The short version
- The test is function, not sight. Under 45 CFR § 160.103 a business associate is a person who creates, receives, maintains or transmits protected health information on behalf of a covered entity for a regulated function — or who provides legal, accounting, consulting, management, administrative or financial services where providing them involves disclosure of PHI.
- The conduit exception is not written in the regulation. It is HHS's reading of "access on a routine basis" in the definition, and the 2013 preamble calls it "a narrow one" covering couriers and internet service providers. The line drawn there is transient versus persistent access, not whether the vendor looks.
- Encryption does not exempt anyone. An entity that maintains PHI on a covered entity's behalf "is a business associate and not a conduit, even if the entity does not actually view the protected health information".
- Twelve terms are compulsory: § 164.504(e)(2) sets ten specific promises plus the permitted-use clause and the termination right, and § 164.314(a)(2)(i) adds Security Rule compliance, subcontractor flow-down and security-incident reporting. Everything else in a BAA — indemnity, insurance, audit rights, a shorter breach clock — is negotiable and nothing requires it.
The vendor's objection is nearly always the same sentence: we do not look at your data, so we are just a pipe. It is said in good faith and it is wrong about the rule, which asks what the vendor does with the information rather than what the vendor reads.
What actually makes a vendor a business associate
The definition at 45 CFR § 160.103 has two limbs. The first catches a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter" — the section then names claims processing, data analysis, utilisation review, quality assurance, billing, benefit management, practice management and repricing. The second catches anyone providing legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services "where the provision of the service involves the disclosure of protected health information".
Paragraph (3) adds three categories by name: a Health Information Organization, E-prescribing Gateway or other data transmission provider "that requires access on a routine basis" to PHI; anyone offering a personal health record on a covered entity's behalf; and any subcontractor further down the chain. Paragraph (4) then carves out four situations, and the useful one is the first — a health care provider is not a business associate "with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual". The referral letter to a specialist needs no agreement, and neither does the records release a patient signs.
Two facts decide it, and neither one alone
How long does it hold the information?
Does the vendor look at the information?
No, or only at random
Yes, to do the job
In transit only
Conduit
A courier, the postal service, an ISP carrying traffic. No agreement needed.
Business associate
Routine access to do the work is exactly what paragraph (3)(i) describes.
It maintains it
Business associate
Storage is the service. Encrypted and key-less makes no difference.
Business associate
The uncontested case, and the smallest share of real disputes.
The conduit exception is narrower than the people invoking it think
There is no conduit exception in the regulation. It is HHS's interpretation of what "access on a routine basis" means, set out when the Omnibus Rule was finalised in January 2013: "The conduit exception is a narrow one and is intended to exclude only those entities providing mere courier services, such as the U.S. Postal Service or United Parcel Service and their electronic equivalents, such as internet service providers (ISPs) providing mere data transmission services." A conduit transports information but does not access it other than on a random or infrequent basis.
The load-bearing sentence comes next. The exception "is limited to transmission services (whether digital or hard copy), including any temporary storage of transmitted data incident to such transmission. In contrast, an entity that maintains protected health information on behalf of a covered entity is a business associate and not a conduit, even if the entity does not actually view the protected health information." HHS gives the example itself: a document storage company is a business associate whether or not it ever opens a box.
What the rule requires the contract to say
§ 164.502(e)(2) requires the assurances to be documented in a written contract meeting § 164.504(e). That section is short and specific. The permitted-use clause comes first, and it is a ceiling rather than a licence: the contract "may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity". Only two things sit outside that ceiling — use for the business associate's own proper management and administration under § 164.504(e)(4), and data aggregation for the covered entity's health care operations.
The promises § 164.504(e)(2)(ii) makes compulsory
A business associate agreement, stripped to what is mandatory
That is the whole compulsory list. Everything a real negotiation is about is absent from it: indemnity, a liability cap, insurance limits, audit rights, who pays for the credit monitoring and the notification mailing, and how fast the vendor must call you. A vendor holding the line on an unlimited indemnity is not refusing to be HIPAA compliant.
Start the underlying vendor agreement
A BAA rides on top of a services contract and does not replace one. Where the commercial terms live in a separate document, that is where the liability, insurance and termination bargain has to be struck.
Agency, and who owns the sixty-day clock
Two provisions people read separately do most of the damage together. § 160.402(c)(1) makes a covered entity liable for a civil money penalty "for a violation based on the act or omission of any agent of the covered entity, including a workforce member or business associate, acting within the scope of the agency". § 164.404(a)(2) then deems a breach discovered by the covered entity as soon as it is known to any agent. If your vendor is your agent, its bad Tuesday is your bad Tuesday, and your notification clock started before anyone rang you.
Whether a vendor is an agent is not settled by the label on the contract. HHS applies the federal common law: "The essential factor ... is the right or authority of a covered entity to control the business associate's conduct." A BAA that simply sets terms, so the only remedy is to amend it or sue, generally does not create agency. One that lets the practice direct how the service is performed after the fact — HHS's example is a clause requiring the associate to release records "based on the instructions to be provided by or under the direction of a covered entity" — generally does. Calling the vendor an independent contractor changes nothing.
Two clocks, and the gap between them
Day 0
The vendor discovers it
Deemed discovered when any employee or agent other than the wrongdoer knew, or by reasonable diligence would have known.
By day 60
The vendor must tell you
§ 164.410(b): without unreasonable delay and in no case later than 60 calendar days after its discovery.
Day 60 from yours
Patients and, at 500+, the Secretary
§ 164.404(b) and § 164.408(b). Below 500 individuals the Secretary is told on an annual log within 60 days of year end.
