Business associate
Who counts as a HIPAA business associate, common examples including SaaS and cloud vendors, subcontractors, and what business associates must do.
Business associate at a glance
A HIPAA business associate is a person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides services such as legal, accounting, consulting, IT or billing that involve access to PHI (45 CFR 160.103). Subcontractors that handle PHI for a business associate are business associates too. They must sign a BAA, comply with the Security Rule and report breaches, and are directly liable to HHS for specified HIPAA requirements.
| Defined in | 45 CFR 160.103 |
|---|---|
| Test | Creates, receives, maintains or transmits PHI on behalf of a covered entity |
| Typical examples | Cloud and email providers, billing companies, IT providers, consultants, SaaS vendors, AI tools used with PHI |
| Includes | Subcontractors that handle PHI for a business associate |
| Duties | BAA, Security Rule safeguards, breach reporting, limits on use of PHI |
| Liability | Directly liable to HHS for specified requirements since the 2013 Omnibus Rule |
The definition
Under 45 CFR 160.103, a business associate is a person — other than a member of the covered entity’s workforce — who:
- creates, receives, maintains or transmits PHI on behalf of a covered entity for a regulated function or activity (claims processing, data analysis, billing, practice management and similar); or
- provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services to a covered entity where the service involves PHI.
The definition expressly includes health information organizations and data transmission services, vendors offering personal health records on behalf of a covered entity, and subcontractors that handle PHI for a business associate. A covered entity can itself be a business associate of another covered entity.
Common examples
| Business associate | Why |
|---|---|
| Email, cloud storage or hosting provider | Maintains or transmits ePHI |
| EHR or practice management software | Creates and maintains PHI |
| Medical billing company | Processes claims with PHI |
| IT support or MSP with access to systems | Accesses PHI to provide services |
| AI assistant used with patient information | Receives and processes PHI |
| Lawyer or accountant reviewing patient files | Professional services involving PHI |
What business associates must do
- Sign a business associate agreement with the covered entity — and with their own subcontractors that handle PHI.
- Use and disclose PHI only as the BAA allows.
- Comply with the Security Rule for ePHI, including a risk analysis.
- Report breaches to the covered entity without unreasonable delay and within 60 days of discovery (164.410).
Since the 2013 Omnibus Rule, business associates are directly liable to HHS for a specific list of requirements — including impermissible uses and disclosures, Security Rule compliance, breach notification to the covered entity, BAAs with subcontractors, providing ePHI needed for patient access, and cooperating with investigations. Other Privacy Rule obligations reach them through the BAA. HHS lists them in its direct-liability fact sheet.
Guides
- HIPAA law →How the HIPAA law is structured: the 1996 statute, the HHS regulations in 45 CFR, the HITECH Act and the Omnibus Rule — and who enforces them.
- What is HIPAA? →A plain-English overview of HIPAA: what it protects, who it applies to, the three main rules, patients' rights and how it is enforced.
- Who must comply with HIPAA? →Who HIPAA applies to — covered entities and business associates — with examples, common edge cases like health apps and private-pay practices, and who is outside HIPAA.
Related requirements
- Covered entity →§ 160.103
- Business associate agreements (BAAs) →§ 164.502(e)
- Notifying patients of a breach →§ 164.402
Frequently asked questions
Is my SaaS company a business associate?
If your product creates, receives, maintains or transmits PHI on behalf of a covered entity customer, yes — and you will need to sign BAAs with those customers and with your own subcontractors that touch PHI.
Is a cloud provider a business associate if it can't see the data?
Generally yes. Maintaining encrypted PHI still counts, even without the key, according to HHS guidance on cloud computing.
Are a practice's employees business associates?
No. Workforce members are excluded from the definition; they are covered by the practice's own obligations.