Skip to main content
Category: Uses and Disclosures

Conduit Exception

Also known as: HIPAA Conduit Exception Rule, Conduit Exception Rule
Simply put

The conduit exception is a narrow HIPAA concept that treats certain entities that merely transmit protected health information (PHI) from one point to another, without accessing it beyond what is needed to move it, as not being business associates. A classic example is a courier such as the U.S. Postal Service or a comparable transmission-only service. Because the exception is narrow, most vendors that store or otherwise handle PHI do not qualify and generally must sign a business associate agreement.

Formal definition

The conduit exception is a limited carve-out from the HIPAA definition of business associate for entities whose only service to a covered entity or business associate customer is the transmission of PHI (including electronic PHI), analogous to the role of the U.S. Postal Service or similar couriers. Per HHS guidance, the exception applies only where the entity transports PHI but does not access it other than on a random or infrequent basis as necessary to perform the transportation service; any storage of PHI by such an entity must be transient rather than persistent. Whether the exception applies is typically the determining factor in assessing whether a business associate agreement (BAA) is required. This is a narrow exception: cloud service providers and other vendors that maintain or store PHI generally fall outside it and are treated as business associates. Practitioners should confirm the specific application against current HHS OCR guidance and the applicable regulatory text, as this summary does not reproduce exact CFR citations.

Why it matters

The conduit exception matters because it draws a narrow but consequential line between vendors that require a business associate agreement (BAA) and the small set of entities that do not. Misapplying the exception is a common compliance error: an organization that wrongly classifies a storage vendor or cloud service provider as a mere conduit may fail to execute a required BAA, leaving PHI handled outside the contractual safeguards HIPAA generally expects. Because the exception is deliberately limited to transmission-only services analogous to the U.S. Postal Service or a comparable courier, most vendors that touch PHI fall outside it.

The practical stakes center on the BAA determination. Per HHS guidance, entities that maintain or store PHI, rather than merely transporting it, generally do not qualify for the exception and are treated as business associates. This means cloud service providers that store ePHI typically must sign a BAA, even if their role feels passive from the covered entity's perspective. Treating persistent storage as if it were transient transmission is precisely the misunderstanding the exception is intended to prevent.

Getting this classification right helps covered entities and business associates document their vendor relationships accurately and demonstrate that appropriate agreements are in place. Because the application of the exception is fact-specific and turns on how PHI is accessed and whether any storage is transient, organizations should confirm the analysis against current HHS OCR guidance and the applicable regulatory text rather than relying on a vendor's self-description.

Who it's relevant to

Privacy and Compliance Officers
These professionals rely on the conduit exception to decide whether a given vendor relationship requires a BAA. Because the exception is narrow and fact-specific, they should scrutinize whether a vendor merely transmits PHI or also stores or accesses it, and document the basis for any conclusion that a vendor qualifies. When in doubt, the more conservative course is to treat the vendor as a business associate and execute a BAA.
Vendor Management and Procurement Teams
Teams that onboard third-party services need to assess each vendor's actual handling of PHI rather than accept a vendor's characterization of itself as a conduit. Vendors that store PHI, including many cloud service providers, generally fall outside the exception and require a BAA, so procurement workflows should flag any persistent storage of PHI as triggering business associate obligations.
Cloud Service Providers and IT Vendors
Vendors offering services to covered entities or business associates should understand that maintaining or storing PHI generally disqualifies them from the conduit exception. Under HHS guidance, storage must be transient rather than persistent for the exception to apply, so most CSPs that hold ePHI are treated as business associates and are expected to enter into BAAs and meet the associated obligations.
Healthcare Legal Counsel
Attorneys advising on HIPAA vendor arrangements use the exception to determine contractual requirements and to allocate risk. Given that application turns on specific facts about access and storage, counsel should confirm each analysis against current HHS OCR guidance and the applicable regulatory text, and should note that state law or other frameworks may impose additional requirements beyond HIPAA.

Inside Conduit Exception

Conduit Exception (Concept)
A narrow interpretive concept under the HIPAA regulatory framework, discussed by HHS OCR, under which an entity that merely transports or transmits protected health information (PHI) without accessing it other than on a random or infrequent basis is generally not treated as a business associate. The exception applies to the conduit's function, not merely to the type of entity.
Transmission-Only Function
The core qualifying element is that the entity's role is limited to transmitting or transporting PHI. Classic examples generally cited include the postal service, certain private couriers, and telecommunications providers that carry data or voice without meaningful access to the content.
Transient vs. Persistent Access
A key distinguishing factor is whether access to PHI is transient (incidental to transport) rather than persistent. Entities that store PHI beyond what is transient to the transmission function generally fall outside the exception and are typically treated as business associates.
Relationship to Business Associate Status
The exception is relevant to the threshold question of whether a business associate agreement (BAA) is required. If an entity qualifies as a true conduit, it generally is not a business associate and a BAA is typically not required for that function.
Random or Infrequent Access Standard
OCR guidance generally frames the exception around access to PHI that occurs only on a random or infrequent basis and as necessary to perform the transport service, rather than ongoing or routine access to the content being transmitted.

