Skip to main content
Category: Uses and Disclosures

Business Associate Functions

Also known as: BA Functions, Business Associate Services, Business Associate Activities
Simply put

Business associate functions are the specific tasks or services that a person or organization performs for a HIPAA covered entity (or for another business associate) that involve creating, receiving, maintaining, or transmitting protected health information (PHI). Common examples include claims processing, billing, quality assurance, practice management, and professional services such as legal, accounting, actuarial, and accreditation work. Performing one of these functions on behalf of a covered entity is generally what makes an organization a business associate under HIPAA.

Formal definition

Under the HIPAA Privacy Rule, 'business associate functions' refers to the activities and services performed on behalf of a covered entity, or of another business associate, that require the creation, receipt, maintenance, or transmission of protected health information. Per HHS guidance, these functions generally include claims processing or administration, billing, quality assurance, practice management, data analysis, and utilization review, as well as services such as legal, actuarial, accounting, and accreditation services performed for a covered entity. A subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate is itself a business associate. Engaging in these functions triggers the requirement for a business associate agreement (BAA) that imposes contractual obligations; in addition, business associates are directly liable for compliance with certain provisions of the HIPAA Rules independent of the BAA. Note that the specific scope of covered functions and the associated direct-liability provisions should be verified against the current regulatory text, and that the HITECH Act and applicable state law may impose additional requirements beyond HIPAA.

Why it matters

Whether an organization is performing a business associate function is often the decisive question in determining whether HIPAA obligations attach to it at all. A vendor does not become subject to HIPAA simply because it does business with a healthcare organization; it becomes a business associate when it performs a function or service on behalf of a covered entity (or another business associate) that involves creating, receiving, maintaining, or transmitting PHI. Misjudging this status can leave both parties exposed. A covered entity that fails to recognize that a vendor is performing a business associate function may neglect to put a required business associate agreement (BAA) in place, while a vendor that overlooks its own status may fail to meet obligations for which it is directly liable.

The stakes extend down the supply chain. Per HHS guidance, a subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate is itself a business associate, meaning the same functional test applies at every tier where PHI flows. Because business associates are directly liable for compliance with certain provisions of the HIPAA Rules independent of their contract, correctly identifying a business associate function is not merely a paperwork exercise; it defines where legal accountability actually sits. Organizations should verify the specific scope of covered functions and the associated direct-liability provisions against the current regulatory text, and should be aware that the HITECH Act and applicable state law may impose additional requirements beyond HIPAA.

Who it's relevant to

Covered Entity Privacy and Compliance Officers
These professionals must determine which of their vendors are performing business associate functions so that the appropriate business associate agreements are in place before PHI is shared. Because status depends on the function performed rather than the vendor's label, they should evaluate whether a service involves creating, receiving, maintaining, or transmitting PHI on the entity's behalf, and confirm the current scope of covered functions against the regulatory text.
Vendors and Service Providers to Healthcare Organizations
Organizations offering services such as claims processing, billing, practice management, data analysis, or professional services like legal, actuarial, accounting, and accreditation work should assess whether their engagements make them business associates. If so, they take on contractual obligations under a BAA and are directly liable for compliance with certain provisions of the HIPAA Rules independent of that contract.
Subcontractors Handling PHI
A subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate is itself a business associate. Subcontractors should not assume they fall outside HIPAA simply because they have no direct relationship with the covered entity; the same functional test applies at their tier of the supply chain.
Legal and Contracting Teams
Counsel and contract managers negotiating vendor and subcontractor relationships need to identify business associate functions to structure BAAs correctly and allocate liability. They should also account for the possibility that the HITECH Act and applicable state law impose additional requirements beyond HIPAA, and verify direct-liability provisions against current guidance.

Inside BA Functions

Function-Based Definition
Business associate status generally arises from the functions or activities a person or entity performs on behalf of, or provides services to, a covered entity that involve the creation, receipt, maintenance, or transmission of protected health information (PHI). Status attaches to what is done with PHI, not to a job title or contract label.
Common Covered Functions
Typical business associate functions include claims processing or administration, data analysis, utilization review, quality assurance, billing, benefit management, and practice management performed on behalf of a covered entity.
Covered Services
Certain services trigger business associate status when they involve PHI, such as legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services provided to or for a covered entity.
Business Associate Agreement (BAA)
Obligations to safeguard PHI generally flow to a business associate through a written business associate agreement, which sets out permitted uses and disclosures and required safeguards. Subcontractors that perform business associate functions are typically bound through similar downstream agreements.
Direct Regulatory Obligations
Under the HITECH Act, business associates became directly subject to certain provisions of the HIPAA Security Rule and to specified Privacy Rule requirements, in addition to their contractual obligations under the BAA. Practitioners should confirm the current scope against applicable regulatory text.
Scope Limitation
Business associate functions apply to services performed on behalf of a covered entity or another business associate. Entities that merely have incidental contact with PHI, or that act as mere conduits, are generally not treated as business associates by virtue of that contact alone.

