Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Freedom 250 banner logo Join HHS in Celebrating Freedom 250
    • About HHS

      HHS is a U.S. executive department that touches the lives of nearly all Americans by protecting your rights, research, food safety, health care, aging, and much more.

    • Explore About HHS
    • About the Department
      • Leadership
      • HHS Divisions
      • Organizational Chart
      • Priorities
      • Budget in Brief
      • Contact Us
    • Press Room
      • Press Releases
      • Request for Comment
      • Request for Interview
      • Connect on Social Media
      • HHS Live
      • Podcasts
    • Careers
      • Working at HHS
      • Opportunities for Attorneys
      • Join the Health Workforce
      • I am HHS
      • New Employee Orientation
      • Transportation Services
    • Standards and Compliance
      • Gold Standard Science
      • Accessibility
      • Plain Writing
      • Digital Communications Standards
      • Records Management
    • Accountability and Transparency
      • Freedom of Information Act (FOIA)
      • Open Government
      • No Fear Act
      • Privacy at HHS
    • NUTRITION IN AMERICA

      HHS is advancing the Make America Healthy Again agenda by putting nutrition at the center of health. President Trump and Secretary Kennedy flipped the food pyramid to encourage Americans to Eat Real Food.

    • Explore Nutrition in America
    • Advancing Nutrition Education
    • Make Hospital Food Healthy Again
    • Eat Real Food
    • The Real Food Show
  • MAHA
    • Programs & Services

      HHS is responsible for public health, health care, and human/social services for the United States of America. This includes administering over 100 programs and services.

    • Explore Programs & Services
    • Health Care
      • Find a Health Center
      • Find an Indian Health Service Facility
      • Find Support for Mental Health, Drugs, or Alcohol
      • Find a Cancer Center
      • Dental Care Options
      • Telehealth
    • Health Insurance
      • Medicare – 65+ or With Disability
      • Medicaid - Low-Income, With Disability, or Pregnant
      • Children’s Health Insurance Programs (CHIP)
      • Find Health Insurance Coverage
      • Insurance Help for Mental Health and Substance Use
      • No Surprise Medicals Bills
    • Social Services
      • Programs for Children and Families
      • Programs for People with Disabilities
      • Programs for Older Adults
      • Resources for Caregivers
    • Public Health and Prevention
      • Emergency Preparedness and Response
      • Healthy Lifestyle
      • Mental Health and Substance Use
      • Food Safety and Nutrition
      • Drug and Product Safety
    • Health Research and Information
      • National Library of Medicine
      • Surgeon General Reports
      • Health Data
      • National Center for Health Statistics
      • Medline Plus
      • Clinical Research Studies
      • Volunteering to Participate in Research
    • Laws & Regulations

      HHS protects and helps you understand the laws and regulations, also known as "rules," that govern the nation. You also have the power to voice your opinion on these laws and regulations.

    • Explore Laws & Regulations
    • Regulatory Information
      • What is a Rule?
      • Find Rules by Division
      • Comment on Open Rules
      • Suggest Deregulatory Actions
      • Understand Key Federal Laws
    • Civil Rights
      • Your Civil Rights
      • Civil Rights Laws Enforced by HHS
      • Health Information Privacy
      • Substance Use Disorder Patient Confidentiality
      • Conscience and Religious Freedom
    • Laws and Regulations by Topic
      • HIPAA Privacy Rule
      • Health Insurance Protections
      • Health IT Legislation
      • Food and Drug Safety
      • Public Health Emergencies
    • Human Research Protections
      • The Belmont Report
      • Regulations, Policy, and Guidance
      • Human Subjects Regulations (45 CFR 46)
      • Register IRBs and Obtain FWAs
      • Trainings, Tutorials, and Workshops
      • International Research
    • Complaints and Appeals
      • File a Medicare Complaint
      • File a HIPAA Complaint
      • File a Civil Rights Complaint
      • Appeal an Insurance Company Decision
      • Report Fraud, Waste, and Abuse to OIG
      • Report a Problem to the FDA
      • Report a Tip on the Chemical and Surgical Mutilation of Children
    • Grants & Contracts

      HHS gives the most money in grants of any federal agency in the U.S. Find out about our grants and how your organization can apply for them. We also provide information on how you can work with us and our support of small businesses.

    • Explore Grants & Contracts
    • Grants
      • Get Ready for Grants Management
      • Grant Policies and Regulations
      • Research Grants and Funding from NIH
      • Search Grants.gov
      • Avoid Grant Scams
      • Contact HHS Grant Officials
    • Contracts
      • Get Ready to Do Business with HHS
      • Programs for Businesses
      • Contract Policies and Regulations
      • Search Opportunities on SAM.gov
      • Contact HHS Contracting Managers
    • Small Business
      • Contract Opportunities
      • Small Business Programs
      • Small Business Resources
      • Contact Small Business Staff
    • Radical Transparency

      HHS protects and helps you understand the laws and regulations, also known as "rules," that govern the nation. You also have the power to voice your opinion on these laws and regulations.

