The short version
- A business associate is any organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Billing companies, IT providers, cloud hosts, transcription services, and many others qualify.
- Since the 2013 Omnibus Rule, business associates are directly liable under the HIPAA Security Rule. OCR can investigate and penalize you without going through your client.
- You must conduct your own risk analysis, implement safeguards, have a written agreement with every covered entity and every subcontractor, and report breaches to your clients within strict timelines.
- The most common gaps are treating the client's compliance as your own, missing subcontractor agreements, and having no risk analysis of your own environment.
A common misconception among vendors to healthcare is that HIPAA is the hospital's problem. The hospital is the covered entity, the vendor is just providing a service, and whatever the contract says about privacy is the extent of the obligation. That was roughly true before 2013. It has not been true since, and organizations still operating on that understanding carry real exposure.
Who is a business associate
HIPAA defines a business associate as a person or organization, other than a member of the covered entity's workforce, that creates, receives, maintains, or transmits protected health information on the covered entity's behalf, or that provides certain services to the covered entity involving PHI.
In practice, the list is long. For a typical medical practice, business associates commonly include:
- The EHR vendor, particularly if hosted
- The billing company or revenue cycle vendor
- The managed IT provider with access to systems holding PHI
- Cloud storage, backup, and email providers
- Transcription and dictation services
- Cloud fax and patient communication platforms
- Shredding and records storage companies
- Consultants, attorneys, and accountants who receive PHI in the course of their work
- Answering services and call centers
- Collection agencies
The test is function, not industry. A software company that never thought of itself as a healthcare vendor becomes a business associate the moment a covered entity uploads patient data to its platform.
The conduit exception is narrow
Some vendors assume they are exempt because they only transmit data and never look at it. HHS recognizes a "conduit" exception, but it is limited to organizations like internet service providers and the postal service that provide transmission only, with access to PHI being transient and incidental. A cloud storage provider that holds encrypted data it cannot read is still a business associate. Persistence of storage, not ability to view, is the deciding factor.
What changed in 2013
Under the original HIPAA rules, business associates had no direct obligations. The covered entity was required to have a contract with them, and that contract imposed privacy and security terms, but enforcement ran through the covered entity. A business associate that mishandled data breached its contract. It did not violate federal law.
The HITECH Act changed that, and the 2013 Omnibus Rule implemented it. Business associates became directly liable for compliance with the entire Security Rule and with specified provisions of the Privacy Rule. OCR gained authority to investigate business associates directly, and to impose civil monetary penalties on them, without any action against the covered entity.
OCR has used that authority. Business associates have been the subject of investigations and settlements in their own right, for failures ranging from missing risk analyses to inadequate access controls to late breach reporting.
What you are required to do
Direct liability under the Security Rule means a business associate must do everything a covered entity does to protect electronic PHI. The core obligations:
Conduct a risk analysis of your own environment
This is the one most often missing. The client's risk analysis covers the client. Yours covers your systems, your staff, your network, your subcontractors. It is required at 45 CFR 164.308(a)(1)(ii)(A) and it applies to you by name. If OCR investigates, this is the first document they will ask for.
Implement administrative, physical, and technical safeguards
Policies and procedures, workforce training, access controls, audit logging, encryption decisions, contingency planning, and the rest of the Security Rule's requirements apply to your organization. The rule is scalable, meaning what is reasonable for a three-person billing company differs from what is reasonable for a national cloud host, but the obligation to address each standard is the same.
Have a business associate agreement with every covered entity client
The covered entity is required to obtain one, but you are also required to have one, and to comply with its terms. If a client has never sent you an agreement, that is a problem for both of you. Raise it.
Have a business associate agreement with every subcontractor
This is the second most common gap. If you use any downstream vendor that touches the PHI you hold, your cloud host, your own IT provider, your backup service, you must have a written agreement with them imposing the same obligations that apply to you. The chain of agreements must be unbroken from the covered entity down to the last subcontractor. A missing link exposes everyone above it.
Report breaches to your covered entity clients
When you discover a breach of unsecured PHI, you must notify the affected covered entity without unreasonable delay and in no case later than 60 days after discovery. Your agreement may, and often does, require faster notice. The covered entity then handles notification to individuals, HHS, and where required the media, but they cannot start until they hear from you. Late notice from a business associate has been a specific finding in enforcement actions.
Use and disclose PHI only as permitted
Your agreement defines what you may do with the data. Using it for anything else, including your own analytics, marketing, or product development, is a violation unless the agreement specifically permits it and the covered entity was permitted to authorize it.
Make PHI available and cooperate with the covered entity
Individuals have rights to access and amend their records and to an accounting of disclosures. Where you hold the data, you must be able to support the covered entity in meeting those obligations.
A frequent point of confusion. Signing a business associate agreement does not make you compliant. It documents that you have agreed to be compliant. The agreement is a promise; the risk analysis, safeguards, and policies are the keeping of it. Vendors who have signed dozens of agreements and conducted zero risk analyses have signed dozens of promises they cannot demonstrate they are keeping.
Where business associates most often fall short
From working with vendors on both sides of these relationships, a few patterns recur:
- Assuming the client's compliance covers you. It does not. Their program addresses their environment.
- No risk analysis of your own. Many vendors have security practices but have never formally analyzed risk to the PHI they hold. Practices without documentation are difficult to demonstrate.
- Missing or outdated subcontractor agreements. Particularly with cloud services adopted informally by staff.
- Treating the agreement as a formality. Signing without reading, and therefore without knowing what notification timeline or security terms were agreed to.
- Breach discovery that never triggers a process. A staff member notices something odd, it is fixed quietly, and nobody considers whether it was a reportable breach with a 60-day clock now running.
- Incidental access treated as no access. IT providers, in particular, sometimes believe that because they do not "use" the data, they are not business associates. Ability to access is what matters.
What the proposed rule would add
The Security Rule revision HHS proposed in January 2025 would place additional obligations on business associates if finalized. Among them: verifying at least annually, through a written analysis by a subject matter expert, that technical safeguards are in place, and providing that verification to covered entity clients; and notifying covered entities within 24 hours of activating a contingency plan. The rule is not yet final and its details may change, but the trajectory is toward more explicit and more frequent demonstration of compliance, not less.
Where to start
If your organization handles PHI for healthcare clients and has not done these things, the sequence is straightforward. Inventory every client relationship and confirm an agreement exists for each. Inventory every subcontractor that touches the data and do the same. Conduct a risk analysis of your own environment. Build the policies and safeguards the analysis says you need. Write down how you will detect and report a breach, and make sure staff know it.
None of this is exotic. It is the same program covered entities have been required to run for two decades, applied to your organization. The difference is that since 2013, the consequences of not having it belong to you.
