Skip to main content
Category: Uses and Disclosures

Business Associate Responsibilities

Also known as: BA, Business Associate Obligations, Business Associate Duties Under HIPAA, BA Responsibilities
Simply put

Business associate responsibilities are the HIPAA obligations that fall on an outside person or organization that performs functions or services for a covered entity and, in doing so, creates, receives, maintains, or transmits protected health information (PHI). These typically include putting safeguards in place to protect that information and using it only for permitted purposes, generally formalized through a signed agreement. Common examples of business associate services include legal, accounting, actuarial, and accreditation services.

Formal definition

A business associate (BA) is generally a person or entity that, on behalf of a covered entity, creates, receives, maintains, or transmits protected health information to perform a function or service, and that is bound by a business associate agreement (BAA). BA responsibilities typically include implementing safeguards to prevent misuse of the information and to help ensure its confidentiality, integrity, and availability, restricting uses and disclosures to those permitted by the BAA and applicable HIPAA rules, and flowing comparable obligations down to subcontractors that handle the same PHI. Because the HIPAA Security Rule applies specifically to electronic PHI (ePHI), a BA's technical, physical, and administrative safeguards under that Rule apply to ePHI, while Privacy Rule obligations extend to PHI in all forms; note that a BA's precise duties depend on the specific services performed and the terms of the applicable BAA. This entry does not enumerate every regulatory requirement or applicable implementation specification, and readers should verify the current definition, obligations, and any additional requirements imposed by the HITECH Act or state law against the current regulatory text.

Why it matters

Business associates sit at the heart of modern healthcare operations. Covered entities routinely rely on outside vendors for legal, actuarial, accounting, accreditation, and technology services, and in performing those functions these vendors frequently create, receive, maintain, or transmit protected health information. Because PHI moves outward through these relationships, the safeguards a business associate puts in place directly affect whether patient information stays protected once it leaves the covered entity's direct control. When a business associate fails to meet its obligations, the exposure is not merely contractual; under HIPAA as amended by the HITECH Act, business associates can be directly subject to certain HIPAA requirements and to enforcement, so the responsibilities carry real regulatory weight.

Who it's relevant to

Vendors serving as business associates
Organizations providing legal, actuarial, accounting, accreditation, or technology services to covered entities need to understand when they meet the definition of a business associate and what obligations attach. If they create, receive, maintain, or transmit PHI on behalf of a covered entity, they generally assume duties to safeguard that information and to limit its use to permitted purposes under the applicable BAA. Their precise responsibilities depend on the services performed and should be confirmed against current regulatory text.
Covered entity privacy and security officers
Privacy and security officers at covered entities are responsible for identifying which vendors are business associates, ensuring appropriate business associate agreements are in place, and understanding what safeguards those vendors are expected to maintain. Because obligations attach through defined relationships and BAA terms, these officers need clarity on the scope of each vendor's duties, including the distinction between Privacy Rule coverage of all PHI and Security Rule coverage of ePHI.
Subcontractors handling PHI
A subcontractor that handles the same PHI on behalf of a business associate generally becomes subject to comparable obligations flowed down through agreement. These organizations should recognize that responsibility for protecting PHI extends beyond the first vendor in the chain and that they may carry safeguard and permitted-use duties of their own, the specifics of which should be verified against the applicable agreement and current regulation.
Compliance and legal counsel
Compliance professionals and attorneys advising healthcare organizations rely on a precise understanding of business associate responsibilities when drafting or reviewing BAAs, scoping vendor obligations, and assessing risk. Counsel should note that HIPAA obligations attach through defined relationships rather than to any vendor that merely touches data, and that the HITECH Act and state law may impose additional requirements beyond the HIPAA baseline.

Inside BA

Direct Statutory Liability
Since the HITECH Act and subsequent rulemaking, business associates are directly subject to certain HIPAA requirements and can be held accountable by HHS OCR, rather than being obligated solely through contract. This generally includes compliance with the Security Rule and specified Privacy Rule provisions. Readers should verify the precise scope of direct liability against current regulatory text.
Security Rule Compliance for ePHI
Business associates that create, receive, maintain, or transmit electronic protected health information (ePHI) are generally required to implement administrative, physical, and technical safeguards, including both required and addressable implementation specifications. Addressable specifications are not optional; they must be assessed and either implemented or documented with a reasonable alternative or justification.
Business Associate Agreement (BAA) Obligations
A BAA is the contractual instrument through which a covered entity conveys certain obligations to a business associate. It typically defines permitted uses and disclosures of PHI, safeguard expectations, breach reporting duties, and termination provisions. Obligations attach through this defined relationship rather than automatically to any vendor that touches data.
Subcontractor Flow-Down
A business associate that engages a subcontractor to perform functions involving PHI is generally required to obtain satisfactory assurances, typically through a written agreement, that the subcontractor will appropriately safeguard the information. Subcontractors that meet the definition of a business associate carry comparable obligations.
Breach Notification Duties
Under the Breach Notification Rule, a business associate that discovers a breach of unsecured PHI is generally required to notify the covered entity, within timeframes and according to terms that should be confirmed against the current regulation and the applicable BAA. The covered entity typically retains responsibility for notifying affected individuals, HHS, and, where applicable, the media.
Permitted Uses and Disclosures
A business associate may generally use or disclose PHI only as permitted by its BAA and by HIPAA, or as required by law. Uses and disclosures outside these boundaries are not authorized, and the Privacy Rule's minimum necessary standard typically applies.

