Skip to content
compliancebase
HIPAATopics — Covered Entity and Business Associate Roles

Covered Entity vs. Business Associate

Covered Entity and Business Associate Roles

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Determine whether each organization acts as a covered entity, business associate, or subcontractor business associate for a given PHI processing relationship.

Points of focus

  • Classify the role based on actual functions and data handling
  • Recognize that one organization may have different roles for different services
  • Document downstream business-associate relationships

Implementation notes

Review each product workflow with legal and technical owners, document why PHI is handled and for whom, and use the resulting role to drive BAAs, safeguards, and customer responsibility matrices. Operationalize classify the role based on actual functions and data handling in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain role analysis tied to products and contractual data flows with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a saas provider assumes it is outside hipaa because it never diagnoses patients Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample role analysis tied to products and contractual data flows with dates and named reviewers. Be ready to walk through how you detect and correct: a saas provider assumes it is outside hipaa because it never diagnoses patients

Evidence auditors typically request:

  • Role analysis tied to products and contractual data flows
  • Customer and vendor BAA matrix
  • Subprocessor inventory identifying PHI functions

Common gaps

  • A SaaS provider assumes it is outside HIPAA because it never diagnoses patients
  • Role classification follows a contract label despite the platform maintaining PHI

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAACovered Entity vs. Business AssociateThis control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

Covered Entity and Business Associate Roles applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — classify the role based on actual functions and data handling — with evidence stored where auditors and customers can sample it.

Lead with role analysis tied to products and contractual data flows and pair it with customer and vendor baa matrix. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a saas provider assumes it is outside hipaa because it never diagnoses patients Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above