Business Associate
Definition
A person or entity that performs services for a HIPAA covered entity that involve creating, receiving, maintaining, or transmitting protected health information (PHI). Business associates must sign a Business Associate Agreement and comply with applicable HIPAA Security Rule requirements.
- Governed by
- HIPAA Security and Privacy Rules
- Handles
- Protected health information (PHI) on behalf of a covered entity
- Required document
- Business Associate Agreement (BAA)
- Examples
- Cloud hosting, billing, transcription, IT support vendors
Common questions
Who counts as a business associate under HIPAA?+
Any vendor or contractor that creates, receives, maintains or transmits PHI while performing a service for a covered entity, such as a cloud storage provider, medical billing company, or forensic laboratory processing health-related records, qualifies as a business associate.
What happens if a business associate has a data breach?+
The business associate is directly liable under the HIPAA Security Rule and must notify the covered entity, which in turn has its own breach notification obligations to affected individuals and regulators. The Business Associate Agreement sets out these notification duties in advance.
Related terms
- Addressable Implementation Specification
- A HIPAA Security Rule specification that organisations must assess for reasonableness and appropriateness. If reasonable and appropriate, it must be implemented; if...
- Cardholder Data Environment (CDE)
- The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. PCI-DSS requirements apply to the CDE...
- Covered Entity
- Under HIPAA, a healthcare provider that transmits health information electronically, a health plan, or a healthcare clearinghouse. Covered entities are directly subject...
- Protected Health Information (PHI)
- Individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium. PHI includes...
- Qualified Security Assessor (QSA)
- An individual certified by the PCI Security Standards Council to perform on-site PCI-DSS assessments for merchants and service providers that cannot self-certify....