Most people assume HIPAA is a hospital problem. Big systems, compliance officers, badge readers, annual training modules. The businesses that get surprised sit one step off to the side: the billing company, the third party administrator, the software vendor, the two person therapy practice, the accounting firm that keeps books for a clinic, and yes, the IT provider. None of them feel like health care organizations. Several are inside the rules anyway.
Before we go further: this is general information, not legal advice. HIPAA is federal regulation with real definitions and real exceptions, and whether it reaches your company depends on facts about your contracts and data flows that no blog post can evaluate. Have an attorney or qualified compliance advisor confirm what applies to you. Our goal here is narrower: helping you decide whether you need that conversation at all.
Covered Entity or Business Associate
HIPAA reaches two kinds of organizations, and the distinction drives everything else. The Department of Health and Human Services describes covered entities as three groups: health plans, health care clearinghouses, and health care providers who electronically transmit health information in connection with certain transactions, such as claims, eligibility inquiries, or referral requests. HHS notes this applies regardless of organization size.
That last group catches people. Being a provider is not the trigger by itself. The trigger is the electronic transmission in connection with those transactions. A solo practitioner who takes only cash may sit outside the definition, while the same practitioner who starts billing electronically next month may not. That is a fact question for counsel, not a message board.
The second category is business associates. HHS defines one as “a ‘person’ that performs certain functions or activities regulated by the HIPAA administrative simplification regulations on behalf of a covered entity (or an organized health care arrangement) that involve creating, receiving, maintaining, or transmitting PHI.” Note the last two words. You do not have to read protected health information to be a business associate. Maintaining or transmitting it is enough. The definition also runs down the chain, to “any subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate.”
The Surprise Cases We See Most
HHS publishes examples, and the list runs broader than most owners expect.
- Billing and practice management services. HHS lists “claims processing or administration, data analysis, billing, and practice management” among the functions that make a company a business associate. Some billing operations may fall under the clearinghouse definition instead, making them covered entities.
- IT, cloud, and hosting providers, including us. HHS explicitly lists an “IT contractor or vendor (e.g., EHR vendor, Managed Services Provider) that provides maintenance and/or support services,” and separately a “cloud service provider engaged to create, receive, maintain, or transmit electronic PHI.” We sign business associate agreements for clients who handle PHI, because we should. If a provider storing your data will not sign, that tells you something.
- Benefits administrators. HHS lists a “third party administrator that assists a health plan with claims processing.” Many benefits and HR service firms fit that description without thinking of themselves as health care companies.
- Professional services firms. HHS lists a “CPA firm whose accounting services to a health care provider involve access to PHI” and an “attorney whose legal services to a health plan involve access to PHI.” The service is ordinary. The access is the point.
One exception is worth knowing, and it is narrower than people hope. HHS recognizes a conduit exception for entities acting “only as a conduit for PHI, for example, the US Postal Service, certain private couriers, and their electronic equivalents.” HHS is direct about the limit: “entities that access PHI on a regular or frequent basis to perform a service on behalf of a covered entity are not conduits.” Storing is not couriering.
The Business Associate Agreement Is Not a Formality
The business associate agreement, usually shortened to BAA, sets the rules between a covered entity and its business associate. HHS says it must “describe the permitted and required uses and disclosures of PHI by the business associate,” provide that the business associate “will not use or further disclose the PHI other than as permitted or required by the BAA or as required by law,” and require compliance with the applicable rules. HHS draws a firm line too: a covered entity “may not contractually authorize its business associate to make any use or disclosure of protected health information that would violate the Rule.” You cannot sign your way out of the regulation.
Two practical points. HHS notes business associates are directly liable for certain HIPAA provisions, so a BAA is not just risk being pushed downhill. And treat signed BAAs as an inventory: one list, both directions, with counterparty, date, and what data the relationship touches. When something goes wrong, that list is the first thing anyone asks for.
The Security Rule in Plain Terms
The Privacy Rule covers protected health information in any form, including paper and spoken conversation. The Security Rule governs the electronic side, and applies to covered entities and business associates alike. Its core requirement is to ensure “the confidentiality, integrity, and availability of electronic protected health information.” Translated: keep it from the wrong people, keep it from being altered or destroyed improperly, keep it available to the right people when they need it. That third one surprises people. Ransomware that locks up records is an availability problem, not only a confidentiality one.
The rule sorts requirements into three safeguard categories: administrative, physical, and technical. Administrative is policy, training, and assigned responsibility. Physical is doors, drives, and device disposal. Technical is access control, authentication, encryption, and logging. Underneath sits a risk analysis requirement, where every real implementation starts. The rule is scalable by design: organizations implement measures appropriate to their size, complexity, and technical capabilities rather than one fixed checklist. A three person practice is not held to a hospital’s architecture. It is held to having thought the problem through and documented the result. On authentication, our comparison of YubiKey versus passkeys versus MFA may help.
One note for accuracy. HHS published a notice of proposed rulemaking on January 6, 2025 proposing modifications to the Security Rule. A proposed rule is a proposal, not a requirement, and rulemaking timelines shift. Ask your advisor where that stands before planning around it.
Where to Start If You Think This Applies
- Map where health data enters and rests. Email attachments, a shared folder, a portal, a scanner, a fax line, an intake form, a laptop. You cannot protect a flow you never drew.
- Get the classification answered by counsel. Covered entity, business associate, subcontractor of one, or none of the above. Everything downstream depends on it, so pay to get it right once.
- Inventory the agreements. Every BAA you signed and every one you should have. Gaps in both directions are common.
- Do a real risk analysis and write it down. Not a vendor questionnaire. An honest assessment of where data is, what could go wrong, and what you are doing about it, dated and kept.
- Fix the basics. Unique accounts per person, strong multifactor authentication, encrypted laptops and phones, limits on who can reach what, tested backups, and a documented process for removing access when someone leaves.
The Bottom Line
If health information moves through your business, the odds that HIPAA is somebody else’s problem are lower than you think, and lowest of all for billing companies, benefits administrators, professional services firms, and technology vendors. The good news: the Security Rule is scalable by design, and most of what it asks for is what a well run small business should do anyway. Map the data, get the classification answered properly, inventory the agreements, document a real risk analysis. Much of that overlaps with the case we made in why cybersecurity is no longer optional for mid-sized businesses. And once more, plainly: this is general information, not legal advice, and a lawyer or compliance advisor should confirm what applies to your business.
We support clients who handle health information every day, we sign business associate agreements, and we can help you map your data, close technical gaps, and document what you did. If you are not sure where your business stands, Contact us today.
Sources:

Comments are closed