Which Rule Expanded HIPAA Compliance to Include Business Associates
The rule that expanded HIPAA compliance to include business associates is the HIPAA Omnibus Final Rule, published by the U.S. Department of Health and Human Services on January 25, 2013. Before that rule, vendors handling protected health information answered only to the covered entity that hired them. After it, they answer directly to the federal government.
The legal authority came earlier. The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 established that third-party vendors should carry direct liability under HIPAA. The Omnibus Rule is what wrote that principle into the regulations and made it enforceable, with a compliance deadline of September 23, 2013.
Three changes did the work: the rule widened the definition of a business associate, it made business associates directly liable for the Security Rule and parts of the Privacy Rule, and it pulled downstream subcontractors into the same chain of accountability. Below we cover each of those changes, which HIPAA rules now apply to a business associate, what compliance actually requires, when business associate agreements are mandatory, who sits outside the definition, and what is changing next.
Which Rule Expanded HIPAA Compliance Requirements to Include Business Associates?
The rule that expanded HIPAA compliance requirements to include business associates is the HIPAA Omnibus Final Rule of 2013. HHS published the final modifications to the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules on January 25, 2013, and regulated entities had until September 23, 2013 to comply.
Compliance in 2013 meant something different from compliance before it. A vendor that processed claims, stored records, or supported a practice's servers had previously been bound only by whatever the covered entity negotiated into a contract. The Omnibus Rule converted that contractual exposure into regulatory exposure, which means the Office for Civil Rights can now investigate and penalize the vendor directly rather than pursuing the medical practice and leaving the practice to chase its vendor. Anyone approaching HIPAA compliance as a vendor rather than as a provider is living inside the change this rule made.
What Rule Expanded Upon HIPAA Compliance?
The rule that expanded upon HIPAA compliance is the Omnibus Rule, and it expanded HIPAA in four directions at once. It widened who the law reaches, it strengthened patient rights over protected health information (PHI), it replaced the old subjective breach standard with a presumption of breach, and it raised the penalties attached to violations.
Four simultaneous expansions is why the rule carries the name "omnibus." HHS bundled modifications to the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Enforcement Rule into a single rulemaking rather than issuing four separate ones. The bundling matters for anyone researching the topic, because a search for a single change often surfaces the whole package.
Which Law Made Business Associates Directly Responsible for Compliance With HIPAA's Security Rule?
The law that made business associates directly responsible for compliance with HIPAA's Security Rule is the HITECH Act of 2009. HITECH is a statute passed by Congress as part of the American Recovery and Reinvestment Act, and it directed that the Security Rule's administrative, physical, and technical safeguard standards apply to business associates in the same way they apply to covered entities.
Statutes and rules do different jobs, which is the distinction most explanations of this topic blur. HITECH created the obligation in law in 2009. The Omnibus Rule implemented it in regulation in 2013, defining exactly who counts, what a compliant contract must say, and how enforcement works. Both answers to "which rule" and "which law" are correct, and they describe two steps in one process rather than two competing facts.
How the Omnibus Rule Changed the Definition of a Business Associate
The Omnibus Rule changed the definition of a business associate to cover any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity, and it explicitly added subcontractors to that definition. The four verbs matter. Earlier readings of HIPAA let vendors argue they merely stored data rather than used it. The Omnibus language closed that argument.
Storage and transmission now count the same as processing. A business associate is also any subcontractor that creates, receives, maintains, or transmits PHI on behalf of another business associate, which means a billing company's cloud host is a business associate even though it has no relationship with the medical practice at all. Across North Alabama practices, the vendor list that touches patient data is usually longer than the practice expects once these verbs are applied honestly.
Which Best Describes a Business Associate Under HIPAA?
A business associate is best described as a person or organization, other than a member of the covered entity's workforce, that performs a function or activity on behalf of a covered entity involving the use or disclosure of PHI, or that provides a service to a covered entity involving the disclosure of PHI. The definition appears at 45 CFR 160.103.
