HIPAA, Security and Medical Transcription
A transcription provider handling protected health information is a Business Associate with direct statutory obligations. This page summarises what that means in practice. It is orientation, not legal advice — the primary sources are linked throughout and should be read directly.
Business Associate status
A transcription vendor creates, receives, maintains and transmits protected health information on behalf of a covered entity, which places it squarely within the Business Associate definition. Since the Omnibus Rule of 2013, Business Associates are directly liable for compliance with the Security Rule and with applicable parts of the Privacy Rule — the obligation is statutory, not merely contractual.
A Business Associate Agreement is still required, and it must be in place before protected health information is disclosed. It should identify permitted uses, require safeguards, address subcontractors, set breach notification obligations and timescales, and specify what happens to the information at termination. The Department of Health and Human Services publishes sample Business Associate Agreement provisions, which are a reasonable baseline to negotiate up from.
Subcontracting matters here. A Business Associate that engages a subcontractor to handle protected health information — an offshore transcription pool, a hosting provider, a recognition service — must obtain satisfactory assurances from that subcontractor, and the chain continues downward. A covered entity is entitled to know that the chain exists and how it is governed.
The Security Rule safeguards in a transcription context
The Security Rule organises requirements into administrative, physical and technical safeguards. Mapped onto a transcription operation:
Administrative
- A documented risk analysis covering the actual workflow — capture devices, upload, storage, the transcription environment, delivery and retention. A generic assessment that does not describe how audio moves is not a risk analysis of this process.
- Workforce sanction, training and termination procedures. In transcription, the termination procedure is the one that fails: access frequently persists after a contractor stops working.
- Incident response and contingency planning, including backup and recovery of both audio and finished documents.
- Periodic evaluation, meaning the risk analysis is revisited when the workflow changes rather than filed permanently.
Physical
- Facility access controls for wherever the work is performed. Where transcriptionists work remotely — which is the norm — this becomes a workstation and home-office policy question rather than a building question.
- Device and media controls covering handheld recorders, laptops and any removable media, including disposal and re-use.
- Workstation security: screen positioning, automatic lock, and the household context of remote work.
Technical
- Unique user identification. Shared logins defeat every downstream control and are the most common single finding.
- Access control scoped to role, so administrative staff can retrieve documents without holding clinical edit rights.
- Audit controls that record access and are actually reviewed. Logs nobody reads provide evidence after an incident and prevent nothing.
- Integrity controls ensuring documents are not altered improperly, plus authentication of the parties exchanging data.
- Transmission security — encryption in transit for every hop, including the upload from a capture device.
Encryption
Encryption is technically an addressable rather than a required implementation specification, which is widely misread as optional. It is not: an addressable specification must be implemented if it is reasonable and appropriate, and if it is not implemented the decision must be documented along with the equivalent alternative adopted. For a transcription workflow moving clinical audio across public networks, there is no serious argument that encryption in transit is unreasonable.
Encryption at rest deserves the same treatment and is more often missing — particularly on handheld recorders and mobile devices, which are the assets most likely to be lost. There is a strong practical incentive beyond compliance: the breach notification requirements apply to unsecured protected health information, and information encrypted to the recognised standard is not unsecured. An encrypted lost device is an inventory problem; an unencrypted one is a reportable breach.
The National Institute of Standards and Technology publishes SP 800-66r2, a practical implementation guide mapping the Security Rule onto concrete controls. It is the most useful single document for anyone specifying transcription security requirements.
Breach notification
Business Associates must notify the covered entity of a breach of unsecured protected health information without unreasonable delay and no later than sixty days from discovery; the covered entity then carries the notification obligations to individuals, to the Secretary and, above certain thresholds, to the media. Agreements commonly shorten the vendor's internal notification window, and doing so is sensible — sixty days consumes most of the covered entity's own timeline.
The full requirements are set out in the HHS breach notification rule.
The exposures that actually occur
Enforcement history and incident reporting point consistently at the mundane rather than the sophisticated:
- Lost or stolen unencrypted devices holding dictation audio.
- Access not revoked when staff or contractors leave.
- Shared credentials making audit logs useless.
- Misdirected delivery — documents sent to the wrong practice or the wrong clinician.
- Undisclosed subcontracting, discovered after an incident rather than at procurement.
- Retained audio and documents kept indefinitely with no retention position and no disposal process.
None of these require an attacker. All of them are addressable with routine controls, which is precisely why they are the ones that attract enforcement attention.
See also the provider evaluation framework and the primary sources.