Common questions

Answers to the questions practitioners most commonly ask about BA.

Does signing a business associate agreement (BAA) by itself make a business associate HIPAA compliant?
No. A BAA is a required contractual mechanism that establishes permitted uses and disclosures and allocates obligations between the parties, but executing one does not by itself establish compliance. A business associate must actually implement the safeguards and practices the law and the agreement require. In most cases this includes complying directly with applicable provisions of the Security Rule for ePHI and with certain Privacy Rule obligations as they flow through the BAA. The document is a starting point, not evidence that the underlying compliance work has been performed. Readers should verify specific obligations against the current regulatory text.
Are business associates only obligated to their covered entity, and not directly liable under HIPAA?
This is a common misconception. Under the HITECH Act, business associates became directly liable for certain HIPAA requirements and can be subject to enforcement by HHS OCR, not solely to contractual liability owed to the covered entity. This direct liability generally applies to specified provisions rather than to every requirement that applies to covered entities. The precise scope of direct liability should be confirmed against current OCR guidance and the applicable regulatory text, and note that state law may impose additional obligations.
What obligations does a business associate have when it engages a subcontractor?
A business associate that discloses PHI to a subcontractor that creates, receives, maintains, or transmits PHI on its behalf must generally obtain satisfactory assurances, typically through a written subcontractor BAA, that the subcontractor will appropriately safeguard the information. The subcontractor is itself treated as a business associate for these purposes, so the obligations flow down the chain rather than stopping at the first vendor relationship. This is a scope point often overlooked; verify the specific flow-down terms against the current regulation.
How should a business associate approach the Security Rule's safeguard categories and implementation specifications?
For ePHI it creates, receives, maintains, or transmits, a business associate is generally responsible for implementing administrative, physical, and technical safeguards. Within these categories, implementation specifications are either required or addressable. Addressable does not mean optional; it means the entity must assess whether the specification is reasonable and appropriate for its environment, and if not, document why and implement an equivalent alternative measure where reasonable and appropriate. Documentation of these decisions is typically expected and should align with current Security Rule requirements.
What should a business associate do when it becomes aware of a breach or security incident involving PHI?
A business associate is generally required to report breaches of unsecured PHI, and certain security incidents, to the affected covered entity, with the specific timing and content often defined in the BAA and in the Breach Notification Rule. In most arrangements the covered entity carries the primary obligation for notifying affected individuals and HHS, but responsibilities can be allocated by contract. Business associates should confirm applicable timeframes, thresholds, and reporting content against the current Breach Notification Rule and their executed agreements, and be aware that state breach laws may add requirements.
How does obtaining HITRUST CSF certification relate to a business associate's HIPAA responsibilities?
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification can help a business associate demonstrate that it has implemented a structured set of security and privacy controls. However, HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. A business associate remains responsible for meeting its applicable HIPAA obligations regardless of certification status. Any mapping between CSF controls and HIPAA requirements should be verified against the current HITRUST CSF version and current regulatory guidance.

Common misconceptions

A business associate is only bound by its contract and cannot be penalized directly by regulators.
Since the HITECH Act, business associates are generally subject to direct liability for certain HIPAA requirements and may be pursued by HHS OCR, in addition to any contractual exposure under the BAA. The specific provisions carrying direct liability should be verified against current regulatory text.
Achieving HITRUST CSF certification means a business associate is HIPAA compliant.
HITRUST is a private organization and its CSF is a certifiable control framework, not a legal requirement. Certification may support and demonstrate a security program, but it does not by itself establish HIPAA compliance, which is enforced by HHS OCR under the applicable regulations.
Business associate safeguard obligations cover PHI in all forms.
The Security Rule obligations that apply to business associates address electronic PHI (ePHI). Handling of PHI in oral or paper form is governed by Privacy Rule provisions and by the terms of the BAA; the two rules should not be conflated.

Best practices

Maintain executed, current business associate agreements with every covered entity you serve and with every subcontractor that handles PHI, and review them when regulations or your services change.
Conduct and document a risk analysis covering ePHI, and implement administrative, physical, and technical safeguards, addressing each addressable implementation specification with an implemented control or a documented, justified alternative.
Establish breach detection and notification procedures that meet the timeframes and terms in your BAAs and confirm them against the current Breach Notification Rule.
Limit uses and disclosures of PHI to what the BAA and HIPAA permit, and apply the minimum necessary standard where it applies.
Treat HITRUST certification, if pursued, as a supporting measure for your security program rather than as evidence of HIPAA compliance, and continue to verify obligations against current HIPAA regulatory text.
Check whether state law or the HITECH Act imposes additional requirements beyond HIPAA, and confirm any penalty figures, deadlines, or citations against current HHS OCR guidance and the current HITRUST CSF version.