Covered Entity vs. Business Associate
Covered Entity and Business Associate Roles
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Determine whether each organization acts as a covered entity, business associate, or subcontractor business associate for a given PHI processing relationship.
Points of focus
- Classify the role based on actual functions and data handling
- Recognize that one organization may have different roles for different services
- Document downstream business-associate relationships
Implementation notes
Review each product workflow with legal and technical owners, document why PHI is handled and for whom, and use the resulting role to drive BAAs, safeguards, and customer responsibility matrices. Operationalize classify the role based on actual functions and data handling in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain role analysis tied to products and contractual data flows with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a saas provider assumes it is outside hipaa because it never diagnoses patients Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample role analysis tied to products and contractual data flows with dates and named reviewers. Be ready to walk through how you detect and correct: a saas provider assumes it is outside hipaa because it never diagnoses patients
Evidence auditors typically request:
- Role analysis tied to products and contractual data flows
- Customer and vendor BAA matrix
- Subprocessor inventory identifying PHI functions
Common gaps
- A SaaS provider assumes it is outside HIPAA because it never diagnoses patients
- Role classification follows a contract label despite the platform maintaining PHI
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | Covered Entity vs. Business Associate | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: Covered Entity vs. Business Associate