Covered Entity vs Business Associate Under HIPAA
Last reviewed: · By Victor Humenhuk (CIPP/US certified)
A covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a HIPAA standard transaction. A business associate is a person or organization outside the covered entity's workforce that creates, receives, maintains, or transmits protected health information to perform a function or service for it. The relationship must be documented in a business associate agreement, and since the 2013 Omnibus Rule implementing HITECH, business associates are directly liable to HHS for the Security Rule and for specified Privacy Rule provisions. Subcontractors that handle PHI for a business associate are themselves business associates.
Who counts as a covered entity?
There are only three categories, and an organization is either in one of them or it is not. The chapter topic on HIPAA covered entities works through the edge cases.
- Health plans - health insurers, HMOs, employer-sponsored group health plans including self-funded plans, and government programs such as Medicare and Medicaid.
- Health care clearinghouses - entities that translate health information between nonstandard and standard formats, such as billing services and repricing companies.
- Health care providers - but only those that transmit health information electronically in connection with a HIPAA standard transaction, such as an electronic claim or eligibility inquiry. A provider that submits everything on paper is not a covered entity.
Two structural points matter in practice. A hybrid entity is a single legal entity with both covered and non-covered functions, such as a university that runs a hospital; it may designate its health care components so that HIPAA applies only to those parts. An organized health care arrangement allows clinically integrated providers to share PHI for joint operations and issue a joint notice of privacy practices.
What does not make you a covered entity: holding health data, being a wellness app, selling wearables, or running a direct-to-consumer genetic testing service. Those companies typically answer to Section 5 of the FTC Act, the FTC's Health Breach Notification Rule, and state consumer health data laws instead.
What makes a vendor a business associate?
A business associate is defined by function, not by contract label. The test is whether the person or organization, outside the covered entity's workforce, creates, receives, maintains or transmits PHI in performing a covered function or activity, or provides one of the listed services involving disclosure of PHI. The topic on business associates covers the contracting chain.
- Covered functions and activities - claims processing or administration, data analysis, utilization review, quality assurance, billing, benefit management, practice management, and repricing.
- Listed services - legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, and financial services.
- Health information organizations, e-prescribing gateways and personal health record vendors offering PHR services on behalf of a covered entity.
- Subcontractors. A vendor that a business associate hires to create, receive, maintain or transmit PHI on its behalf is itself a business associate, and the chain of agreements has to follow the data down.
Two boundary cases are tested constantly. Workforce members - employees, volunteers, trainees and others under the covered entity's direct control - are never business associates, because they are inside the entity. And the conduit exception is narrow: it covers entities that merely transport information without accessing it other than randomly or occasionally, such as the postal service or an internet service provider carrying traffic. In OCR's guidance, cloud storage providers do not qualify, because they maintain PHI persistently; they are business associates even when the data is encrypted and they hold no decryption key.
Covered entity vs business associate: obligations compared
| Covered entity | Business associate | |
|---|---|---|
| Definition | Health plan, health care clearinghouse, or provider transmitting electronic standard transactions | Non-workforce person or organization creating, receiving, maintaining or transmitting PHI for a covered entity |
| Full Privacy Rule compliance | Yes, in full | Only as to specified provisions and as limited by its agreement; it may use PHI only as the contract and the rule permit |
| Security Rule compliance | Yes | Yes - directly and independently, since the 2013 Omnibus Rule |
| Notice of privacy practices | Must produce and distribute one | Not required to issue its own |
| Individual rights requests | Must respond to access, amendment and accounting requests | Must assist the covered entity so that it can respond |
| Breach notification | Notifies affected individuals, HHS, and prominent media outlets where a breach affects 500 or more residents of a state or jurisdiction | Notifies the covered entity without unreasonable delay and no later than 60 days after discovery |
| Direct HHS enforcement | Yes | Yes - OCR can investigate and penalize a business associate directly |
| Contract required | Must obtain a business associate agreement before disclosing PHI | Must sign one, and must flow equivalent terms down to subcontractors |
What has to be in a business associate agreement?
The agreement is the mechanism that lets PHI leave the covered entity lawfully, and the Privacy Rule prescribes its core content. At minimum it must:
- Describe the permitted and required uses and disclosures of PHI by the business associate, and prohibit any use or disclosure beyond what the contract allows or the law requires.
- Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
- Require the business associate to report to the covered entity any use or disclosure not provided for by the contract, including security incidents and breaches.
- Require the business associate to flow equivalent obligations down to subcontractors that handle PHI.
- Require it to make PHI available for access, amendment and accounting, and to make its internal practices, books and records available to HHS.
- Provide for return or destruction of PHI at termination where feasible, and allow the covered entity to terminate for material breach.
A covered entity is not automatically liable for a business associate's misconduct. Liability attaches where the business associate is an agent acting within the scope of the agency, or where the covered entity knew of a pattern of activity or practice amounting to a material breach of the agreement and failed to act. That is why vendor oversight, not just signature collection, is the substance of the obligation.
Related study notes
- Covered Entities Under HIPAA
- Business Associates and BAAs
- The HIPAA Privacy Rule and the FIPPs
- HIPAA Enforcement and Penalties
- HITECH and Breach Notification
Frequently asked questions
Is a cloud storage provider a HIPAA business associate?
Yes, if it maintains protected health information for a covered entity or another business associate. OCR guidance is explicit that the conduit exception is limited to transmission-only services, and that a cloud provider remains a business associate even where it holds only encrypted PHI and cannot decrypt it.
Are employees business associates?
No. Members of the workforce - employees, volunteers, trainees and others whose conduct is under the covered entity's direct control - sit inside the covered entity. The business associate concept exists to govern PHI moving to an outside organization.
Can HHS penalize a business associate directly?
Yes. Before HITECH, business associates were reachable mainly through their contracts. The 2013 Omnibus Rule made them directly liable for the Security Rule and for specified Privacy Rule obligations, so the Office for Civil Rights can investigate and penalize them without going through the covered entity.
Does a health app that stores my medical data have to follow HIPAA?
Usually not. A direct-to-consumer app is neither a covered entity nor acting on behalf of one, so it falls outside HIPAA. It is more likely to answer to the FTC under Section 5 and the Health Breach Notification Rule, and to state consumer health data laws such as Washington's My Health My Data Act.
Test yourself
Try the free CIPP/US practice questions, or read the full CIPP/US study guide - free.