The chain does not stop at your vendor
Every subcontractor that touches the information is itself a business associate, and the duty to paper it travels with the delegation rather than with the relationship to you. § 164.502(e)(1)(i) is explicit that a covered entity "is not required to obtain such satisfactory assurances from a business associate that is a subcontractor"; § 164.502(e)(1)(ii) puts that obligation on your vendor instead. HHS put the reach plainly in 2013: covered entities must obtain assurances from their business associates, "and business associates must do the same with regard to subcontractors, and so on, no matter how far ‘down the chain’ the information flows".
The five vendors small practices get wrong
| The vendor | Where it lands | The term that matters |
|---|---|---|
| AI scribe or ambient note tool | Business associate. It receives the consultation audio and creates the note. | Whether the agreement lets the vendor train its models on your patients' PHI. That is neither its own management and administration nor data aggregation, which § 164.501 confines to analyses relating to the covered entities' own operations. |
| Email and e-fax | A hosted service that stores the messages maintains PHI. An ISP merely carrying the traffic is a conduit. | Whether your account tier is one the vendor will sign for — many will sign only above a certain plan. |
| Reminder and marketing platforms | Business associate. Reminders are treatment communications; campaigns are not. | The marketing clause. Paid third-party promotion generally needs patient authorisation, whatever the BAA permits. |
| Outsourced IT and managed services | Business associate wherever the engineer holds credentials to systems holding ePHI. | Whether access is persistent. The conduit reasoning does not survive an administrator account. |
| Website analytics and tracking pixels | Depends entirely on whether the vendor will sign. Most large ad platforms will not. | What runs on authenticated pages. Nothing that transmits identified PHI to a non-signing vendor belongs on a patient portal. |
A signed BAA is not a compliance programme
The agreement is the paperwork of one obligation among many, and filing it does not discharge the others. § 164.306(a) applies the Security Rule to covered entities and business associates alike, and § 164.308(a)(1)(ii)(A) requires each of them to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities" to the ePHI it holds. A folder of countersigned agreements and no risk analysis is the least useful half of the file.
For vendors, the exposure is direct rather than contractual. § 160.402(a) lets the Secretary impose a civil money penalty on "a covered entity or business associate" that violates an administrative simplification provision, and since HITECH the Security Rule, the breach notification duty and the limits on use and disclosure apply to associates in their own right. OCR does not enforce your BAA's terms against your vendor — it enforces the Rules. That is also why the contract still matters: your indemnity is the only thing that moves money between you.
Where this leaves the two sides of the table
The classification question has one right answer and it does not depend on who has the leverage. A vendor that maintains protected health information is a business associate whether or not it signs, whether or not it can read the records, and whether or not anyone at either company has thought about it. What the signature changes is the covered entity's position, not the vendor's status — which is why the practice is the party with the urgent problem when a vendor refuses, and why the honest response to a refusal is usually to move the data rather than to accept the assurance.
For the vendor, the twelve mandatory terms are not the part worth fighting. They are identical in every agreement and they come from the regulation; resisting them signals only that nobody has read § 164.504(e). The cap, the indemnity, the notification window and the audit right are where a negotiation belongs, and where a software or platform contract usually settles it.
Sources
- 45 CFR § 160.103 — the definition of "business associate" and "subcontractor"
- 45 CFR § 164.504(e) — business associate contracts and the required provisions
- 45 CFR § 164.502(e) — disclosures to business associates and subcontractors
- 45 CFR § 164.314(a) — the Security Rule's three additional contract terms
- 45 CFR § 164.410 — breach notification by a business associate, and the 60-day limit
- 78 FR 5566 — HIPAA Omnibus Rule, on the conduit exception, the subcontractor chain and agency
- OCR guidance on HIPAA and cloud computing
- American Hospital Association v. Becerra — the tracking bulletin vacatur
General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.
Frequently asked
Does a vendor that only stores encrypted data need a BAA?
Yes. HHS drew the line at whether the vendor maintains the information rather than whether it can read it. The Omnibus Rule preamble states that an entity maintaining protected health information on a covered entity's behalf is a business associate and not a conduit even where it does not actually view the information, and OCR's cloud computing guidance applies that squarely to a provider holding encrypted records without the decryption key.
What happens if we never signed a BAA with a vendor that should have had one?
The disclosures already made were impermissible, and that exposure does not disappear when the agreement is signed later. Sign one now, because every day without it adds to the problem, but treat the gap as something to document and assess rather than something the new signature erases. The vendor is separately liable in its own right for any Security Rule failures during the period.
How quickly does a business associate have to report a breach?
Under 45 CFR 164.410 the associate must notify the covered entity without unreasonable delay and in no case later than 60 calendar days after it discovers the breach. That is an outer limit rather than a budget, and it consumes the covered entity's own 60-day window for notifying patients. Most agreements shorten it by contract, commonly to somewhere between five and fifteen days.
Do we need agreements with our vendor's subcontractors?
No, and the rule says so. 45 CFR 164.502(e)(1)(i) provides that a covered entity is not required to obtain satisfactory assurances from a business associate that is a subcontractor; the obligation sits with your vendor under 164.502(e)(1)(ii), and with each link below it. You can require disclosure of who the subcontractors are and a right to object, but that is a commercial term.
Is a BAA needed to send records to another doctor?
No. The definition of business associate at 45 CFR 160.103 excludes a health care provider with respect to disclosures by a covered entity to that provider concerning the treatment of the individual. Referrals, consultation letters and transfers of care sit outside the business associate framework entirely. The disclosure still has to be permitted, but no contract between the two providers is required.