An overview of HIPAA, published in Innovations in Clinical Neuroscience, explains that “business associates are third parties that perform a function on behalf of or provide services to a Covered Entity that require the release of PHI.” HIPAA defines that element of protected health information (PHI) as any identifiable information about a person’s health, care, or payment for care. Information is also only considered PHI when held or transmitted by a HIPAA covered entity or business associate.

Professional service firms become business associates when engaged to do work that requires them to create, receive, maintain, or transmit PHI. Providers can define this relationship ahead of time when sending records and keep exchanges approved through secure email. Now, if a professional firm is a business associate, its staff and systems extend the pool of people who can access patient data.

A Dovepress indexed analysis published in 2026 based on 7,327 reported breaches found that breaches involving business associates were larger, adding that “business associate involvement was independently associated with a larger breach magnitude (IRR = 2.0).” After controlling for other factors, this statistically relevant result in the model showed about twice the magnitude of breaches involving business associates. The study could not prove that one caused the other, but providers should take the association seriously. Limiting each vendor’s access to the PHI necessary for its project and sending records through a secure, auditable email platform are two safeguards.

 

The service and the data determine the firm’s status

The Paubox’s guide on HIPAA compliant email explains, “A business associate is someone who provides services to covered entities.” A firm generally qualifies as a business associate when it works for a covered entity or another business associate and creates, receives, maintains, or transmits PHI on that organization’s behalf. Hiring any professional listed in the law makes an organization a business associate when the contracted service includes disclosing PHI to the vendor. A firm could be a business associate for one project but not for another. Providers can clarify their services, required data, and approved recipients before employees transmit files via email.

 

Professional services that can trigger HIPAA

The Paubox legal services review points out, “Legal professionals qualify as business associates when they provide legal services that require access to PHI.” Accounting, actuarial, consulting, data aggregation, management, administrative, accreditation, and financial services can also become HIPAA regulated when they access patient data.

Professional services apply whether the organization uses a small firm led by the provider or a large corporation. Title does not make the provider a business associate; the data does. Providers can send only necessary files through HIPAA compliant email and keep access limited to the project team.

 

Common examples

  • Law firms accessing medical records for litigation support, regulatory counseling, or data breach response.
  • Accounting firms or audit firms accessing patient-level billing, claims, or payment records.
  • Actuarial firms accessing claims or benefit information that includes identifiers.
  • Consultants performing utilization review, quality improvement work, or revenue-cycle analysis with patient data.
  • Accreditation organizations accessing clinical files that include identifiers.
  • Financial advisers who receive patient identifiers during due diligence.

 

When the firm is not a business associate

Paubox notes in a discussion of disclosures, “HIPAA acknowledges that incidental disclosures may occur even when safeguards are in place.” The HIPAA website clearly differentiates accidental access from anything that involves handling PHI as part of the core service. Organizations such as janitorial services or electricians do not become business associates simply because a worker might inadvertently see protected information.

Two safeguards must exist for that exception namely, PHI is not part of the job, and the covered entity has maintained reasonable safeguards. Providers can also avoid business associate status by limiting work to general corporate functions without access to PHI or by receiving only properly de-identified information. There is no practical way to provide those services and receive PHI without becoming a business associate. Providers should strip out needless identifiers and avoid putting unnecessary PHI in emails or attachments.

 

What must a business associate agreement include?

An article offering comments about business associate agreements (BAAs), said, “Simply put, a BAA is a contract between a HIPAA covered entity and a HIPAA business associate.” The agreement governs the access, use, and disclosure of PHI by both parties. Covered entities should sign the BAA with the vendor before disclosing PHI. Pertinent points include defining the allowed uses and disclosures of PHI, requiring safeguards and incident reporting, addressing permitted patient rights, and returning or destroying PHI if possible.

The BAA should reflect the work as stated in the provider’s agreement with the vendor. HIPAA includes a minimum necessary standard that limits uses, disclosures, and requests to the PHI needed for that purpose. Providers can uphold that standard by carefully limiting approved email recipients and using systems that have signed a business associate.

 

A BAA does not secure the data by itself

The HIPAA Security Rule mandates administrative, physical, technical safeguards for ePHI. Covered providers should review the vendor’s risk analysis, role-based access, multifactor authentication, encryption, audit logs, training, incident response plan, backup procedures, and disposal methods. HIPAA compliant email services keep PHI off personal accounts and unapproved file-sharing platforms. Encrypting data in transit and at rest with proper access controls and audit logs also reduce exposure and help with investigations.

 

Subcontractors extend the compliance chain

Neglecting to sign an agreement with a subcontractor is considered a HIPAA violation in itself. A professional service firm may have subcontractors that create additional business associate relationships. If a vendor uses subcontractors to access client PHI on its behalf, then they are considered business associates as well.

Examples include e-discovery companies, cloud platforms, subject matter experts, and managed IT services. Business associates may be held liable for certain violations of the Security Rule, unauthorized disclosures, breach notifications, and failure to execute downstream contracts. Providers can request the primary vendor affirm its approved subcontractors and use secure email platforms when working with them.

 

FAQs

Does attorney-client privilege replace a BAA?

No, privilege and confidentiality duties do not replace a BAA when legal services for a covered entity involve PHI.

 

Does an NDA satisfy the business associate requirement?

No, a general NDA usually lacks the provisions HIPAA requires in a business associate contract.

 

Does encryption eliminate the need for a BAA?

No, an organization that maintains encrypted electronic PHI (ePHI) on another regulated entity’s behalf can still be a business associate without the decryption key.

 

Is a firm a business associate when a patient sends it records directly?

Not automatically, because business associate status depends on performing a qualifying service for a covered entity or another business associate.