    • Explore Radical Transparency
    • CDC’s ACIP Conflicts of Interest
    • Ending Anti-Semitism on College Campuses
    • Ending Wasteful Spending
    • Keeping Food Ingredients Safe
    • Chemical Contaminants Transparency Tool
  • HIPAA for Individuals
  • Filing a Complaint
  • HIPAA for Professionals
  • Newsroom
Breadcrumb
  1. HHS
  2. HIPAA Home
  3. For Professionals
  4. Privacy
  5. Guidance Materials
  6. Business Associates
  • HIPAA for Professionals
  • Regulatory Initiatives
  • Privacy
    • Summary of the Privacy Rule
    • Guidance
    • Combined Text of All Rules
    • HIPAA Related Links
  • Security
    • Security Rule NPRM
    • Summary of the Security Rule
    • Security Guidance
    • Cyber Security Guidance
  • Breach Notification
    • Breach Reporting
    • Guidance
    • Reports to Congress
    • Regulation History
  • Compliance & Enforcement
    • Enforcement Rule
    • Enforcement Process
    • Enforcement Data
    • Resolution Agreements
    • Case Examples
    • Audit
    • Reports to Congress
    • State Attorneys General
  • Special Topics
    • Parental Access
    • Mental and Behavioral Health
    • Change Healthcare Cybersecurity Incident FAQs
    • HIPAA and COVID-19
    • HIPAA and Reproductive Health
      • HIPAA and Final Rule Notice
    • HIPAA and Telehealth
    • HIPAA and FERPA
    • Research
    • Public Health
    • Emergency Response
    • Health Information Technology
    • Health Apps
  • Patient Safety
  • Covered Entities & Business Associates
    • Business Associate Contracts
    • Business Associates
  • Training & Resources
  • FAQs for Professionals
  • Other Administrative Simplification Rules
  • Substance Use Disorder Confidentiality

Business Associates

Background

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules1 (“HIPAA Rules”) apply to covered entities–-health plans, health care clearinghouses, and health care providers who transmit health information in electronic form in connection with a covered transaction. Certain provisions of the HIPAA Rules also apply directly to business associates of covered entities. Generally, business associates are persons, other than a workforce member of a covered entity, that are engaged by a covered entity to carry out certain health care activities and functions or to provide certain services that involve the use or disclosure of PHI. The HIPAA Rules permit a covered entity to disclose PHI to a business associate if the covered entity obtains satisfactory assurances, in the form of a contract or other written arrangement (collectively referred to as a “business associate agreement,” or BAA), that the business associate will appropriately safeguard the information, among other obligations.2 A business associate is also directly liable for complying with certain provisions of the HIPAA Rules.

Key Definitions
See 45 CFR 160.103 for definitions, including:

  • Covered entity.
  • Business associate.
  • Protected health information.
  • Person.

What is a Business Associate?

A “business associate” is, generally, a “person” (a term that includes natural persons, as well as organizations such as corporations and other entities) that performs certain functions or activities regulated by the HIPAA administrative simplification regulations3 on behalf of a covered entity (or an organized health care arrangement) that involve creating, receiving, maintaining, or transmitting PHI, or that provides certain services to or for a covered entity that involves the disclosure of PHI to that person. A business associate also is any subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate.4 A covered entity can be a business associate of another covered entity.

The definition of business associate lists some of the functions or activities, as well as the particular services that make a person a business associate if the activity or service involves the use or disclosure of PHI. Some examples of activities performed on behalf of a covered entity by a business associate include claims processing or administration, data analysis, billing, and practice management. Some examples of business associate services performed for covered entities include legal, actuarial, accounting, and accreditation services.

