HIPAA Business Associates: What They Are and Why They Matter
- May 23, 2026
- Posted by: allan
- Category: Healthcare Law
Most people understand that HIPAA — the Health Insurance Portability and Accountability Act — applies to hospitals, doctors, and health insurance companies. What is far less well understood is that HIPAA’s obligations extend significantly beyond traditional healthcare providers to cover a large and diverse group of businesses and individuals that are called business associates. If your company provides services to a hospital, physician practice, health plan, or other healthcare organization, and if you come into contact with patient health information in doing so, there is a very real possibility that you are a HIPAA business associate — with all of the legal obligations that classification entails.
What Is a HIPAA Business Associate?
A business associate, in HIPAA terminology, is a person or entity that performs certain functions or activities on behalf of a HIPAA-covered entity and that involves the use or disclosure of protected health information (PHI) in doing so. The definition was substantially expanded by the Health Information Technology for Economic and Clinical Health Act in 2009, and it has continued to evolve through regulatory guidance.
The key functional test is whether the service you provide to a covered entity involves creating, receiving, maintaining, or transmitting protected health information. If it does, you are almost certainly a business associate regardless of whether your primary business has anything to do with healthcare. The list of common business associate categories is extensive. It includes medical billing companies, claims processing services, health information organizations, e-prescribing gateways, patient scheduling software providers, cloud storage services that host electronic health records, email or communication platforms used by healthcare providers, data analytics firms that analyze clinical or claims data, transcription services, shredding companies, third-party administrators, collection agencies processing healthcare debts, law firms and accounting firms that access PHI in the course of their engagements, and many others.
The Subcontractor Rule: Business Associates of Business Associates
HIPAA’s business associate definition also extends to subcontractors. If you are a business associate and you engage a subcontractor to help you perform your services, and that subcontractor will have access to the PHI you received from the covered entity, your subcontractor is also a business associate under HIPAA and has the same direct compliance obligations that you do.
This means that a cloud hosting company hired by a medical billing company to store billing data is itself a business associate subject to HIPAA. A translation service hired by a hospital to translate patient records is a business associate. An IT support firm with remote access to a healthcare provider’s systems is a business associate if those systems contain PHI. Many technology companies are surprised to discover that their contracts with healthcare sector customers create this downstream compliance obligation, which flows through the supply chain.
What Does a Business Associate Have to Do?
Business associates are directly subject to many of the same HIPAA obligations that apply to covered entities. This is a significant development compared to the original HIPAA framework, under which business associates were primarily regulated through their contracts rather than directly by the law.
Business associates must comply with the HIPAA Security Rule in full, which means implementing administrative, physical, and technical safeguards to protect electronic protected health information. They must conduct a risk analysis, implement a risk management program, train employees on security policies and procedures, and maintain documentation of their security program. Business associates must also comply with the Privacy Rule’s use and disclosure requirements, meaning they can only use or disclose PHI as permitted by their business associate agreement and by applicable law.
Business associates must report any security incidents involving PHI to the covered entity without unreasonable delay. If a breach of unsecured PHI occurs, the business associate must notify the covered entity within 60 days of discovering the breach and must include specific information about the nature of the breach, the types of PHI involved, the number of individuals affected, the steps taken to investigate and mitigate the incident, and the steps taken to prevent recurrence. The covered entity then has its own notification obligations to affected individuals, HHS, and in some cases the media.
The Business Associate Agreement
Before a covered entity may share PHI with a business associate, HIPAA requires them to enter into a Business Associate Agreement, commonly called a BAA. The BAA is a written contract that establishes the terms under which the business associate may use and disclose PHI, the obligations the business associate must fulfill to protect PHI, and the consequences of a failure to comply.
A HIPAA-compliant BAA must contain specific provisions required by the Privacy Rule. It must establish the permitted and required uses and disclosures of PHI by the business associate. It must prohibit the business associate from using or disclosing PHI other than as permitted by the agreement or required by law. It must require the business associate to implement appropriate safeguards, including compliance with the Security Rule for electronic PHI. It must require the business associate to report to the covered entity any security incident or breach involving PHI. It must require the business associate to make PHI available to the covered entity so that individuals can exercise their rights. And it must require the business associate to return or destroy all PHI at the conclusion of the relationship.
Operating as a business associate without a signed BAA in place is itself a HIPAA violation. Both the covered entity and the business associate can face penalties for this failure. The covered entity is at risk if it discloses PHI to a business associate without a proper BAA. The business associate is at risk because it is accepting and using PHI that it has no legal authority to hold.
What the BAA Does Not Do
A common misunderstanding among businesses new to HIPAA compliance is that signing a BAA is the end of the compliance obligation. It is not. The BAA is a legal agreement — it documents what the parties have promised to do — but it does not by itself create the technical safeguards, policies, or training programs that HIPAA requires. A business associate that signs a BAA but fails to implement a Security Rule-compliant information security program is in violation of HIPAA regardless of what the BAA says.
Covered entities sometimes treat the BAA as a liability transfer device: if a breach occurs, they can point to the BAA and say the business associate was responsible. While the BAA does allocate certain contractual responsibilities, HIPAA enforcement is a direct regulatory matter, not merely a contractual one. The Office for Civil Rights can and does investigate and penalize business associates directly, independently of whatever the BAA says about indemnification or responsibility.
Negotiating and Reviewing Business Associate Agreements
When a covered entity presents you with a BAA to sign, you should read it carefully rather than treating it as boilerplate. BAAs vary significantly in their terms, and some include obligations that go well beyond what HIPAA requires. Some BAAs require the business associate to indemnify the covered entity for the costs of any breach notification resulting from the business associate’s conduct. Some impose requirements about the business associate’s security practices that are more specific or demanding than the Security Rule itself. Some include data return or destruction timelines that may conflict with the business associate’s own data retention policies or legal obligations.
Business associates should also pay attention to what the BAA permits the covered entity to do with the relationship if a breach occurs. Some BAAs give the covered entity the right to audit the business associate’s security practices, require the business associate to cooperate with investigations, or impose financial penalties that go beyond what HIPAA itself would require.
If you are the covered entity presenting a BAA to a vendor, you should ensure the BAA is tailored to the actual services being provided and that it includes all required HIPAA provisions. A BAA that is missing required elements does not satisfy HIPAA’s requirements and may not provide the contractual protections you are relying on.
HIPAA Enforcement Against Business Associates: The Stakes Are Real
The Office for Civil Rights has pursued enforcement actions against business associates of all sizes, including small companies that provide technology services or administrative support to healthcare providers. Civil penalties for HIPAA violations are organized into four tiers based on the level of culpability, ranging from $141 per violation (for violations where the business associate did not know and could not have known of the violation) to more than $2 million per violation category per calendar year (for violations constituting willful neglect that is not corrected). Violations can also be referred for criminal prosecution in cases involving knowing misuse of PHI.
Understanding your status as a business associate, signing proper BAAs, implementing a HIPAA-compliant security program, and training your employees on privacy and security obligations is not merely a legal formality. It is a genuine risk management necessity for any business that provides services to the healthcare industry.
