Carepassage

Do you need a BAA to book a hotel for a patient?

This question usually arrives second, right after somebody has satisfied themselves that helping with lodging is allowed at all. It is a good question and it has a cleaner answer than most compliance questions do, but the answer depends on a distinction that is easy to blur: the difference between telling a hotel someone is arriving and telling a vendor someone is a patient.

What makes a hotel booking a privacy question

Protected health information is not only diagnoses and test results. It is individually identifiable health information, and that includes the fact that a named person is receiving care from a named provider. A reservation that carries a patient's name plus your clinic's name plus the dates of their treatment is telling a story about that person's health, even though not one clinical word appears in it.

That is the whole of the issue. Nothing about the room is sensitive. The link between the person, the provider and the dates is.

Is the hotel a business associate?

Generally not. A business associate is a person or entity that creates, receives, maintains or transmits protected health information in performing a function or activity on behalf of a covered entity. A hotel selling a room is doing neither: it is an ordinary commercial vendor in an arm's-length transaction, and the guest happens to be a patient.

The usual comparison is a restaurant or an airline. You would not sign a BAA with an airline because a patient flew to see you. What changes the analysis is not who the guest is, it is what you tell the vendor and why.

The vendor in the middle is the one that needs the agreement

If a third party books on your behalf, it necessarily receives the patient's identity, the dates of their care and the name of the provider delivering it. That is the classic business-associate fact pattern: it is performing a function for you, and it is receiving protected health information to do it.

This is the part programs most often get backwards, asking whether the Marriott needs to sign something while a booking platform is quietly accumulating a list of everyone who travels to their clinic. Ask any vendor that touches the reservation on your behalf whether it will sign a BAA, and treat "we do not do that" as the answer it is.

Minimum necessary, applied to a reservation

Where a booking does have to be made on a patient's behalf, the discipline is the same one that applies everywhere else: send the least that will accomplish the task. A hotel needs a name, dates and a way to be paid. It does not need to know why the guest is in town, what they are being treated for, or which department is arranging it.

A useful test is to read the reservation as a stranger would and ask what it reveals. If it discloses that this person is being treated, and for what, it is carrying more than the booking needs.

The structure with the least exposure

There is a version of this where the question mostly dissolves. The patient books their own room, in their own name, with their own card. You give them access and coordination, not a reservation made for them.

Nothing about the patient moves from you to a hotel or to a booking vendor, because you are not the one booking. The patient is a guest like any other guest, and what your program holds afterwards is its own record of the trip rather than a disclosure to somebody else.

Common questions

Is this legal advice?

No. This is general information about how these rules are commonly read, written so you know what to raise with your privacy officer or counsel. They decide what your specific arrangement requires, and state law can be stricter.

Do we need a BAA with the hotel?

Almost certainly not. A hotel selling a room is an ordinary vendor, not a business associate performing a function on your behalf. The agreement question belongs to anyone who books, coordinates or holds the reservation for you.

What if we hold a room block under our programme name?

Then the block itself identifies everyone in it as your patients, to every hotel employee who can see the rooming list. That is worth thinking about before you set one up, and it is one of the practical reasons programs move away from blocks.

Does this change if the patient pays for their own room?

It changes a great deal. The analysis above is about information you disclose. When the patient books and pays themselves, you are not disclosing anything to the hotel, and the only record of the trip is the one your program keeps.

Related