The definition covers a wide field of vendors. HHS names these among its examples:
- Health information exchange organizations, health information networks, and e-prescribing gateways that provide data transmission services and require routine access to PHI
- Vendors offering a personal health record to individuals on behalf of a covered entity
- Health care application developers contracting with a covered entity to provide an app to patients
- Cloud service providers engaged to create, receive, maintain, or transmit electronic PHI (ePHI)
- IT contractors and vendors, including electronic health record (EHR) vendors and managed services providers, that support systems containing ePHI
- Technicians servicing a device that stores PHI, such as a copier or a medical device, where the service involves disclosure of the PHI
- Third-party artificial intelligence (AI) chatbots on a patient portal that handle symptom assessment, medical reminders, or appointment scheduling
- Third-party administrators assisting a health plan with claims processing
- CPA firms, attorneys, and consultants whose services to a covered entity involve access to PHI
- Independent medical transcriptionists and pharmacy benefits managers
The AI chatbot entry is the newest addition to that list and shows how the 2013 definition absorbs technology that did not exist when the rule was written. Absorbing new technology is exactly what the four-verb construction was built to do.
Is a Managed Services Provider a Business Associate?
Yes, a managed services provider is a business associate when its support work requires it to create, receive, maintain, or transmit ePHI. HHS names IT contractors and vendors, including managed services providers, directly in its published examples of business associates.
Remote support is the usual trigger. A provider that administers servers, manages backups, holds domain credentials, or connects to a workstation displaying a patient chart has access to ePHI whether or not anyone intends it to. We sign business associate agreements ourselves for this reason, which puts us on the same side of this rule as every other vendor a practice engages.
Are Business Associates a Covered Entity Under HIPAA?
No, business associates are not covered entities under HIPAA. They are a separate regulated category with overlapping but narrower obligations. Covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction. Business associates are the outside parties those covered entities engage.
Separate categories do not mean mutually exclusive ones. A covered entity can be the business associate of another covered entity, which happens routinely when a hospital provides billing or IT services to an independent practice. In that arrangement the hospital carries covered entity obligations for its own patients and business associate obligations for the practice's patients at the same time, under two different sets of documentation. Smaller healthcare providers sit on the receiving end of these arrangements far more often than they realize.
What HIPAA Rules Apply to Business Associates?
Four HIPAA rules apply to business associates: the Security Rule in full, specified provisions of the Privacy Rule, the Breach Notification Rule, and the Enforcement Rule. The table below sets out how each rule reaches a business associate compared with a covered entity, drawing on the HIPAA rules at 45 CFR parts 160 and 164 and the Office for Civil Rights guidance on direct liability.
HIPAA RuleApplies to Covered EntitiesApplies to Business AssociatesKey Obligation for Business AssociatesPrivacy RuleIn fullSpecified provisions onlyUse and disclose PHI only as the agreement or law permits; provide access and records to OCR; honor minimum necessarySecurity RuleIn fullIn fullImplement administrative, physical, and technical safeguards for ePHI, including a documented risk analysisBreach Notification RuleIn fullIn full, reporting upstreamReport breaches of unsecured PHI to the covered entity, which then notifies individuals and HHSEnforcement RuleIn fullIn fullSubject to the same four-tier civil money penalty structure and to criminal referralOmnibus RuleModifies the four aboveModifies the four aboveThe rule that created direct liability and extended coverage to subcontractors
The Security Rule row is the one that changes daily operations. Applying in full means a business associate owes the same safeguard standards as the hospital it serves, sized to its own environment, and the same requirement to keep a current risk analysis on file. Working out which of the broader compliance regulations reach a given vendor usually starts with this table and ends with a scoping conversation.
Are Business Associates Exempt From the HIPAA Security Rule?
No, business associates are not exempt from the HIPAA Security Rule. The Security Rule applies to a business associate in full, exactly as it applies to a covered entity, and has done since the Omnibus Rule took effect in 2013.
