Skip to content
compliancebase

Business associate

Under HIPAA, a person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity (or another business associate) for covered functions — typically requiring a Business Associate Agreement (BAA) and Security Rule compliance for ePHI handled in that role.

In practice

A SaaS vendor becomes a business associate the moment its systems touch ePHI on behalf of a covered entity — through a hosted EHR integration, a billing platform, or an analytics pipeline — regardless of whether the vendor's own staff ever view PHI directly. That status triggers direct Security Rule obligations, including §164.312(a)(1) access control, independent of what the BAA itself says, because the HITECH Act extended liability straight to business associates.

Common confusion

Founders frequently assume that signing a BAA is what makes a company a business associate, when the relationship is actually defined by the underlying data flow, not the paperwork. Refusing to sign a BAA doesn't remove the obligations if ePHI is already being processed — it just removes the covered entity's contractual protection and creates a compliance gap on both sides of the relationship.

Related controls

Framework versions referenced in this page:

Last verified: July 2026 · Primary sources linked above