Common questions

Answers to the questions practitioners most commonly ask about BA Functions.

Does signing a business associate agreement mean my vendor is now directly regulated by HIPAA for everything they do?
Not exactly. HIPAA obligations attach through defined relationships and the scope of the business associate agreement (BAA), not to every activity a vendor performs. A business associate is generally regulated with respect to the functions or services it performs on behalf of a covered entity that involve creating, receiving, maintaining, or transmitting PHI. Activities unrelated to that PHI or those services typically fall outside the HIPAA relationship. Since the HITECH Act, business associates do have certain direct compliance obligations, but the reach of those obligations is tied to the business associate function itself rather than the vendor as a whole. Readers should confirm the specific scope against the executed BAA and current regulatory text.
If a vendor merely stores or transmits our data without ever looking at it, does that keep them from being a business associate?
Generally no. A person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a business associate function is typically treated as a business associate even if it does not routinely access or view the PHI. Persistent access to or maintenance of PHI is commonly what triggers business associate status, regardless of whether the data is actively used. The narrow conduit concept has historically been interpreted to apply only to entities that transport data transiently, and it is generally read narrowly. Whether a specific arrangement qualifies should be evaluated against current HHS guidance and the applicable regulatory definitions.
How do we determine whether a given vendor is performing a business associate function?
In most cases the analysis focuses on whether the vendor performs a service or function for the covered entity that involves creating, receiving, maintaining, or transmitting PHI. It is useful to inventory what the vendor actually does, what data it can access, and whether that access is necessary to the service. The label on the contract does not control; the substance of the relationship and the data involved generally governs. Where the answer is unclear, organizations often document their reasoning and consult legal counsel, and should verify their approach against current regulatory guidance.
What should a business associate agreement address regarding these functions?
A BAA generally describes the permitted and required uses and disclosures of PHI tied to the specific functions the business associate performs, and sets out safeguards, reporting obligations, subcontractor flow-down requirements, and return or destruction of PHI at termination. Because obligations attach to the defined function and relationship, clearly scoping the described services helps establish what the business associate may and may not do. Organizations should confirm required BAA provisions against the current regulatory text, and note that state law or other frameworks may impose additional terms.
Do our business associates need to enter agreements with their own subcontractors?
Generally yes, when a subcontractor creates, receives, maintains, or transmits PHI on behalf of the business associate to help perform the business associate function. In those cases the obligation typically flows down through a written agreement between the business associate and the subcontractor. The subcontractor is itself generally treated as a business associate for that function. The specific flow-down requirements should be confirmed against the current regulation.
Does having a HITRUST-certified vendor satisfy our obligations around business associate functions?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. A vendor's HITRUST certification may inform due diligence, but it does not replace the need for an appropriately scoped business associate agreement or the covered entity's own compliance responsibilities. Organizations should treat certification as one input among several and verify HITRUST scope and version details separately from their HIPAA obligations.

Common misconceptions

Any vendor that could potentially access PHI is automatically a business associate regulated by HIPAA.
Business associate status generally depends on whether the vendor performs a covered function or service involving the creation, receipt, maintenance, or transmission of PHI on behalf of a covered entity. Obligations typically attach through a defined relationship and a business associate agreement, not from mere potential or incidental contact with data.
Signing a business associate agreement is the only compliance step required, and the contract itself creates all obligations.
While the BAA is the mechanism that flows contractual safeguard obligations, business associates are also directly subject to certain HIPAA requirements under the HITECH Act. The agreement documents and allocates responsibilities but does not replace the underlying regulatory duties, which should be verified against current guidance.
Subcontractors that handle PHI for a business associate fall outside HIPAA.
A subcontractor that performs business associate functions is generally itself treated as a business associate, and safeguard obligations are typically extended downstream through agreements between the business associate and its subcontractors.

Best practices

Assess vendor relationships based on the actual functions performed with PHI rather than on job titles or contract labels, and document why each relationship does or does not create business associate status.
Execute a written business associate agreement before allowing a business associate to create, receive, maintain, or transmit PHI, and ensure downstream agreements bind subcontractors performing business associate functions.
Recognize that business associates carry certain direct HIPAA obligations under the HITECH Act in addition to contractual duties, and confirm the current scope of those obligations against the applicable regulatory text.
Maintain an inventory of business associates and subcontractors, mapping each to the specific covered functions or services it performs, so that PHI flows and safeguard responsibilities remain clear.
Periodically review and update business associate agreements to reflect changes in services, PHI handling, and current regulatory requirements.
Verify penalty exposure, applicable definitions, and any state-law or framework requirements beyond HIPAA against current HHS OCR guidance rather than relying on assumptions or outdated figures.