Common questions

Answers to the questions practitioners most commonly ask about Conduit Exception.

Does the conduit exception apply to any vendor that merely transmits or stores our PHI?
No. This is a common misconception. The conduit exception is generally construed narrowly and typically applies only to entities that transport information but do not access it other than on a random or infrequent basis as necessary to perform the transportation service or as required by law. A vendor that maintains or stores PHI, even without routinely viewing it, is generally treated as a business associate rather than a conduit. Because the distinction turns on the specific nature and persistence of access, readers should evaluate each relationship against the current regulatory text and applicable HHS OCR guidance rather than assuming the exception applies.
If a service provider qualifies as a conduit, does that mean it has no HIPAA obligations at all?
Not necessarily in the way this is often assumed. A true conduit is generally not considered a business associate and therefore is typically not required to enter into a business associate agreement for that function. However, this status describes a limited exception to business associate treatment; it does not mean the entity is exempt from all law, and it does not extend to any separate services the same organization may provide that do involve business associate functions. The scope of the exception is narrow, so its application should be confirmed against current regulation and guidance.
How do we determine whether a particular vendor is a conduit or a business associate?
In most cases the analysis focuses on whether the vendor's access to PHI is transient and incidental to transporting the information, versus whether the vendor maintains, stores, or otherwise has ongoing or more than random access to PHI. Persistent storage generally weighs toward business associate status even where the vendor states it does not routinely view the data. Because this is a fact-specific determination, organizations typically document their reasoning and, where the analysis is close, treat the relationship as a business associate relationship. Verify the governing criteria against the current regulatory text.
Should we still put a business associate agreement in place if we are unsure whether the conduit exception applies?
As a practical matter, many organizations execute a business associate agreement when the conduit determination is uncertain, because the exception is narrow and the consequences of misclassifying a business associate as a conduit can include compliance gaps. Entering into a business associate agreement where one may not be strictly required is generally a conservative approach, though organizations should weigh this against their own risk posture and confirm the current requirements with counsel and against applicable guidance.
Does a cloud service provider generally qualify for the conduit exception?
In most cases a cloud service provider that maintains or stores ePHI is generally treated as a business associate rather than a conduit, even where its personnel do not routinely access the stored data. The conduit exception is typically limited to transmission-only services rather than storage or maintenance functions. Because cloud arrangements vary and the underlying regulatory analysis is fact-specific, organizations should assess each provider against the current regulation and relevant HHS OCR guidance rather than assuming conduit status.
How should we document a conduit determination for audit purposes?
Organizations typically document the specific service provided, the nature and frequency of the vendor's access to PHI, and the reasoning supporting the conclusion that access is transient and incidental to transportation rather than involving storage or maintenance. Retaining this analysis helps demonstrate a reasoned, good-faith classification decision. Note that this documentation supports HIPAA compliance efforts but does not by itself guarantee compliance, and the criteria applied should be verified against the current regulatory text and guidance.

Common misconceptions

Any vendor that transmits or handles PHI qualifies as a conduit and therefore never needs a business associate agreement.
The exception is narrow and function-specific. It generally applies only to entities providing mere transmission or transport with, at most, transient and random or infrequent access to PHI. Vendors that store PHI or have persistent access, such as many cloud storage providers, are typically treated as business associates requiring a BAA, even if they do not routinely view the content. Practitioners should verify against current OCR guidance.
A cloud service provider is a conduit because it only 'passes through' or holds encrypted data it cannot read.
OCR has generally indicated that maintaining or storing PHI is more than a transient function, so an entity that stores PHI on behalf of a covered entity or business associate is generally a business associate regardless of whether it actually views the data or whether the data is encrypted. Lack of access to the content does not by itself establish conduit status.
Whether the conduit exception applies depends on the category of company (for example, a telecom or courier is always a conduit).
The analysis turns on the actual function performed with respect to the PHI, not the general industry label of the entity. The same organization may act as a conduit for one service and as a business associate for another, so the determination should be made service by service.

Best practices

Analyze the conduit question by function and by service rather than by vendor type, documenting exactly what the entity does with the PHI and whether any access is transient and random or infrequent.
Treat storage or maintenance of PHI as generally disqualifying for the conduit exception, and default to executing a business associate agreement where an entity holds or persistently accesses PHI, including cloud storage arrangements.
When in doubt, err toward classifying a vendor as a business associate and putting a BAA in place, since misclassifying a business associate as a conduit can leave a compliance gap under HIPAA.
Document the basis for any conduit determination, including the reasoning and the scope of the entity's access, so the decision can be defended if reviewed by HHS OCR.
Verify the current OCR guidance and applicable regulatory text before relying on the exception, as interpretive guidance and examples may be updated over time.
Consider whether state law, the HITECH Act, or contractual obligations impose additional requirements beyond HIPAA, and remember that avoiding business associate status does not by itself establish overall HIPAA compliance or exempt an entity from other applicable duties.