HIPAA & compliance

HIPAA for Business Associates: What Vendors Must Know

Any vendor handling PHI is a HIPAA business associate with direct liability since 2009. Here are your obligations, what a BAA must contain, and the penalties for getting it wrong.

If your company creates, receives, maintains, or transmits protected health information for a healthcare provider or plan, you are a HIPAA business associate, and since 2009 you are directly liable to regulators. That means the same safeguards, the same breach-reporting duties, and the same penalties that apply to hospitals now apply to you. Here is what that requires.

Who qualifies as a business associate?

A business associate is any third party that handles PHI on behalf of a covered entity. Common examples:

  • Medical billing and coding services
  • EHR vendors
  • Patient intake platforms
  • Cloud storage and hosting providers
  • IT support with PHI access
  • Healthcare attorneys and accountants
  • Transcription, translation, and document-shredding services

If PHI passes through your systems, you almost certainly qualify. (For the full map of who HIPAA covers, see who must follow HIPAA.)

What is a Business Associate Agreement?

A BAA is the contract that binds a business associate to HIPAA. It must specify:

  • Permissible uses and disclosures of PHI
  • The security safeguards you will maintain
  • The requirement that subcontractors also sign BAAs
  • Breach-notification terms, including the 60-day discovery window
  • Provisions to return or destroy PHI when the contract ends

Operating without a signed BAA is one of the most-cited violations.

What are business associates required to do?

Your obligations under the Security Rule include:

  • Conduct and document a security risk analysis
  • Encrypt ePHI in transit and at rest
  • Use multi-factor authentication and access controls
  • Maintain audit logs
  • Train your workforce on HIPAA policies
  • Report security incidents and breaches to covered-entity clients within 60 days
  • Ensure subcontractors sign BAAs and comply
  • Implement administrative, physical, and technical safeguards, and verify them annually

Common compliance failures

Regulators cite the same gaps repeatedly:

  • Operating without a signed BAA
  • No documented security risk analysis
  • Inadequate ePHI encryption
  • No documented incident-response plan
  • Insufficient workforce training
  • Failing to notify covered entities of breaches within 60 days

What are the penalties?

Business associates face the same tiers as covered entities: from about $145 per violation (Tier 1) up to $2,190,294 per violation category (Tier 4). 2024 was one of the most active enforcement years on record, with 22 resolved cases, many involving business associates, and HHS estimated the first-year cost of the 2025 Security Rule updates at $9 billion industry-wide.

How Zentake meets its obligations

As a patient intake platform, Zentake is a business associate and is built to act like one: encryption in transit and at rest, role-based access and audit logging, workforce training, breach procedures, and a signed BAA on every plan. That is what lets practices collect HIPAA-compliant intake and e-signatures with confidence.

The bottom line

Being a business associate is not a formality, it is direct legal exposure with real penalties. Sign BAAs, run your risk analysis, encrypt everything, train your team, and report breaches on time. Vendors that treat this seriously are the ones healthcare practices can safely build on. Learn more about choosing compliant intake software.

Frequently asked questions

Who qualifies as a HIPAA business associate?

Any vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. That includes billing services, EHR vendors, patient intake platforms, cloud hosts, IT support, and even shredding companies.

What must a business associate do under HIPAA?

Conduct a security risk analysis, encrypt PHI in transit and at rest, use MFA and access controls, keep audit logs, train staff, report breaches within 60 days, and ensure any subcontractors also sign BAAs and comply.

What must a BAA contain?

Permissible uses and disclosures of PHI, required safeguards, subcontractor obligations, breach-notification terms (a 60-day discovery window), and provisions to return or destroy PHI when the contract ends.

Are business associates directly liable to regulators?

Yes. Since the HITECH Act of 2009, business associates are directly liable to HHS OCR, not just contractually responsible to their covered-entity clients. Penalties reach into the millions per violation category.

Start your free trial← Back to the journal