Home
Common Examples of Business Associates Under HIPAA Regulations
Identifying a Business Associate is a critical task for any healthcare organization or service provider operating within the United States. Under the Health Insurance Portability and Accountability Act (HIPAA), a Business Associate is defined as a person or entity that performs certain functions or activities that involve the use or disclosure of Protected Health Information (PHI) on behalf of, or provides services to, a covered entity. This definition extends far beyond simple healthcare providers, touching upon technology firms, legal professionals, and administrative support services.
The significance of this classification lies in legal liability. Since the implementation of the HITECH Act, Business Associates are directly liable for compliance with many aspects of the HIPAA Privacy and Security Rules. Understanding who fits this description through concrete examples is the first step in ensuring regulatory compliance and protecting patient privacy.
Technology and IT Infrastructure Providers
In the modern digital landscape, IT vendors represent the largest and most diverse category of Business Associates. Any tech company that creates, receives, maintains, or transmits PHI on behalf of a healthcare provider or health plan falls under this umbrella.
Cloud Service Providers (CSPs)
Cloud computing has become the backbone of healthcare data management. Whether a provider uses Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS), if PHI is stored on those servers, the CSP is a Business Associate. Even if the data is encrypted and the CSP does not have the decryption key, they are still considered to be "maintaining" PHI.
For instance, a hospital using a major cloud platform to store patient imaging files must have a signed Business Associate Agreement (BAA) with that platform. The fact that the cloud provider's employees never actually "read" the files is irrelevant under the law; the act of hosting the data is enough to trigger the classification.
Electronic Health Record (EHR) Vendors
EHR systems are the primary repositories of PHI. The companies that develop, host, and provide technical support for these systems are quintessential Business Associates. These vendors often have administrative access to the database to perform updates, troubleshoot performance issues, or manage backups, which inherently involves potential exposure to sensitive patient records.
Managed Service Providers (MSPs) and IT Support
Many small to medium-sized clinics outsource their entire IT department to Managed Service Providers. These firms monitor networks, manage firewalls, and provide help-desk support. Because MSP technicians often use remote desktop tools to access computers containing PHI or manage the servers where medical records reside, they qualify as Business Associates.
In a typical scenario observed in the industry, an MSP might be hired only to manage network security. However, if their security scans or log management tools ingest data that includes patient names or identifiers, they have crossed the threshold into Business Associate territory.
Financial and Administrative Outsourcing
Healthcare is not just about clinical care; it is a complex business involving vast amounts of administrative and financial data. Organizations that help manage these "back-office" functions are frequently Business Associates.
Medical Billing and Revenue Cycle Management
Billing companies are perhaps the most recognizable examples. They receive patient diagnosis codes, insurance information, and personal identifiers to submit claims to payers. Because their entire business model relies on the processing of PHI to secure payment for the covered entity, they are bound by HIPAA regulations as Business Associates.
Third-Party Administrators (TPAs)
In the insurance and health plan sector, TPAs handle the heavy lifting of claims processing, utilization review, and member enrollment. A TPA assisting a self-insured employer’s health plan is a Business Associate because they are performing a core function of the "Health Plan" (the covered entity) using PHI.
Medical Transcription Services
While the use of AI-driven transcription is rising, many providers still use external services to convert voice recordings into written medical reports. These recordings and the resulting documents are rich in PHI. The transcriptionists and the companies they work for are Business Associates because they are "creating" and "transmitting" PHI on behalf of the physician.
Document Shredding and Disposal Firms
Physical security is as important as digital security. Companies contracted to haul away and destroy paper medical records or old hard drives are Business Associates. Their service involves the handling of PHI, and a breach in their chain of custody could lead to a significant HIPAA violation for the covered entity.
Professional and Legal Service Providers
A common misconception is that Business Associate status only applies to those in the "healthcare supply chain." In reality, professional service providers who require access to PHI to perform their jobs are also included.
Law Firms and Legal Counsel
Attorneys representing hospitals in malpractice suits, merger negotiations, or healthcare fraud investigations often need to review patient charts to build their cases. When a law firm receives these records, they become a Business Associate. They must implement the same level of technical and administrative safeguards as the hospital itself to protect that data.