Full application is frequently misunderstood as partial application. The Privacy Rule reaches business associates only through specified provisions, and vendors sometimes carry that limitation across to the Security Rule by mistake. No such limitation exists there. Every administrative, physical, and technical safeguard standard in the Security Rule binds the vendor.
What Are the 5 Main HIPAA Rules?
The 5 main HIPAA rules are the Privacy Rule, the Security Rule, the Breach Notification Rule, the Enforcement Rule, and the Omnibus Rule. Some sources count four key rules instead, leaving the Omnibus Rule out on the basis that it modified the other four rather than creating an independent set of requirements.
Both counts describe the same body of regulation. The Privacy Rule governs how PHI may be used and disclosed. The Security Rule governs how ePHI must be protected. The Breach Notification Rule governs what happens after unauthorized access. The Enforcement Rule governs investigations and penalties. The Omnibus Rule amended all four in 2013 and is counted as a fifth rule wherever writers want to flag those amendments as a distinct milestone.
What Are the Requirements for HIPAA Compliance for Business Associates?
The requirements for HIPAA compliance for business associates are a documented risk analysis, implemented safeguards, written policies and procedures, workforce training, signed business associate agreements up and down the chain, a breach reporting process, and six years of retained documentation. These obligations sit on the vendor itself, not on the covered entity that hired it.
Order matters as much as content, because each step produces the input for the next one:
- Complete a risk analysis. Identify every system, device, and service that creates, receives, maintains, or transmits ePHI, then assess the threats and vulnerabilities against each one. The Office for Civil Rights has made risk analysis its most consistent enforcement focus, and a missing or stale analysis appears in nearly every Security Rule settlement.
- Remediate the gaps the analysis found. Apply the administrative, physical, and technical safeguards the Security Rule requires, sized to the organization's scale and the sensitivity of the data.
- Write the policies and procedures. Document access control, workforce sanctions, device and media handling, contingency planning, and incident response as they actually operate.
- Train the workforce. Every person with access to ePHI needs role-appropriate training, refreshed and recorded.
- Execute business associate agreements. Sign upstream with each covered entity and downstream with each subcontractor before any PHI moves.
- Build the breach reporting path. Define how a security incident is detected, assessed against the four-factor standard, and reported to the covered entity inside the deadline.
- Retain the documentation for six years. HIPAA requires policies, risk analyses, training records, and agreements to be kept and available for six years from creation or from the date they were last in effect.
Step one carries the most weight and receives the least attention. A vendor that treats the risk assessment as a form to complete rather than an inventory to build produces documentation that collapses under examination.
Documentation that holds up starts from a real inventory of systems and data flows. Building that inventory is the foundation of every healthcare compliance engagement we take on, because every later step inherits whatever the first one got wrong.
Are Business Associate Agreements Mandatory Under HIPAA?
Yes, business associate agreements are mandatory under HIPAA whenever a covered entity discloses PHI to a business associate, and whenever a business associate discloses PHI to a subcontractor. A covered entity may disclose PHI to a business associate only after obtaining satisfactory assurances, in the form of a written contract, that the information will be properly safeguarded.
The written contract has mandatory contents, specified at 45 CFR 164.504(e). A compliant business associate agreement (BAA) must describe the permitted and required uses and disclosures of PHI, provide that the business associate will not use or further disclose PHI beyond what the agreement or law allows, and, where the business associate carries out any of the covered entity's Privacy Rule obligations, provide that it will comply with the Privacy Rule requirements attached to those obligations. The Security Rule adds its own BAA requirements at 45 CFR 164.308(b), including the obligation to report security incidents to the covered entity.
A signed BAA also creates a duty to act on what you learn. Where a covered entity knows of a pattern of activity that constitutes a material breach of the agreement by its business associate, the covered entity must take reasonable steps to cure the breach, and terminate the agreement if those steps fail. The same duty runs from a business associate to its subcontractor. Vendors operating under managed compliance arrangements typically maintain a live register of every BAA they hold in both directions for precisely this reason.
Do Subcontractors Need a Business Associate Agreement?
Yes, subcontractors need a business associate agreement, and the business associate must execute it before disclosing any PHI to that subcontractor. The covered entity is not required to hold an agreement directly with its business associate's subcontractor, which places the responsibility on the business associate in the middle.
Responsibility in the middle produces a continuous chain. Every downstream subcontractor that handles PHI is itself a business associate and must in turn sign agreements with anyone further down. The chain has no natural stopping point, which is what the Omnibus Rule intended when it extended coverage past the first tier of vendors.
Does Signing a BAA Make a Vendor HIPAA Compliant?
No, signing a BAA does not make a vendor HIPAA compliant. The agreement is one requirement among several, and it records a commitment rather than demonstrating that the commitment has been met.
The gap between signing and complying is where most vendors sit. A signed agreement with no risk analysis behind it, no implemented safeguards, and no training records is a document that describes obligations the organization has not performed. Covered entities increasingly ask for evidence rather than signatures, and asking for evidence is the correct instinct.
What Are Business Associates Not Permitted to Do?
Business associates are not permitted to use or disclose PHI in any way the business associate agreement does not allow, and they are not permitted to make a disclosure that the covered entity itself could not lawfully make. The second limit is the broader of the two, because it imports the whole Privacy Rule as a ceiling on vendor behavior.
Specific prohibitions follow from that ceiling. A business associate may not sell PHI without patient authorization. It may not use PHI for marketing communications without authorization. It may not use or disclose PHI beyond the minimum necessary for the task at hand. It may not retain PHI after the agreement ends where the contract requires return or destruction. Two narrow exceptions exist: a business associate may use PHI for its own proper management and administration, and it may provide data aggregation services relating to the covered entity's health care operations, both only where the agreement permits.
Return and destruction obligations are where technology and contract language meet. Backups, archived mailboxes, and retired storage media all hold PHI after an engagement ends, and honoring a destruction clause means accounting for every copy. Sound file encryption practice makes that accounting considerably easier, since encrypted media can often be rendered unreadable by destroying keys rather than hardware.
Who Is Exempt From the HIPAA Security Rule?
Organizations exempt from the HIPAA Security Rule are those that are neither covered entities nor business associates, which means anyone whose work does not involve creating, receiving, maintaining, or transmitting PHI on behalf of a covered entity. Falling outside the definition is what produces the exemption, and HHS identifies several situations where it applies.
A business associate agreement is not required, and Security Rule obligations do not attach, in these cases:
- Disclosures by a covered entity to a health care provider for treatment of the individual, such as a hospital sending a chart to a specialist it referred the patient to
- Disclosures to a health plan sponsor, such as an employer, where the plan documents have been amended appropriately
- Disclosures among covered entities participating in an organized health care arrangement for their joint activities
- Persons whose services do not involve the use or disclosure of PHI, such as a janitorial service or an electrician, provided any access would be incidental and reasonable safeguards are in place
- Financial institutions processing consumer payment transactions, clearing checks, or transferring funds for payment of health care
- Researchers receiving PHI for research purposes under authorization, waiver, or as a limited data set, unless they also provide services to the covered entity involving PHI
Incidental access is the boundary that trips people up. An electrician who happens to walk past a monitor is incidental. A copier technician who services a device storing patient records is not, and HHS lists that technician among its business associate examples. Either way the vendor belongs in the same asset inventory and the same incident response plan as every other party with physical or logical access.
What Is the Conduit Exception Under HIPAA?
The conduit exception under HIPAA applies to entities that transmit PHI without accessing it, such as the U.S. Postal Service, certain private couriers, and their electronic equivalents. A conduit may carry PHI, including temporary storage incidental to transport, without a business associate agreement.
The exception is narrower than vendors claim it to be. It covers only entities that provide transmission services and nothing else. Any organization that accesses PHI on a regular or frequent basis to perform a service is not a conduit, which is why cloud storage providers, hosted email platforms, and backup services all fall inside the business associate definition despite frequently invoking this exception during contract negotiation. Persistent storage of data is what separates a business associate from a conduit.
When Must Business Associates Comply With the HIPAA Security Standards?
Business associates have been required to comply with the HIPAA security standards since September 23, 2013, the compliance deadline set by the Omnibus Rule. Covered entities and business associates received roughly eight months between publication on January 25, 2013 and that deadline to bring their operations into line.
Existing contracts received a longer runway. Agreements already in place on the compliance date could be revised within one year of that deadline, which pushed the final transition to September 22, 2014. Every business associate agreement signed after September 23, 2013 had to reflect the new requirements from the start.
Both dates are long past, and neither leaves any transition period in effect today. A vendor that handles PHI is subject to the Security Rule now, in full, with no phase-in remaining. Practices that discover a vendor operating without documentation usually find the gap during due diligence rather than during an investigation, which is the better of the two ways to find it and the reason HIPAA compliance programs increasingly include vendor review as a standing item.
What Is the New HIPAA Rule in 2026?
The new HIPAA rule in 2026 is a proposed overhaul of the HIPAA Security Rule, and it is still a proposal rather than law. The Office for Civil Rights published the Notice of Proposed Rulemaking in the Federal Register on January 6, 2025, the comment period closed on March 7, 2025, and HHS received more than 4,000 comments in response.
Timing has moved more than once. HHS initially signaled a 2026 final rule, then moved the proposal to its long-term regulatory agenda with a July 2027 target for final action under RIN 0945-AA22. Unified Agenda dates are planning estimates rather than binding deadlines, and the proposal could still be finalized as written, narrowed, delayed further, or withdrawn. HHS estimated first-year compliance costs across regulated entities at approximately $9 billion, which is part of why more than 100 hospital systems and provider associations formally asked the Department to withdraw it.
The proposal carries specific consequences for business associates. It would remove the "addressable" designation that currently lets organizations document a reason for not encrypting ePHI, making encryption at rest and in transit mandatory. It would require multi-factor authentication for systems accessing ePHI, asset inventories, annual penetration testing, and shorter restoration timelines after an incident. It would also tighten business associate oversight, requiring vendors to verify their safeguards to covered entities on a set schedule. None of this is in force, and the Security Rule as it stands today remains the operative standard, a point OCR states directly on its own rulemaking page.
Preparation still makes sense on its own terms. Encryption, multi-factor authentication, a current asset inventory, and tested restoration are reasonable security in 2026 regardless of which direction the rulemaking goes, and each one already maps to an existing Security Rule standard. Vendors building toward advanced security now will find the eventual compliance date far less disruptive than those waiting for certainty that may not arrive until 2027.
Why Business Associate Compliance Matters More Now Than It Did in 2013
Business associate compliance matters more now than it did in 2013 because the breach data shows that vendors, not providers, hold most of the exposed records. More than 375 million individuals were affected by healthcare data breaches in 2025, and business associates accounted for 77 percent of all breached records. The Change Healthcare incident alone compromised 192.7 million records.
Concentration is the reason the numbers skew that way. Analysis of the OCR breach portal shows business associates involved in roughly 22 percent of recent incidents but 33 percent of individuals affected, meaning the average vendor breach reaches about twice as many people as the average provider breach. One vendor serving two hundred practices holds two hundred practices' worth of records behind a single set of credentials. That concentration is what the Omnibus Rule anticipated when it extended liability past the covered entity.
Enforcement has followed the data. The Office for Civil Rights has logged 374,322 complaints since 2003 and 7,419 reported healthcare data breaches since 2009, and its recent enforcement docket falls disproportionately on small and mid-sized practices, business associates, behavioral health providers, and dental practices. Penalties run on a four-tier civil money penalty structure based on culpability, with amounts adjusted for inflation each year and the current figures effective January 28, 2026. The top tier, willful neglect left uncorrected, carries an annual cap above $2 million.
Penalties are rarely the first cost a vendor feels. The practical cost of non-compliance arrives earlier, in lost contracts and failed vendor reviews, and it lands hardest on the small practices and small vendors across Huntsville and North Alabama that have no dedicated internal IT department absorbing the work.
Covered entities have noticed. Vendor questionnaires now routinely ask for a risk analysis date, a policy set, and training records rather than a signature on a BAA, and a vendor without those documents loses the engagement. Building the risk analysis support and evidence trail in advance turns a compliance obligation into a competitive position.
Frequently Asked Questions
Is a Cloud Service Provider a Business Associate Even If the PHI Is Encrypted?
Yes, a cloud service provider is a business associate even if the PHI is encrypted and the provider holds no decryption key. HHS addressed this directly in its cloud computing guidance: a provider that maintains ePHI on behalf of a covered entity or business associate meets the definition regardless of whether it can read the data. Encryption reduces risk without removing the provider from the regulation.
Can a Covered Entity Be a Business Associate of Another Covered Entity?
Yes, a covered entity can be a business associate of another covered entity. This arises when one organization performs a regulated function for another, such as a hospital handling billing or IT services for an independent practice. The organization then carries both sets of obligations at once, with separate documentation for each role.
What Happens If a Business Associate Has a Breach?
If a business associate has a breach, it must report the breach of unsecured PHI to the covered entity, which then notifies affected individuals and HHS. Notification to individuals is due within 60 days of discovery. Breaches affecting 500 or more individuals require notice to HHS and to prominent local media outlets, while smaller breaches are logged and reported to HHS annually.
How Long Must a Business Associate Keep HIPAA Documentation?
A business associate must keep HIPAA documentation for six years from the date it was created or the date it was last in effect, whichever is later. The requirement covers policies and procedures, risk analyses, training records, security incident logs, and business associate agreements. Documentation that cannot be produced is treated the same as documentation that was never created.
Who Enforces HIPAA Against Business Associates?
The HHS Office for Civil Rights enforces HIPAA against business associates through investigations, corrective action plans, and civil money penalties. State attorneys general can also bring actions for HIPAA violations, and the Department of Justice handles criminal referrals involving knowing misuse of PHI. A business associate faces the same enforcement machinery as the covered entity that hired it.
What Changed About Breach Notification Under the Omnibus Rule?
Under the Omnibus Rule, breach notification changed from a subjective harm standard to a presumption of breach. Before 2013, an incident counted as a breach only where it posed a significant risk of financial or reputational harm. Now any impermissible use or disclosure of PHI is presumed to be a breach unless the organization demonstrates a low probability of compromise through a four-factor assessment covering the nature of the PHI, who received it, whether it was actually acquired or viewed, and how far the risk was mitigated.
The Bottom Line
The HIPAA Omnibus Final Rule of January 25, 2013 is the rule that expanded HIPAA compliance to include business associates, implementing direct liability that the HITECH Act of 2009 had established in statute. It widened the definition to anyone creating, receiving, maintaining, or transmitting PHI on a covered entity's behalf, extended that definition down through subcontractors, and made the Security Rule apply to vendors in full. Compliance has been required since September 23, 2013, with no transition period remaining.
What that means in practice is straightforward. A vendor handling PHI owes a documented risk analysis, implemented safeguards, written policies, trained staff, signed agreements in both directions, a working breach reporting path, and six years of retained records. The proposed Security Rule overhaul may tighten several of those obligations, but it changes none of them today, and the organizations preparing now will absorb it far more comfortably than the ones waiting.
We have spent over 20 years helping organizations across Huntsville and North Alabama weave technology into a compliant infrastructure, and we sign business associate agreements ourselves, so this rule governs our work as much as our clients'. If you would like a clear view of where your practice or your vendor chain stands, the team at Interweave Technologies is glad to walk through it with you. You can reach us at (256) 837-2300.
.webp)
.webp)



.webp)





Share Post