Examples of Business Associates

  • Health Information Exchange Organization, Health Information Network, E-prescribing Gateway, or other person that provides data transmission services with respect to PHI to a covered entity and that requires access on a routine basis to such PHI.
  • Vendor that offers a personal health record to individuals on behalf of a covered entity.
  • Health care application (“app”) developer that contracts with a covered entity to provide the health care app to the covered entity’s patients and creates, receives, maintains, or transmit patients’ PHI for patient management services (e.g., remote patient health counseling, patient messaging, monitoring of patients’ food and exercise, electronic health record (EHR) access) on behalf of the covered entity.
  • Cloud service provider engaged to create, receive, maintain, or transmit electronic PHI (ePHI) (such as to process and/or store ePHI) on behalf of the covered entity or business associate. See OCR’s Guidance on HIPAA & Cloud Computing.
  • IT contractor or vendor (e.g., EHR vendor, Managed Services Provider) that provides maintenance and/or support services (either in person or remotely) for information systems that require the contractor or vendor to create, receive, maintain, or transmit ePHI.
  • Technician who services a covered entity’s electronic device that stores individuals’ PHI (e.g., copier, medical device) where the contracted service involves the disclosure of the PHI to the technician (e.g., maintenance on hardware components where PHI is stored, service requiring elevated access permissions that provides access to PHI).
  • Third-party vendor Artificial Intelligence (AI) chatbot on a provider’s patient portal that provides services involving the patient’s PHI such as symptom assessment, medical reminders, and appointment scheduling.
  • Third party administrator that assists a health plan with claims processing.
  • CPA firm whose accounting services to a health care provider involve access to PHI.
  • Attorney whose legal services to a health plan involve access to PHI.
  • Patient Safety Organization (PSO) that creates, receives, maintains, or transmits PHI on behalf of a covered provider.
  • Consultant that performs utilization reviews for a hospital.
  • Health care clearinghouse that translates a claim from a non-standard format into a standard transaction on behalf of a health care provider and forwards the processed transaction to a payer.
  • Independent medical transcriptionist, or the vendor of an app, that provides transcription services to a physician.
  • Pharmacy benefits manager that manages a health plan’s pharmacist network.

Business Associate Agreements 

The HIPAA Privacy and Security Rules establish requirements for BAAs between covered entities and their business associates, and between business associates and their subcontractors.

The HIPAA Privacy Rule requires that the BAA between a covered entity and a business associate, or between a business associate and its business associate subcontractor, contain the elements specified at 45 CFR 164.504(e). More specifically, the BAA must: describe the permitted and required uses and disclosures of PHI by the business associate; provide that the business associate will not use or further disclose the PHI other than as permitted or required by the BAA or as required by law; and to the extent that the business associate is to carry out a covered entity’s obligations under the Privacy Rule, provide that the business associate will comply with the Privacy Rule requirements in performance of these obligations. The HIPAA Privacy Rule also restricts a BAA from authorizing a business associate to use or further disclose PHI in a manner that would violate the Privacy Rule, if done by a covered entity, except as needed for the proper management and administration of the business associate or the provision of data aggregation services relating to health care operations of the covered entity.

Where a covered entity or business associate knows of a pattern of activity or practice that constitutes a material breach or violation by the business associate (or subcontractor) of the BAA, the covered entity (or business associate in relation to a subcontractor) is required to take reasonable steps to cure the breach or end the violation, and if such steps are unsuccessful, to terminate the BAA if feasible.

A business associate must establish a BAA with its subcontractor before disclosing PHI to the subcontractor for work to be done for a covered entity.5  All such downstream subcontractors are also business associates, and therefore contractually responsible for complying with the terms of their BAAs with the business associate.

The HIPAA Security Rule also includes BAA requirements, which apply when a business associate creates, receives, maintains, or transmits ePHI on behalf of a covered entity or a subcontractor does the same on behalf of a business associate.6 For example, the HIPAA Security Rule requires BAAs to provide that a business associate, and any subcontractors, will comply with applicable Security Rule requirements and report any security incident of which a business associate becomes aware to the covered entity, including breaches of unsecured PHI as required by the Breach Notification Rule.7

Please view our Sample Business Associate Agreement Provisions.

Exceptions to the Business Associate Definition 

The definition of business associate includes the following exceptions. In these situations, a covered entity is not required to have a BAA in place before PHI may be disclosed to the person.

  • Disclosures by a covered entity to a health care provider for treatment of the individual. For example:
    • A hospital is not required to have a BAA with the specialist to whom it refers a patient and transmits the patient’s medical chart for treatment purposes.
    • A physician is not required to have a BAA with a clinical laboratory as a condition of disclosing PHI to the clinical laboratory for the treatment of an individual.
    • A hospital laboratory is not required to have a BAA with a reference laboratory as a condition of disclosing PHI to the reference laboratory for the treatment of the individual.  
    • A covered entity is not required to have a BAA to disclose PHI about an individual to a health care provider for treatment purposes, such as case management and coordination of care.
  • Disclosures to a health plan sponsor, such as an employer, by a group health plan, or by the health insurance issuer or HMO that provides the health insurance benefits or coverage for the group health plan, provided that the group health plan’s documents have been amended to limit the disclosures or one of the exceptions at 45 CFR 164.504(f) have been met.  
  • The collection and sharing of PHI by a health plan that is a public benefits program, such as Medicare, and an agency other than the agency administering the health plan, such as the Social Security Administration, that collects PHI to determine eligibility or enrollment, or determines eligibility or enrollment, for the government program, where the joint activities are authorized by law.
  • Disclosures among covered entities who participate in an organized health care arrangement (OHCA) to make disclosures that relate to the joint health care activities of the OHCA.

