Skip to main content
Category: Uses and Disclosures

Business Associate Disclosures

Also known as: BA Disclosures, Business Associate Uses and Disclosures
Simply put

Business associate disclosures refer to the ways a business associate, an outside person or company that handles protected health information (PHI) on behalf of a covered entity, may share or use that health information. The HIPAA Rules generally allow a covered entity to disclose PHI to a business associate only after obtaining satisfactory assurances (typically through a written agreement) that the information will be safeguarded. A business associate must also keep records of certain disclosures so the covered entity can account for how PHI was shared.

Formal definition

Under the HIPAA Privacy Rule, a business associate is generally a person or entity that creates, receives, maintains, or transmits PHI to perform functions or activities on behalf of, or provide certain services to, a covered entity. A covered entity may disclose PHI to a business associate provided it obtains satisfactory assurances, typically documented in a business associate agreement (BAA), that the business associate will appropriately safeguard the information. A business associate may generally use or disclose PHI only as permitted by its agreement and only in ways a covered entity itself would be permitted to use or disclose the information; it may not make disclosures that would violate the Privacy Rule if made by the covered entity. Business associates are also expected to maintain disclosure records sufficient to allow a covered entity to fulfill its accounting-of-disclosures obligations. Note that the specific permitted uses and disclosures, required contract provisions, and accounting requirements are governed by the applicable regulatory text (e.g., 45 CFR 164.504(e) and related provisions), which readers should verify against the current regulation; state law and the HITECH Act may impose additional obligations, and this entry does not address Security Rule ePHI safeguard requirements, which are treated separately.

Why it matters

Business associate disclosures sit at the heart of how PHI moves beyond the covered entity's own walls. Covered entities routinely rely on outside vendors, claims processors, billing companies, IT service providers, cloud hosts, and consultants, to carry out functions that require access to health information. Because that information leaves the covered entity's direct control, the Privacy Rule generally conditions the disclosure on obtaining satisfactory assurances, typically documented in a business associate agreement, that the information will be appropriately safeguarded. Without those assurances, the disclosure itself can fall outside what the Rule permits.

Getting this relationship right matters for accountability as well as protection. A business associate may generally use or disclose PHI only as its agreement allows and only in ways the covered entity itself would be permitted to disclose the information; it may not make a disclosure that would violate the Privacy Rule if the covered entity made it directly. Business associates are also expected to keep disclosure records sufficient to let the covered entity meet its accounting-of-disclosures obligations, so gaps in a vendor's recordkeeping can translate directly into a compliance gap for the covered entity.

Readers should treat this as a Privacy Rule topic and confirm details against the current regulatory text, because the specific permitted uses, required contract provisions, and accounting requirements are set out in provisions such as 45 CFR 164.504(e) and related sections. This entry does not address the Security Rule safeguards that apply to electronic PHI, which are treated separately, and state law and the HITECH Act may impose additional obligations beyond what is described here.

Who it's relevant to

Privacy Officers at Covered Entities
Privacy officers are responsible for ensuring that PHI is disclosed to a business associate only after satisfactory assurances are in place, and for confirming that vendor agreements limit uses and disclosures to what the Privacy Rule permits. They also depend on business associates' disclosure records to meet the covered entity's accounting-of-disclosures obligations.
Business Associates and Their Compliance Staff
Business associates must understand that they may generally use or disclose PHI only as their agreement allows and only in ways a covered entity would be permitted to disclose it. They should also maintain disclosure records adequate to support the covered entity's accounting obligations, and verify their specific contract and recordkeeping duties against the current regulation.
Legal and Contracting Teams
Attorneys and contracting staff draft and review business associate agreements that document the satisfactory assurances required before disclosure and set the permitted scope of a business associate's uses and disclosures. They should confirm required contract provisions against the current regulatory text and consider additional obligations that may arise under the HITECH Act or state law.
Vendor and Procurement Managers
Those who onboard outside service providers need to identify when a vendor qualifies as a business associate, that is, when it creates, receives, maintains, or transmits PHI on the covered entity's behalf, so that the required agreement and safeguards are secured before any PHI is disclosed.

Inside Business Associate Disclosures

Permitted Disclosures Under the BAA
A business associate may generally use or disclose PHI only as permitted or required by its business associate agreement (BAA) with the covered entity, or as required by law. Disclosures outside the scope of the BAA are typically not authorized.
Disclosures for the Business Associate's Own Management and Administration
A BAA may generally permit the business associate to disclose PHI as necessary for its proper management and administration or to carry out its legal responsibilities, provided certain conditions are met (such as obtaining reasonable assurances of protection from the recipient).
Disclosures to Subcontractors
When a business associate discloses PHI to a subcontractor that creates, receives, maintains, or transmits PHI on its behalf, the subcontractor is itself treated as a business associate. Obligations flow through a written agreement between the business associate and the subcontractor, not directly from the covered entity.
Required-by-Law Disclosures
A business associate may generally disclose PHI where required by law, and must disclose PHI to HHS when required for a compliance investigation or enforcement action, as reflected in the terms of the BAA.
Minimum Necessary Standard
Disclosures by a business associate are generally subject to the Privacy Rule's minimum necessary standard, meaning the disclosure should be limited to the minimum PHI reasonably needed to accomplish the intended purpose, subject to applicable exceptions.
Reasonable Assurances from Recipients
For certain disclosures (such as those for management and administration), the business associate typically must obtain reasonable assurances that the PHI will be held confidentially, used or further disclosed only as required by law or for the purpose disclosed, and that the recipient will notify the business associate of any breach.

