Insight · Business Associates

HIPAA requirements for business associates: what you are directly on the hook for

If your company handles patient information for a healthcare client, HIPAA applies to you directly, not just through your contract. Here is who qualifies, what the rule requires, and the gaps that most often catch vendors off guard.

By Thomas J. Johnson, Founder, EHR Resources LLC September 6, 2026 8 minute read

The short version

  • A business associate is any organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Billing companies, IT providers, cloud hosts, transcription services, and many others qualify.
  • Since the 2013 Omnibus Rule, business associates are directly liable under the HIPAA Security Rule. OCR can investigate and penalize you without going through your client.
  • You must conduct your own risk analysis, implement safeguards, have a written agreement with every covered entity and every subcontractor, and report breaches to your clients within strict timelines.
  • The most common gaps are treating the client's compliance as your own, missing subcontractor agreements, and having no risk analysis of your own environment.

A common misconception among vendors to healthcare is that HIPAA is the hospital's problem. The hospital is the covered entity, the vendor is just providing a service, and whatever the contract says about privacy is the extent of the obligation. That was roughly true before 2013. It has not been true since, and organizations still operating on that understanding carry real exposure.

Who is a business associate

HIPAA defines a business associate as a person or organization, other than a member of the covered entity's workforce, that creates, receives, maintains, or transmits protected health information on the covered entity's behalf, or that provides certain services to the covered entity involving PHI.

In practice, the list is long. For a typical medical practice, business associates commonly include:

The test is function, not industry. A software company that never thought of itself as a healthcare vendor becomes a business associate the moment a covered entity uploads patient data to its platform.

The conduit exception is narrow

Some vendors assume they are exempt because they only transmit data and never look at it. HHS recognizes a "conduit" exception, but it is limited to organizations like internet service providers and the postal service that provide transmission only, with access to PHI being transient and incidental. A cloud storage provider that holds encrypted data it cannot read is still a business associate. Persistence of storage, not ability to view, is the deciding factor.

What changed in 2013

Under the original HIPAA rules, business associates had no direct obligations. The covered entity was required to have a contract with them, and that contract imposed privacy and security terms, but enforcement ran through the covered entity. A business associate that mishandled data breached its contract. It did not violate federal law.

The HITECH Act changed that, and the 2013 Omnibus Rule implemented it. Business associates became directly liable for compliance with the entire Security Rule and with specified provisions of the Privacy Rule. OCR gained authority to investigate business associates directly, and to impose civil monetary penalties on them, without any action against the covered entity.

OCR has used that authority. Business associates have been the subject of investigations and settlements in their own right, for failures ranging from missing risk analyses to inadequate access controls to late breach reporting.

What you are required to do

Direct liability under the Security Rule means a business associate must do everything a covered entity does to protect electronic PHI. The core obligations:

Conduct a risk analysis of your own environment

This is the one most often missing. The client's risk analysis covers the client. Yours covers your systems, your staff, your network, your subcontractors. It is required at 45 CFR 164.308(a)(1)(ii)(A) and it applies to you by name. If OCR investigates, this is the first document they will ask for.

Implement administrative, physical, and technical safeguards

Policies and procedures, workforce training, access controls, audit logging, encryption decisions, contingency planning, and the rest of the Security Rule's requirements apply to your organization. The rule is scalable, meaning what is reasonable for a three-person billing company differs from what is reasonable for a national cloud host, but the obligation to address each standard is the same.

Have a business associate agreement with every covered entity client

The covered entity is required to obtain one, but you are also required to have one, and to comply with its terms. If a client has never sent you an agreement, that is a problem for both of you. Raise it.

Have a business associate agreement with every subcontractor

This is the second most common gap. If you use any downstream vendor that touches the PHI you hold, your cloud host, your own IT provider, your backup service, you must have a written agreement with them imposing the same obligations that apply to you. The chain of agreements must be unbroken from the covered entity down to the last subcontractor. A missing link exposes everyone above it.

Report breaches to your covered entity clients

When you discover a breach of unsecured PHI, you must notify the affected covered entity without unreasonable delay and in no case later than 60 days after discovery. Your agreement may, and often does, require faster notice. The covered entity then handles notification to individuals, HHS, and where required the media, but they cannot start until they hear from you. Late notice from a business associate has been a specific finding in enforcement actions.

Use and disclose PHI only as permitted

Your agreement defines what you may do with the data. Using it for anything else, including your own analytics, marketing, or product development, is a violation unless the agreement specifically permits it and the covered entity was permitted to authorize it.

Make PHI available and cooperate with the covered entity

Individuals have rights to access and amend their records and to an accounting of disclosures. Where you hold the data, you must be able to support the covered entity in meeting those obligations.

A frequent point of confusion. Signing a business associate agreement does not make you compliant. It documents that you have agreed to be compliant. The agreement is a promise; the risk analysis, safeguards, and policies are the keeping of it. Vendors who have signed dozens of agreements and conducted zero risk analyses have signed dozens of promises they cannot demonstrate they are keeping.

Where business associates most often fall short

From working with vendors on both sides of these relationships, a few patterns recur:

What the proposed rule would add

The Security Rule revision HHS proposed in January 2025 would place additional obligations on business associates if finalized. Among them: verifying at least annually, through a written analysis by a subject matter expert, that technical safeguards are in place, and providing that verification to covered entity clients; and notifying covered entities within 24 hours of activating a contingency plan. The rule is not yet final and its details may change, but the trajectory is toward more explicit and more frequent demonstration of compliance, not less.

Where to start

If your organization handles PHI for healthcare clients and has not done these things, the sequence is straightforward. Inventory every client relationship and confirm an agreement exists for each. Inventory every subcontractor that touches the data and do the same. Conduct a risk analysis of your own environment. Build the policies and safeguards the analysis says you need. Write down how you will detect and report a breach, and make sure staff know it.

None of this is exotic. It is the same program covered entities have been required to run for two decades, applied to your organization. The difference is that since 2013, the consequences of not having it belong to you.

Thomas J. Johnson
About the author

Thomas J. Johnson, Founder, EHR Resources LLC

Thomas founded EHR Resources in 2011 after three years helping more than 1,400 practices adopt electronic health records under the Meaningful Use program. He served on a national HHS working group that developed guidance for covered entities conducting their own security risk analyses, and has spent the years since conducting them. Read his message to prospective clients or browse more articles.

Have a question this didn't answer?

A short conversation about where you stand is free and confidential. You will speak with Thomas directly, and there is no obligation on the other side.

Request a consultation