Who Needs to Sign a Business Associate Agreement?

The requirements and obligations of Covered Entities to satisfy themselves that the Protected Health Information (PHI) they share with other organizations will be protected…

Read More

Jim Hook, MPH

By Jim Hook, MPH | February 9, 2026

Pen signing a HIPAA Business Associate Agreement.

The requirements and obligations of Covered Entities to satisfy themselves that the Protected Health Information (PHI) they share with other organizations will be protected from unauthorized disclosures have been around since the original HIPAA Privacy Rule in 2002. The mechanism for a covered entity to demonstrate that satisfaction is by means of a written contract – a business associate agreement. So one answer to the question of who needs to sign a business associate agreement is: any covered entity that shares PHI with an organization supplying services/functions to that covered entity. If you are supplying services or performing functions with that shared PHI on behalf of a covered entity, are you required to sign a business associate contract? Let’s look at some definitions.

What is the definition of a Covered Entity?

HIPAA covered entities include three major categories of healthcare organizations:

  • A health care provider,
  • Health plans/health insurance companies, and
  • A health care clearinghouse.

All of these organizations are covered by the HIPAA Privacy Rule. In addition, a covered entity that creates, maintains or stores electronic PHI is also covered by the HIPAA Security Rule. So the requirements for business associates are addressed in both the HIPAA Privacy Rule and the HIPAA Security Rule.

Who is a Business Associate?

The Privacy Rule spells out some of the functions that, when assigned to an outside entity instead of the covered entity’s workforce, make the outside entity a business associate. These include functions involving access to PHI, such as claims processing, data analysis, billing, or practice management. Business associate services include, in part, legal, consulting, accounting, accreditation, and financial transaction services.

If you don’t sign a Business Associate Agreement, are you a Business Associate?

YES! Performing any specified function involving PHI, and fitting into the definition of business associate services, makes you a business associate – subject to the requirements (and potential penalties) of the HIPAA regulations. The Office for Civil Rights (OCR) of the Health and Human Services Department (HHS) has not hesitated to impose penalties on a covered entity and it’s erstwhile service provider when there is an unauthorized disclosure of PHI. So the second party who should sign a business associate agreement is the entity providing functions/services that involve access to a covered entity’s PHI.

And the subcontractors of business associates that have access to the PHI from a contracting covered entity, are also covered by the Privacy rule and Security rule. Business associates should execute appropriate agreements with their business associate subcontractors to address this concern.

When is a Business Associate Agreement not required?

Believe it or not, there are many circumstances where PHI is shared, but the entity receiving the PHI is not a business associate of the disclosing entity. Some of the common circumstances include:

  • A covered health care provider sharing PHI with another covered health care provider for treatment purposes does not need a business associate agreement with the other provider. 
  • A financial institution that processes electronic funds transfers, like credit or debit card payments, is performing normal banking services, not business associate services.
  • A data processing center which does not have access to covered entity servers with PHI would not be a business associate. But a cloud service provider is considered a business associate, and needs to sign a business associate agreement. 

What are the other Obligations and Requirements of Business Associates?

In a word, numerous. The HITECH Act of 2010 amended the HIPAA regulations to extend the responsibilities for maintaining the privacy of protected health information to business associates on a par with a covered entity. This means compliance with with several provisions of the HIPAA Privacy, Security, Breach Notifications and Enforcement Rules. A good business associate agreement must address all of these elements to demonstrate HIPAA compliance. And while most HIPAA violations result in fines as penalties, criminal penalties are also possible under HIPAA. 

According to IBM, the cost of a global data breach rose to $4.88 million in 2024. The cost of data breaches in health care in the same year were $9.77 million! Making sure your business associates have proper agreements and are complying with HIPAA rules is more important than ever! This is a new blog post!