Yes, HIPAA generally does apply even if a cloud provider can’t read the data. If a cloud service provider stores electronic protected health information (ePHI) for a HIPAA covered entity or business associate, then the service provider is typically a business associate, even if it does not have the means to decrypt or access the information. An International Journal of Environmental Research and Public Health-indexed review published in 2024 explains, “E-Health data are some of the most critical and private information in modern society.” When a cloud vendor can decrypt the files handled, that creates obvious risk. The sensitivity does not end when the vendor lacks the necessary key. A cloud service provider holding onto ePHI for a covered entity or business associate automatically becomes a business associate itself, no matter if the data's encrypted or if the provider has the decryption key. This arrangement is known as a no-view service.

 

What no-view encryption changes

A 2024 JMIR Formative Research study states, “Cloud technology can meet requirements of the healthcare industry.” A no-view setup could put that possibility into practice by ensuring that only the customer can decrypt the information. Although keeping keys separate can limit exposure if someone accesses the provider’s storage system, it does not alter the legal status of the information.

 

Encryption is one part of the Security Rule

The peer-reviewed survey eHealth Cloud Security Challenges explains, “Confidentiality can be achieved by access control and using encryption techniques.” Confidence and encryption do not equal HIPAA. Covered entities and business associates must also guard against unauthorized alteration (integrity) and ensure that authorized users can access PHI when they need it (availability).

Encryption does not address everything in those categories. Malware could still corrupt encrypted files, a cyberattack could prevent decryption, and an intrusion could block access to both. Administrative and physical safeguards cover other solutions. Healthcare entities can use HIPAA compliant email to share details about their risk analysis so staff knows how to contact them if the cloud service goes down.

 

A business associate agreement (BAA) is still required

The Paubox Report published in 2025 reported that almost one in five email-related breaches involved business associates. That risk shows why technical design cannot replace HIPAA compliant agreements. When a cloud provider maintains PHI on a customer’s behalf, HIPAA considers the provider to be the customer’s business associate.

Accordingly, a BAA is required. The contract should specify allowed uses, mandatory safeguards, breach notification responsibilities, subcontractors, and final disposition of PHI. A related service-level agreement may outline uptime guarantees, backup timing, recovery procedures, data return, and support arrangement.

 

Encryption does not create a conduit or make data de-identified

Paubox covered cloud service providers in a newsletter. According to that article, vendors that process PHI for a covered entity or business associate are business associates. HIPAA includes a limited conduit exception for third parties that transmit PHI and temporarily store it as part of the transmission process. A cloud vendor that merely cannot view customer data is not necessarily a conduit.

HIPAA also does not consider encrypted PHI to be de-identified. Information is only de-identified if it has been processed under a HIPAA Privacy Rule method so that it no longer identifies a person as defined by HIPAA. Covered entities can email staff to inform them that encryption does not make data de-identified. Only information de-identified under HIPAA’s Privacy Rule is outside of HIPAA’s PHI protections. Accurate expectations can prevent someone from accidentally emailing restricted data.

 

No-view providers still need an incident process

No-view cloud providers must respond to security incidents as directed by HIPAA and their BAAs. While not all incidents reach the level of breach, providers should expect to hear from customers about problems in their system. Sending and receiving those notices through HIPAA compliant email can ensure timely delivery and complete documentation.

But it should be noted that an event where ePHI was properly encrypted may still fall outside the realm of a reportable HIPAA breach, as HHS affords a safe harbor if the required encryption standard was applied and the decryption key was not obtained.

 

How to evaluate a no-view cloud provider

The 2026 Paubox Healthcare Email Security Report analyzed 170 email-related breaches reported in 2025 and assessed 41% of the affected organizations as high risk based on their email configuration, up from 31% in 2024. Before working with any cloud service, a healthcare organization should:

  • Confirm that the vendor will enter a BAA before receiving any PHI.
  • Map the data that enters the cloud service, where it goes, and who accesses it through subcontractors.
  • Define who manages, backs up, rotates, and recovers encryption keys.
  • Assign responsibility for authentication, admin accounts, logging activity, patching apps, backups, and disaster recovery.
  • Demand timely incident reports and define required information for each notice.
  • Confirm the vendor will return or destroy PHI if the agreement ends.
  • Verify restored data is available when needed and cannot be withheld during a dispute.
  • Only use HIPAA compliant email when communicating PHI with your cloud service provider.

Selecting a vendor with a HIPAA compliant email platform like Paubox can streamline the communication requirement. Paubox has a strong track record of meeting HIPAA requirements, and their BAA is available upon request. But providers are still responsible for their own policies, access controls, workforce rules, and vendor management.

 

FAQs

Can a SOC 2 report or HITRUST certification replace a business associate agreement?

HIPAA requires BAAs between vendors and customers that create, store, access, or transmit PHI on behalf of the customer. Certification might help an organization assess a vendor, but it does not replace this requirement.

 

Does HIPAA allow encrypted PHI to be stored on servers outside the United States?

HIPAA applies when healthcare information is stored outside the United States, but vendors can serve foreign customers if they sign a BAA and address any local risks.

 

What should a business associate do if their no-view provider refuses to sign a BAA?

Covered entities and business associates should choose vendors that will sign a BAA before creating relationships. Establishing a relationship without a signed BAA is a direct violation of HIPAA.