Accounting and Audit Firms
CPA firms conducting financial audits for healthcare organizations may need to verify billing records against actual services rendered. This verification process often involves looking at patient files to ensure the numbers match. Therefore, accountants who touch PHI during an audit are classified as Business Associates.
Healthcare Consultants
Consultants hired to improve operational efficiency, conduct compliance audits, or analyze patient outcomes are Business Associates if their analysis requires access to identifiable patient data. If the consultant only works with "de-identified" data (where all 18 HIPAA identifiers have been removed), they might not be a Business Associate, but most high-level strategic consulting in healthcare requires at least some access to the raw data.
Digital Health, Apps, and AI Tools
As healthcare moves toward mobile platforms and artificial intelligence, the boundaries of the Business Associate definition are being tested by new technologies.
Telehealth Platforms
Companies that provide the video conferencing infrastructure specifically designed for clinical visits are Business Associates. Unlike a standard "conduit" (like a telephone landline), these platforms often provide recording features, chat logs, and integration with EHRs, meaning they "maintain" and "transmit" PHI.
Patient Engagement and CRM Tools
Marketing agencies or software companies that provide Customer Relationship Management (CRM) tools for patient outreach are often Business Associates. If a hospital uses a platform to send personalized appointment reminders or post-discharge instructions, that platform is handling PHI (names, phone numbers, and clinical status).
It is a common pitfall for marketing departments to assume that because they aren't "medical" vendors, HIPAA doesn't apply. However, in our experience, the use of a patient list for any purpose—even a newsletter—triggers the requirement for a BAA if the vendor is managing that list.
AI and Data Analytics Platforms
AI companies that ingest large datasets to train diagnostic algorithms or predict patient readmission rates are Business Associates. The complexity here lies in the "secondary use" of data. If the AI firm is performing this analysis on behalf of the hospital to improve the hospital's own operations, they are a BA.
The Downstream Chain: Subcontractors as Business Associates
One of the most critical updates provided by the HIPAA Omnibus Rule is the inclusion of "subcontractors" in the definition of a Business Associate.
A subcontractor is a person or entity to whom a Business Associate delegates a function, activity, or service that involves PHI. The law creates a chain of responsibility:
- Covered Entity (e.g., a Hospital) signs a BAA with a Business Associate (e.g., a Billing Company).
- The Billing Company hires a Subcontractor (e.g., a Cloud Storage provider to store the billing data).
- The Subcontractor is now also a Business Associate under the law and must sign a BAA with the Billing Company.
This means that even if a company has no direct contract with a hospital, they can still be a HIPAA Business Associate if they are handling that hospital's data through an intermediary. Every link in the chain is directly liable to the Department of Health and Human Services (HHS) for data breaches.
Who Is Not a Business Associate?
To avoid "over-compliance" and unnecessary administrative burdens, it is equally important to understand who does not qualify as a Business Associate.
Workforce Members
Employees, volunteers, and trainees of a covered entity are part of the entity's workforce. They are not Business Associates. Their actions are governed by the entity's internal policies, not a BAA.
The Conduit Exception
Entities that move PHI from one point to another but do not have access to it except on a random or infrequent basis are "conduits."
- The U.S. Postal Service and private couriers like FedEx or UPS are conduits.
- Internet Service Providers (ISPs) like Comcast or AT&T are generally considered conduits because they simply provide the "pipes" through which encrypted data flows.
- Note: A cloud storage provider is not a conduit because they store data for long periods, whereas a conduit only handles data in transit.
Incidental Contact Vendors
Vendors whose primary job has nothing to do with PHI, and whose access to it would be incidental, are not Business Associates.
- Janitorial Services: A cleaning crew that enters a clinic after hours is not a BA, even if they might see a file left on a desk. The clinic is responsible for "reasonable safeguards" (like a clean-desk policy), but the cleaners do not need to sign a BAA.
- Electricians or Plumbers: Maintenance workers who might be in the vicinity of PHI are not Business Associates.