Common questions

Answers to the questions practitioners most commonly ask about Business Associate Disclosures.

Does signing a business associate agreement mean HIPAA now directly regulates the vendor for everything it does?
Not in the broad sense many assume. HIPAA obligations attach to a business associate through the defined relationship and the business associate agreement (BAA), and they generally apply to the protected health information (PHI) the vendor creates, receives, maintains, or transmits on behalf of the covered entity. A BAA does not convert every activity of the vendor into a HIPAA-regulated function. The business associate is directly liable for certain HIPAA requirements, but that liability is tied to its handling of PHI under the relationship, not to all of its business operations. Readers should review the specific terms of their BAA and the applicable regulatory text to understand the precise scope.
Is any vendor that comes into contact with our data automatically a business associate subject to these disclosure rules?
No. Business associate status turns on the nature of the relationship and the function performed, not merely on whether a vendor could encounter data. A party is generally a business associate when it creates, receives, maintains, or transmits PHI to perform a function or service on behalf of a covered entity. Vendors whose access to PHI is incidental, or who do not perform such functions, may fall outside the definition. Because these determinations can be fact-specific and may be affected by exceptions, you should evaluate each relationship against the current regulation rather than assuming coverage based on data contact alone.
What should a business associate agreement address before we permit disclosures to a business associate?
In most cases a BAA is expected to describe the permitted and required uses and disclosures of PHI, require appropriate safeguards, obligate the business associate to report certain incidents, address the flow-down of obligations to subcontractors, and set expectations for return or destruction of PHI at termination. The specific required provisions are set by regulation and should be confirmed against the current regulatory text. A BAA defines the boundaries within which disclosures may occur; disclosures outside those boundaries are generally not permitted under the arrangement.
How do disclosure obligations flow down to subcontractors of a business associate?
When a business associate engages a subcontractor that will create, receive, maintain, or transmit PHI on its behalf, the applicable protections and restrictions are generally expected to be extended to that subcontractor through a written agreement. A subcontractor in this position is itself treated as a business associate for HIPAA purposes. The intent is that the safeguards and use-and-disclosure limits do not weaken as PHI moves down the chain. Confirm the specific flow-down requirements against the current regulation and ensure each downstream agreement reflects them.
Can a business associate use or disclose PHI for its own purposes?
Generally, a business associate may use or disclose PHI only as permitted by its BAA and as allowed under the applicable regulation, which typically ties uses and disclosures to the functions performed on behalf of the covered entity. Limited additional uses, such as for the proper management and administration of the business associate or to carry out its legal responsibilities, may be permitted in certain circumstances, but these are constrained by the agreement and the regulatory text. A business associate should not treat PHI as generally available for its own independent business purposes without a clear basis in the BAA and the regulation.
Does adding HITRUST CSF certification into a business associate arrangement satisfy HIPAA disclosure requirements?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. A covered entity may choose to reference a security framework in its vendor management and contracting, but doing so does not replace the need for a compliant BAA or the obligation to limit uses and disclosures as required under HIPAA. Note also that state law and other frameworks may impose additional requirements beyond HIPAA, so contractual and framework provisions should be verified against current guidance and the current HITRUST CSF version where relevant.

Common misconceptions

A business associate can use or disclose PHI however it wishes as long as it protects the data.
A business associate's permitted uses and disclosures are generally limited to what the BAA allows or what is required by law. Protecting the data does not itself expand the scope of permitted disclosures; disclosures outside the agreement are typically impermissible.
Only the covered entity is responsible for disclosures made by subcontractors down the chain.
Subcontractors that handle PHI on a business associate's behalf are themselves treated as business associates. Obligations flow through written agreements at each tier, and each party carries responsibilities for compliant disclosures rather than everything resting solely with the covered entity.
The minimum necessary standard does not apply to business associate disclosures.
Business associate disclosures are generally subject to the minimum necessary standard, subject to the standard's exceptions. Practitioners should confirm applicability to specific disclosure types against the current regulatory text.

Best practices

Map every category of PHI disclosure your organization makes and confirm each is expressly permitted by the applicable BAA or required by law before proceeding.
Execute written business associate agreements with every subcontractor that creates, receives, maintains, or transmits PHI on your behalf, ensuring obligations flow through each tier of the chain.
Apply the minimum necessary standard to disclosures where it applies, limiting PHI shared to what is reasonably needed for the stated purpose.
For disclosures made for your own management, administration, or legal responsibilities, obtain and document reasonable assurances of confidentiality and breach notification from recipients.
Maintain records of disclosures and the authority relied upon for each, so you can demonstrate that disclosures stayed within permitted scope during an audit or investigation.
Verify your disclosure practices against the current Privacy Rule text and applicable state law, which may impose additional restrictions beyond HIPAA.