more fear — they need a short list they actually manage.
Brotherly Technology helps dental and medical SMBs across Northwest Georgia build that list, tighten Microsoft 365 and remote access, and pressure-test backups and BA paperwork before the next advisory lands.
Context: timely companion to public reporting on the eAssist investigation and GDA’s Sep 9, 2026 advisory; this article is operational guidance, not a claim that any specific practice’s PHI was confirmed exposed.