Business Associate Disclosures
Business associate disclosures refer to the ways a business associate, an outside person or company that handles protected health information (PHI) on behalf of a covered entity, may share or use that health information. The HIPAA Rules generally allow a covered entity to disclose PHI to a business associate only after obtaining satisfactory assurances (typically through a written agreement) that the information will be safeguarded. A business associate must also keep records of certain disclosures so the covered entity can account for how PHI was shared.
Under the HIPAA Privacy Rule, a business associate is generally a person or entity that creates, receives, maintains, or transmits PHI to perform functions or activities on behalf of, or provide certain services to, a covered entity. A covered entity may disclose PHI to a business associate provided it obtains satisfactory assurances, typically documented in a business associate agreement (BAA), that the business associate will appropriately safeguard the information. A business associate may generally use or disclose PHI only as permitted by its agreement and only in ways a covered entity itself would be permitted to use or disclose the information; it may not make disclosures that would violate the Privacy Rule if made by the covered entity. Business associates are also expected to maintain disclosure records sufficient to allow a covered entity to fulfill its accounting-of-disclosures obligations. Note that the specific permitted uses and disclosures, required contract provisions, and accounting requirements are governed by the applicable regulatory text (e.g., 45 CFR 164.504(e) and related provisions), which readers should verify against the current regulation; state law and the HITECH Act may impose additional obligations, and this entry does not address Security Rule ePHI safeguard requirements, which are treated separately.
Why it matters
Business associate disclosures sit at the heart of how PHI moves beyond the covered entity's own walls. Covered entities routinely rely on outside vendors, claims processors, billing companies, IT service providers, cloud hosts, and consultants, to carry out functions that require access to health information. Because that information leaves the covered entity's direct control, the Privacy Rule generally conditions the disclosure on obtaining satisfactory assurances, typically documented in a business associate agreement, that the information will be appropriately safeguarded. Without those assurances, the disclosure itself can fall outside what the Rule permits.
Getting this relationship right matters for accountability as well as protection. A business associate may generally use or disclose PHI only as its agreement allows and only in ways the covered entity itself would be permitted to disclose the information; it may not make a disclosure that would violate the Privacy Rule if the covered entity made it directly. Business associates are also expected to keep disclosure records sufficient to let the covered entity meet its accounting-of-disclosures obligations, so gaps in a vendor's recordkeeping can translate directly into a compliance gap for the covered entity.
Readers should treat this as a Privacy Rule topic and confirm details against the current regulatory text, because the specific permitted uses, required contract provisions, and accounting requirements are set out in provisions such as 45 CFR 164.504(e) and related sections. This entry does not address the Security Rule safeguards that apply to electronic PHI, which are treated separately, and state law and the HITECH Act may impose additional obligations beyond what is described here.
Who it's relevant to
Inside Business Associate Disclosures
Common questions
Answers to the questions practitioners most commonly ask about Business Associate Disclosures.