HIPAA Compliance for Temporary & Contract Staff
Comprehensive guide to screening, training, and compliance requirements for contract workers and temporary healthcare staff
Quick Answer: Temporary and contract staff must complete the same HIPAA training, background checks, and confidentiality agreements as permanent employees, plus sign Business Associate Agreements if they are contractors providing services.
Understanding Temporary vs. Contract Staff Classification
Temporary Staff (via Staffing Agencies)
- Employed by staffing agency, not your organization
- Classified as Business Associates if accessing PHI
- Staffing agency must provide BAA
- Your organization responsible for training and access control
- Agency responsible for background checks
- Limited-term employment (days to months)
Contractors & Consultants
- Independent contractors or consulting firms
- Always Business Associates if accessing PHI
- Must have executed BAA before PHI access
- Contractor responsible for their own security
- Your organization responsible for access control
- May work for extended periods
Per Diem/Call Staff
- Often independent contractors or agency staff
- May be treated as workforce members or Business Associates
- Require same training and agreements regardless of classification
- Background checks required before first shift
Pre-Engagement Compliance Checklist
Before First Shift/Service Delivery
- Verify staffing agency has HIPAA BAA in place
- Obtain copy of contractor's BAA (if applicable)
- Conduct or verify background check completion
- Verify OIG Exclusions List check is current
- Obtain signed confidentiality agreement
- Collect emergency contact information
- Document start date and expected duration
BAA Requirements
Critical: Any temporary staff or contractor accessing PHI must be covered by a Business Associate Agreement. The BAA must address:
- Definition of allowed uses and disclosures of PHI
- Safeguard requirements (physical, technical, administrative)
- Subcontractor management and BAAs
- Breach notification requirements
- Audit and compliance rights
- Return or destruction of PHI upon termination
- Indemnification and liability clauses
Background Check Requirements for Temporary Staff
Staffing Agency Responsibility
- Agency must conduct background checks before assignment
- Obtain copy of background check verification
- Verify criminal background check (7+ years)
- Confirm professional license verification (if applicable)
- Request OIG Exclusions List clearance documentation
- Get confirmation of reference checks
Your Organization's Verification
- Request background check documentation from staffing agency
- Independently verify OIG Exclusions List (LEIE)
- Check state professional licensing boards (nurses, therapists, etc.)
- Document verification dates and results
- Maintain records in compliance file
- Deny access if exclusions found
What to Do If Issues Are Found
- OIG Exclusion: Immediately deny PHI access; report to organization leadership
- Criminal Conviction: Assess job-relevance; may be grounds for denial of assignment
- License Issues: Verify license status; deny if inactive/suspended
- Incomplete Checks: Do not allow PHI access until cleared
- False Information: Report to staffing agency and document
Training and Onboarding for Temporary Staff
Required Training Components
- HIPAA Privacy Rule overview (30-60 minutes)
- HIPAA Security Rule requirements (30-60 minutes)
- Organization-specific policies and procedures
- System access and passwords (if applicable)
- Patient confidentiality expectations
- Incident reporting procedures
- Role-specific training (if applicable)
Documentation Requirements
- Signed confidentiality agreement
- Training completion certification
- Acknowledgment of HIPAA policies
- Badge/access card issuance record
- Trainer name and date
- Retained in compliance file during engagement
Training Responsibility Matrix
| Training Type | Responsibility | Documentation |
|---|---|---|
| HIPAA General Training | Your Organization | Signed certification in file |
| System Access Training | Your IT Department | System logon record |
| Department-Specific Training | Assigned Department | Training log/attestation |
| Contractor Security (if BA) | Contractor | BAA requirements |
Access Control and Monitoring
System Access Provisioning
- Create temporary user accounts with limited permissions
- Restrict access to minimum necessary for job duties
- Enable MFA if accessing systems remotely
- Set account expiration date matching assignment end date
- Document date access was activated
- Monitor access logs for unusual activity
Access Restrictions by Role
- Nursing Pool: EHR access to assigned patients only
- Physician Consultants: EMR access for consultation documentation
- IT Contractors: System admin access to specific systems/timeframes
- Cleaning/Maintenance: No system access; physical access controlled
- Administrative Contractors: Specific database/office suite access only
Ongoing Monitoring
- Monitor system access logs during assignment
- Investigate any unusual access patterns
- Require managers to report behavioral concerns
- Review OIG Exclusions List monthly for current assignments
- Document all monitoring activities
Termination and Off-Boarding
At End of Assignment
- Disable system access on last day
- Retrieve all access badges and credentials
- Collect any physical documentation containing PHI
- Ensure return of organization-issued devices
- Conduct exit confidentiality reminder
- Document termination date in compliance file
- Archive all training and access records
Documentation Retention
- Retain all HIPAA compliance documentation for minimum 6 years
- Keep background check results and verification
- Archive training certificates and attendance records
- Maintain confidentiality agreement signatures
- Store access log summaries
- Retain any incident or discipline records
Post-Termination Obligations
- Confidentiality obligations continue after assignment ends
- May not use PHI learned during assignment for other purposes
- Subject to same sanctions as permanent employees for violations
- Document any ongoing concerns or issues
Specific Scenarios and Compliance Requirements
Agency Nurse/Clinical Staff
Classification: Business Associate (staffing agency)
- Staffing agency must provide BAA
- You verify background checks/OIG clearance
- You provide HIPAA training before assignment
- You control EHR access (minimum necessary)
- You document all access and training
IT Contractor/Consultant
Classification: Business Associate
- Contractor must execute BAA
- BAA addresses system access and security obligations
- Background check required before access
- NDA/confidentiality agreement required
- Access audit and logs required
Per Diem Clinical Pool
Classification: Workforce member (if regular) or Business Associate (if agency)
- Same training and agreements required each shift
- Background checks up-to-date and verified
- OIG Exclusions List checked before each assignment
- Consider whether repeated assignments suggest employment classification
Professional Consultants (Compliance, Quality, etc.)
Classification: Business Associate if accessing PHI
- BAA required even for limited access
- Background check and screening required
- HIPAA training required
- Confidentiality/NDA required
- Document scope of PHI access
Frequently Asked Questions
Q: Do temporary staff need background checks if they're only working one shift?
A: Yes. If they will access PHI, they must have background checks completed before their first shift, even if it's just one day. A HIPAA-compliant background check is a prerequisite for any PHI access, regardless of duration.
Q: Who is responsible for ensuring the staffing agency has a BAA?
A: Your organization is responsible. If the staffing agency doesn't have a BAA when temporary staff are assigned to access PHI, you are in violation. Don't accept staff assignments without confirming BAA is in place first.
Q: Can we use the same confidentiality agreement for both temporary and permanent staff?
A: Yes, you can use the same agreement. The key is that all workforce members—permanent, temporary, or contractor—must sign it before accessing PHI. Some organizations add a supplemental clause for contractors regarding BAA obligations.
Q: What if a contractor is found on the OIG Exclusions List?
A: You must immediately discontinue their work and deny access to all systems and PHI. Notify your compliance officer and leadership. Do not allow them to work in any capacity. Document the finding and action taken.
Protect Your Organization
Medcurity provides BAA templates, compliance checklists, and contractor screening procedures.
Get Contractor Compliance Tools