Other Situations in Which a Business Associate Agreement Is NOT Required

Many common and permitted exchanges of PHI for health care and other purposes can be conducted without a BAA between the parties because neither entity is acting on behalf of, or providing a service to, a covered entity or business associate. For example, a BAA is not required:

  • When a health care provider discloses PHI to a health plan for payment purposes, or when the health care provider simply accepts a discounted rate to participate in the health plan’s network. A provider that submits a claim to a health plan and a health plan that assesses and pays the claim are each acting on its own behalf as a covered entity, and not as the “business associate” of the other.
  • With a person (e.g., janitorial service, electrician) whose functions or services do not involve the use or disclosure of PHI, provided that access to PHI by such persons would be only incidental, if at all, and that reasonable safeguards are in place.
  • Disclosures by a covered entity to another covered entity for its own health care operations purposes, or for the health care operations of the entity receiving the information. For example, if an individual switches health plans, the former health plan can disclose PHI to the new health plan to coordinate the individual’s care without a BAA between the plans.
  • When transmitting PHI through a person that acts only as a conduit for PHI, for example, the US Postal Service, certain private couriers, and their electronic equivalents. The conduit exception is limited to entities that only provide transmission services for PHI (whether in electronic or paper form), including any temporary storage of PHI. Entities that access PHI on a regular or frequent basis to perform a service on behalf of a covered entity are not conduits.
  • Where a group health plan purchases insurance from a health insurance issuer or HMO. The relationship between the group health plan and the health insurance issuer or HMO is defined by the Privacy Rule as an OHCA, with respect to the individuals they jointly serve or have served. Thus, these covered entities are permitted to share PHI that relates to the joint health care activities of the OHCA without a BAA.
  • Where one covered entity purchases a health plan product or other insurance, for example, reinsurance, from an insurer. Each entity is acting on its own behalf when the covered entity purchases the insurance benefits, and when the covered entity submits a claim to the insurer and the insurer pays the claim.
  • To disclose PHI to a researcher for research purposes, either with patient authorization, pursuant to a waiver under 45 CFR 164.512(i), or as a limited data set pursuant to 45 CFR 164.514(e). Because the researcher is not conducting a function or activity regulated by the Administrative Simplification Rules, such as payment or health care operations, or providing one of the services listed in the definition of “business associate” at 45 CFR 160.103, the researcher is not a business associate of the covered entity, and no business associate agreement is required. However, if the researcher provides services to a covered entity involving PHI (e.g., de-identifying and aggregating data sets containing PHI), the researcher may be a business associate with respect to such services, but not for the researcher’s own research activities.
  • When a financial institution processes consumer-conducted financial transactions by debit, credit, or other payment card, clears checks, initiates or processes electronic funds transfers, or conducts any other activity that directly facilitates or effects the transfer of funds for payment for health care or health plan premiums. When it conducts these activities, the financial institution is providing its normal banking or other financial transaction services to its customers; it is not performing a function or activity for, or on behalf of, the covered entity.  

More Guidance

Sample Business Associate Agreement Provisions

Fact Sheet on Direct Liability of Business Associates

Business Associate FAQs

Health Information Technology FAQs

Guidance on HIPAA & Cloud Computing

Resources for Mobile Health Apps Developers

The 2002 Privacy Final Rule and the 2013 Omnibus Final Rule (which modified the definition of a business associate and made business associates directly liable for compliance with certain requirements of the HIPAA Rules) both contain significant preamble guidance on business associate relationships and are searchable. 

  • 1

    45 CFR parts 160 and 164. The HIPAA Breach Notification Rule was promulgated under section 13402 of the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009.

  • 2

    See 45 CFR 164.502(e)(1)(i) and (e)(2).

  • 3

    See 45 CFR parts 160-164.

  • 4

    In this guidance, the term “subcontractor” refers specifically to a subcontractor that meets the definition of business associate because it creates, receives, maintains, or transmits PHI on behalf of a business associate. 45 CFR 160.103 (definition of “Business associate”, paragraph (3)(iii)).

  • 5

    A covered entity is not required to establish a BAA directly with a subcontractor of its business associate. See 45 CFR 164.502(e)(1)(i).

  • 6

    See 45 CFR 164.308(b).

  • 7

    See 45 CFR 164.314(a)(2)(i)(A)-(C).

Content last reviewed July 30, 2026
Back to top
Secretary Robert F. Kennedy Jr.

Follow @SecKennedy

HHS icon

Follow @HHSGov

HHS Email updates

Receive email updates from HHS.

Subscribe

HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​

  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • Press Room
  • HHS Archive
  • Accessibility Statement
  • Privacy Policy
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy