Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Glossary

Definition · Allowed AI at work

Covered entity vs business associate

Under HIPAA, a covered entity is a health plan, a clearinghouse, or a provider that conducts standard electronic transactions such as claims. A business associate is a person or company that creates, receives, maintains, or transmits PHI on a covered entity's behalf. Both must follow HIPAA, and a Business Associate Agreement binds them.

Covered entities and business associates

Both terms are defined at 45 CFR 160.103. Covered entities are the organizations HIPAA regulates directly: health plans, clearinghouses, and providers who bill or check eligibility electronically. That includes most practices, pharmacies, and hospitals. Business associates are the vendors and partners that handle PHI to do work for them.

Business associates include billing companies, IT and cloud vendors, AI tools, health information organizations, and e-prescribing gateways. A business associate's own vendors that touch PHI are subcontractors and are business associates too. Since 2013, business associates have been directly liable for complying with the Security Rule and parts of the Privacy Rule.

The conduit exception is narrow. A conduit, like the postal service or a courier, only transports information and does not access it except randomly or rarely. HHS says a cloud provider that stores ePHI is a business associate even if the data is encrypted. Rivvi acts as a business associate and signs a BAA, included on the free plan.

Questions

Covered entities and business associates, answered

Is a medical practice a covered entity?
Almost always. A provider becomes a covered entity by conducting HIPAA standard transactions electronically, such as submitting claims or checking eligibility. Nearly every practice that bills insurance does this, directly or through a billing company. A cash-only provider that never transacts electronically may fall outside HIPAA.
What is the HIPAA conduit exception?
It exempts entities that only transmit PHI and do not access it, except on a random or infrequent basis. The postal service, couriers, and internet service providers are examples. It covers transmission with only transient storage. A vendor that stores PHI, even briefly for processing, is not a conduit.
Is a cloud provider a business associate if data is encrypted?
Yes. HHS guidance says a cloud service provider that stores or handles ePHI is a business associate. That holds even if the data is encrypted and the provider has no key. It needs a BAA and must meet the applicable Security Rule requirements.
Is an AI vendor a business associate?
Yes, when it handles PHI for a covered entity. That covers AI chat tools, transcription, voice agents, and analytics. The covered entity must have a signed BAA before sending patient data. The vendor, in turn, needs BAAs with any subcontractors that touch the PHI, such as model providers.

Try it on your own data today.

Free to start. Most teams are using it the same day.