HIPAA Business Associates
A business associate is any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity. If your company provides services to healthcare organizations and handles PHI in the process, you are a business associate and must comply with HIPAA — directly, with your own regulatory liability, whether or not the paperwork is in order.
This lesson matters in both directions. If you are a covered entity or a vendor with downstream vendors, you must identify every business associate and paper the relationship correctly. If you are a SaaS founder selling into healthcare, business associate status is your HIPAA program: it defines what you must build, what you must sign, and what you are on the hook for when something goes wrong.
Who Is (and Is Not) a Business Associate
The test is functional: does the organization create, receive, maintain, or transmit PHI on behalf of a covered entity (or another business associate) in the course of providing services? "Maintain" is doing a lot of work in that sentence — merely storing PHI makes you a business associate even if you never open a single record and even if it is encrypted with keys you do not hold, in OCR's view.
Common business associates: cloud service providers hosting ePHI (AWS, Azure, GCP all sign BAAs for designated services), EHR and health IT vendors, SaaS products used with patient data, medical billing and revenue cycle companies, IT managed service providers, claims processors, transcription services, e-prescribing gateways, data analytics firms, patient communication platforms, shredding and records storage companies, consultants with PHI access, attorneys and accountants handling PHI matters, and health information exchanges.
Not business associates:
- Workforce members — employees and similarly controlled personnel are inside the covered entity, not vendors.
- Conduits — entities that merely transmit PHI transiently without persistent storage: the postal service, couriers, ISPs. OCR reads this exception very narrowly; any meaningful storage defeats it. A fax line is a conduit; a cloud storage bucket is not.
- Treatment disclosures between providers — a specialist receiving a referral gets PHI for treatment, not "on behalf of" anyone; no BAA needed.
- Other covered-entity relationships — a health plan receiving claims from a provider is acting in its own covered capacity.
- Janitorial and incidental-access services — where PHI access is incidental and not part of the service.
- Financial institutions processing standard payment transactions.
| Vendor | BA Status | Why |
|---|---|---|
| Cloud host storing ePHI | Yes | Maintains PHI, even without viewing it |
| Email/productivity suite used with PHI | Yes | Receives and maintains PHI (use HIPAA-eligible tiers) |
| Specialist physician receiving a referral | No | Treatment between providers |
| Courier moving sealed records | No | Conduit exception |
| Analytics vendor receiving only de-identified data | No | De-identified data is not PHI — verify the de-identification |
| Your vendor's hosting subcontractor | Yes | Subcontractor business associate, needs its own BAA |
| Payment processor handling card transactions | Generally no | Financial transaction exception |
The Business Associate Agreement
A Business Associate Agreement (BAA) is a legally required contract between a covered entity and each business associate (and between business associates and their subcontractors). The rule prescribes minimum content; the rest is negotiation.
Required elements include: the permitted and required uses and disclosures of PHI; a prohibition on use or disclosure beyond the agreement or the law; a requirement to use appropriate safeguards and comply with the Security Rule for ePHI; reporting of security incidents and breaches of unsecured PHI to the covered entity; ensuring subcontractors agree in writing to the same restrictions; making PHI available for individual access, amendment, and accounting of disclosures; making internal records available to HHS; and, at termination, returning or destroying PHI where feasible (or extending protections where not). The agreement must also authorize termination if the business associate materially violates it.
What actually gets negotiated — and what founders should watch:
- Breach notification timeline. The rule allows up to 60 days; BAAs typically demand 5 to 15 days, sometimes 72 hours or "without unreasonable delay, not to exceed X." Sign only what your incident response process can actually deliver, and mirror the same timeline down to your subcontractors.
- Definition of reportable events. Some BAAs require reporting every "security incident" including harmless probes; negotiate an aggregate-reporting clause for unsuccessful attempts (blocked pings and scans) so you are not drafting letters about firewall noise.
- Indemnification, liability caps, and audit rights. Not HIPAA requirements at all — pure commercial terms, often the hardest part of the negotiation.
- Data return and destruction mechanics. Backups make literal destruction slow; a clause acknowledging retention in backups until cycle expiry, with continued protections, is standard.
No PHI should flow before a BAA is signed. Sharing PHI with a vendor without a BAA is itself an impermissible disclosure — one of the most common HIPAA violations, and one OCR has penalized on its own. Note that a BAA transfers obligations, not liability: both parties remain independently accountable to OCR.
Direct Obligations of Business Associates
Since the HITECH Act and 2013 Omnibus Rule, business associates carry direct regulatory liability — OCR can investigate and fine you independently of any covered entity, and has done so, including a seven-figure settlement against a business associate whose breach traced back to a missing risk analysis.
As a business associate you must, in your own right:
- Comply with the Security Rule in full — risk analysis, safeguards, policies, training, the works. This is not optional and not inherited from your customer.
- Use and disclose PHI only as your BAA and the Privacy Rule permit — including applying minimum necessary. Using customer PHI for your own product analytics without proper de-identification violates both contract and rule.
- Report breaches upstream within your contractual and regulatory deadlines, as covered in the breach notification lesson.
- Cascade BAAs to subcontractors and remain responsible for the flow-down.
