hipaa.systems
General provisions · 45 CFR 160.103, 164.502(e)

Business associate

Who counts as a HIPAA business associate, common examples including SaaS and cloud vendors, subcontractors, and what business associates must do.

Checked 2026-10-06Sources 5

Business associate at a glance

A HIPAA business associate is a person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides services such as legal, accounting, consulting, IT or billing that involve access to PHI (45 CFR 160.103). Subcontractors that handle PHI for a business associate are business associates too. They must sign a BAA, comply with the Security Rule and report breaches, and are directly liable to HHS for specified HIPAA requirements.

Defined in45 CFR 160.103
TestCreates, receives, maintains or transmits PHI on behalf of a covered entity
Typical examplesCloud and email providers, billing companies, IT providers, consultants, SaaS vendors, AI tools used with PHI
IncludesSubcontractors that handle PHI for a business associate
DutiesBAA, Security Rule safeguards, breach reporting, limits on use of PHI
LiabilityDirectly liable to HHS for specified requirements since the 2013 Omnibus Rule

The definition

Under 45 CFR 160.103, a business associate is a person — other than a member of the covered entity’s workforce — who:

  • creates, receives, maintains or transmits PHI on behalf of a covered entity for a regulated function or activity (claims processing, data analysis, billing, practice management and similar); or
  • provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services to a covered entity where the service involves PHI.

The definition expressly includes health information organizations and data transmission services, vendors offering personal health records on behalf of a covered entity, and subcontractors that handle PHI for a business associate. A covered entity can itself be a business associate of another covered entity.

Common examples

Business associate Why
Email, cloud storage or hosting provider Maintains or transmits ePHI
EHR or practice management software Creates and maintains PHI
Medical billing company Processes claims with PHI
IT support or MSP with access to systems Accesses PHI to provide services
AI assistant used with patient information Receives and processes PHI
Lawyer or accountant reviewing patient files Professional services involving PHI

What business associates must do

  • Sign a business associate agreement with the covered entity — and with their own subcontractors that handle PHI.
  • Use and disclose PHI only as the BAA allows.
  • Comply with the Security Rule for ePHI, including a risk analysis.
  • Report breaches to the covered entity without unreasonable delay and within 60 days of discovery (164.410).

Since the 2013 Omnibus Rule, business associates are directly liable to HHS for a specific list of requirements — including impermissible uses and disclosures, Security Rule compliance, breach notification to the covered entity, BAAs with subcontractors, providing ePHI needed for patient access, and cooperating with investigations. Other Privacy Rule obligations reach them through the BAA. HHS lists them in its direct-liability fact sheet.

Guides

Frequently asked questions

Is my SaaS company a business associate?

If your product creates, receives, maintains or transmits PHI on behalf of a covered entity customer, yes — and you will need to sign BAAs with those customers and with your own subcontractors that touch PHI.

Is a cloud provider a business associate if it can't see the data?

Generally yes. Maintaining encrypted PHI still counts, even without the key, according to HHS guidance on cloud computing.

Are a practice's employees business associates?

No. Workforce members are excluded from the definition; they are covered by the practice's own obligations.