Disclosures for Treatment
When one doctor sends a patient’s records to a specialist for a referral, they are not Business Associates of each other. They are both Covered Entities. HIPAA allows for the free flow of information between covered entities for the purpose of treatment, payment, and healthcare operations without the need for a BAA.
What Must Be in a Business Associate Agreement?
If you determine that a vendor is a Business Associate, a BAA is not just a suggestion—it is a legal requirement. A compliant BAA must contain specific elements:
- Permitted Uses: Clearly state what the BA can and cannot do with the PHI.
- Safeguards: Require the BA to use appropriate administrative, physical, and technical safeguards to protect the data, specifically mentioning compliance with the HIPAA Security Rule.
- Breach Notification: Obligate the BA to report any unauthorized use or disclosure (a breach) to the covered entity within a specific timeframe.
- Subcontractor Compliance: Ensure the BA agrees that any subcontractors they use will also sign a BAA and follow the same rules.
- Access Rights: Require the BA to make PHI available to the covered entity so the entity can fulfill patient requests for access or amendments to their records.
- Termination Clause: Allow the covered entity to terminate the contract if the BA violates a material term of the agreement.
- Return or Destruction of Data: Specify that at the end of the contract, the BA must return or destroy all PHI.
How to Determine if Your Vendor Is a Business Associate
When evaluating a new partnership, we recommend a three-step litmus test to decide if a BAA is necessary:
- Is the client a Covered Entity? (Are they a healthcare provider, health plan, or clearinghouse?)
- Will the vendor create, receive, maintain, or transmit PHI? (Even if the data is encrypted or the vendor "won't look at it.")
- Is the vendor a member of the client's workforce? (If they are an outside contractor/company, the answer is usually no.)
If the answer to the first two is "Yes" and the third is "No," the vendor is a Business Associate.
Conclusion
The definition of a Business Associate is broad and continues to expand as healthcare becomes more integrated with external technology and service providers. From the cloud giants hosting terabytes of medical images to the local law firm reviewing a single patient chart, the requirement for HIPAA compliance is a shared responsibility.
Failing to identify a Business Associate or neglecting to sign a BAA can result in severe financial penalties from the Office for Civil Rights (OCR), even if no data breach occurs. For service providers, accepting PHI without a BAA in place is a high-stakes risk that invites direct federal oversight. By understanding these examples and the underlying legal framework, organizations can build safer, more compliant partnerships that prioritize the security of patient information.
Frequently Asked Questions
Is an answering service a Business Associate?
Yes. If an answering service takes messages for a doctor’s office that include patient names, symptoms, or appointment details, they are receiving and transmitting PHI and must have a BAA.
Does a software developer need a BAA if they only see "test data"?
If the "test data" is real patient data that hasn't been fully de-identified, yes. If the developer uses purely synthetic data that was never associated with a real person, then no BAA is required.
Are banks Business Associates?
Generally, no. HIPAA has a specific exception for financial institutions that are limited to processing banking transactions (like clearing a check or processing a credit card payment). However, if the bank provides "value-added" services like health savings account (HSA) management or detailed healthcare data analysis, they may become a Business Associate.
Can a Business Associate be sued by a patient?
Currently, HIPAA does not provide for a "private right of action," meaning a patient cannot sue a BA directly for a HIPAA violation. However, patients can sue under state privacy laws or for breach of contract, and the HHS can levy massive fines against the BA directly.
Does a janitorial service need a BAA?
No. Their access to PHI is considered "incidental." The covered entity is expected to use reasonable safeguards (like locking file cabinets) rather than requiring the cleaning crew to sign a BAA.
-
Topic: Business Associates | HHS.govhttps://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
-
Topic: HIPAA Business Associate Agreement - 2026 Updatehttps://www.hipaajournal.com/hipaa-business-associate-agreement/?__hsfp=f5552f786d1246ec7e5ceba22c578058&__hssc=7610925.1.1782932674170&__hstc=7610925.8d0f3653a7579306b819360fe190b586.1782932674170.1782932674170.1782932674170.1
-
Topic: How to know if you’re a business associatehttps://www.paubox.com/blog/how-to-know-if-youre-a-business-associate