- Support patient rights — provide PHI for access requests, amendments, and accountings as your BAA directs.
- Cooperate with HHS investigations.
Practical translation for a health tech startup: your HIPAA program is a Security Rule program (risk analysis, encryption, MFA, logging, training, policies), a BAA book (upstream with customers, downstream with vendors), a breach runbook tuned to your shortest contractual deadline, and data-use discipline in your product.
Subcontractors: The Chain of Trust
Business associates must ensure that subcontractors who create, receive, maintain, or transmit PHI on their behalf sign BAAs containing the same restrictions. This creates a chain of accountability with no bottom: covered entity → business associate → subcontractor → sub-subcontractor, each link papered, each entity directly liable to OCR.
Example: a hospital (covered entity) uses a care coordination SaaS (business associate), which hosts on a cloud provider (subcontractor BA), and uses an email delivery service for appointment reminders (subcontractor BA), which itself uses a data center vendor (sub-subcontractor). The hospital signs one BAA — with the SaaS. The SaaS signs BAAs with its cloud, email, and any other PHI-touching vendors and is responsible for the chain below it.
For cloud specifically: the major providers sign BAAs covering designated HIPAA-eligible services only. Using a service outside the eligible list with PHI puts you out of compliance even with a BAA in place — check the service list, not just the signature. Also verify HIPAA-eligible tiers for the everyday tools PHI leaks into: support desks, logging platforms, LLM APIs, session-replay tools, and communication apps. If PHI can land there and there is no BAA, you have a gap — either sign one, block the data flow technically, or drop the tool.
Managing Business Associate Relationships
A working BAA program, from the covered entity or upstream-BA side:
- Inventory every vendor and classify PHI exposure — including shadow IT and free-tier tools.
- Execute BAAs before access, gated in procurement so no contract closes without the classification question answered.
- Diligence proportional to risk — security questionnaires, SOC 2 reports, or HITRUST certification for high-volume PHI vendors; a signed BAA alone is a legal document, not evidence of actual security.
- Track agreements centrally with effective dates, notification deadlines, and renewal or template-refresh triggers.
- Monitor annually — attestations, updated reports, incident history.
- Offboard deliberately — trigger the return/destruction clause and collect a destruction certificate.
Business Associate Compliance Checklist
- Determined our status honestly (covered entity, business associate, subcontractor, or none)
- Complete vendor inventory with PHI exposure classification
- BAA executed with every vendor that touches PHI — before any PHI flows
- Cloud usage limited to HIPAA-eligible services under the provider BAA
- Our own Security Rule program in place: risk analysis, safeguards, policies, training
- Upstream BAA obligations cataloged: breach deadlines, incident definitions, audit rights
- Downstream subcontractor BAAs mirror our upstream commitments
- Breach notification runbook meets our shortest contractual deadline
- Product data use reviewed against BAA-permitted purposes; de-identification documented for secondary use
- Patient access, amendment, and accounting support processes defined
- Termination workflow returns or destroys PHI with documentation
- BAA repository current, with owners and annual review dates
- Standard BAA template maintained and legal-reviewed for our side of negotiations
Frequently Asked Questions
We encrypt everything and can't see customer data. Are we still a business associate?
Yes. OCR guidance is explicit that a cloud provider maintaining ePHI is a business associate even if the data is encrypted and it lacks the keys ("no-view" services). Encryption changes your risk profile and may simplify your safeguards analysis, but not your status or your need for a BAA.
Who provides the BAA — us or the customer?
Either. Large covered entities usually insist on their template; startups should still maintain their own founder-friendly template for smaller customers and for downstream vendors. Expect the hospital's version to have shorter breach deadlines, audit rights, and indemnification — read those three sections before anything else.
What happens if we shared PHI with a vendor before signing a BAA?
The disclosure was impermissible: run a breach risk assessment as described in the breach notification lesson, document it, sign the BAA immediately, and fix the procurement gap that let it happen. OCR has settled cases based specifically on missing BAAs, so treat it as a real incident, not a paperwork cleanup.
Do we need a BAA with our penetration testers or auditors?
If they may access PHI while performing services — testing production systems, sampling records — yes. Many teams instead scope engagements to synthetic data or masked environments so no PHI is accessible; either path works, but decide deliberately and document it.
Can a business associate use PHI for its own purposes?
Only as the BAA permits, and the rule allows BAAs to authorize limited things: management and administration of the business associate itself, its legal responsibilities, and data aggregation services for the covered entity's health care operations. Building your own commercial datasets or training models requires de-identification (see the Privacy Rule lesson) or authorization — a BAA clause alone cannot license uses HIPAA prohibits.
How do enterprise healthcare customers evaluate us beyond the BAA?
Security review: expect questionnaires plus requests for a SOC 2 Type II report, HITRUST certification (see What Is HITRUST), penetration test summaries, and your risk analysis process. The BAA gets you legally compliant; third-party assurance gets you through procurement.
Whether you are papering fifty vendor BAAs or proving your own program to a hospital procurement team, tooling matters. AuditXYZ helps you compare compliance automation platforms and auditors so you can manage vendors and demonstrate HIPAA readiness without drowning in spreadsheets.