Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap
Five Nines Executive Team : Sep 24, 2026, 6:00:00 AM
1 min read
Telehealth platforms typically connect to multiple downstream services: video infrastructure, scheduling, recording, transcription, integration with clinical systems. Each handler of ePHI in the chain requires BAA coverage. Most clinics only have BAA with the primary platform vendor.
The gap is the BAA chain: downstream vendors that the primary vendor uses to deliver telehealth functionality. If those vendors handle ePHI, the chain must include BAAs flowing through.
The CFO question is not whether the clinic has a BAA with its telehealth vendor. It is whether the BAA chain extends through every handler of ePHI, and whether the financial exposure from chain gaps is sized.
Why the Telehealth BAA Chain Is a CFO Responsibility
A clinic CFO walking into telehealth budget discussions typically sees the primary platform line.
How the Telehealth Vendor Chain Actually Works — And Where the Gaps Appear
Primary telehealth vendor signs BAA. That vendor uses video infrastructure, recording services, transcription, and integration providers. Each that handles ePHI needs to be in the BAA chain.
What BAA Chain Gaps Actually Cost When an Incident Occurs
When chain gaps exist and incidents occur, the clinic carries exposure for the gap. Settlements have explicitly cited chain gaps.
What CFO-Level Telehealth BAA Oversight Looks Like
Inventory of all vendors handling telehealth ePHI, BAA coverage for each, flow-down provisions in primary BAA, and gaps if any.
Why "The Vendor Handles Downstream" Leaves the Clinic Exposed
A CFO will hear: the telehealth vendor is responsible for downstream relationships.
False. The covered entity is responsible for ensuring the chain extends.
The BAA Chain Audit That Closes the Coverage Gap
A defensible approach involves healthcare CFO through telehealth BAA chain audit.
The BAA Chain Extends Beyond the Primary Vendor — Audit the Whole Thing
The BAA chain extends beyond the primary vendor. CFOs who size only the primary line miss the chain exposure.
If your clinic has not audited the telehealth BAA chain in the last twelve months, that is the conversation worth having with your Tech-Operations partner.
Five Nines Technology Group is the Tech-Operations partner serving clinics, hospitals, and healthcare practices across the region. We focus on helping CFOs audit BAA chains for telehealth and other multi-vendor clinical workflows.
Frequently asked questions
How does the clinic discover the chain?
Through vendor diligence; ask the primary vendor about their sub-processors handling ePHI.
What if a sub-processor refuses BAA?
The primary vendor is responsible for ensuring sub-processors have appropriate coverage.
How does this interact with cyber insurance?
Carriers ask about telehealth vendor coverage during underwriting.
Should the clinic audit the chain regularly?
Annually at minimum, with material changes triggering review.
What about telehealth platforms designed for healthcare specifically?
Healthcare-specialty platforms typically handle BAA chain better than generic platforms.
How does this affect Risk Analysis?
Telehealth and chain coverage should be in the Risk Analysis explicitly.
What does HHS examine first?
The primary BAA, then asks about the chain.