HIPAA

HIPAA Covered Entity vs Business Associate: How to Scope Your Compliance Program in 2025

Priya Nair July 14, 2026 8 min read
Diagram illustrating the difference between a HIPAA covered entity vs business associate with compliance program scope
Understanding HIPAA covered entity vs business associate roles is the foundation of any compliant healthcare data program.

Getting your HIPAA compliance scope wrong is one of the most expensive mistakes a healthcare-adjacent organization can make — and it happens far more often than regulators like to admit. Understanding the distinction between a HIPAA covered entity vs business associate is the foundational step that determines which safeguards you must implement, which agreements you must sign, and ultimately, how much liability you carry. Whether you are a startup building a health app or an established billing company serving hospital networks, this guide will help you scope your program accurately in 2025.

Why HIPAA Scoping Matters More Than Ever in 2025

The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services has significantly increased its enforcement activity over the past two years. In 2024 alone, OCR settled multiple cases involving business associates that had failed to implement even basic Security Rule safeguards — not because they were negligent, but because they genuinely did not realize they qualified as business associates under HIPAA. The penalties ranged from $100,000 to over $1.9 million per incident.

Meanwhile, the proliferation of cloud-based health tools, AI-driven diagnostics, and third-party revenue cycle management platforms has blurred the lines between who handles Protected Health Information (PHI) and who does not. In 2025, if your software touches, stores, transmits, or analyzes PHI on behalf of a healthcare organization, you almost certainly have HIPAA obligations — even if your contract does not explicitly say so.

Scoping your compliance program correctly from the start saves you from retrofitting controls later, avoids breach notification nightmares, and builds the trust that healthcare clients increasingly demand before signing contracts.

What Is a HIPAA Covered Entity? The 2025 Definition

Under HHS guidance on covered entities, a covered entity is any organization that falls into one of three categories:

  • Health Plans: Health insurance companies, HMOs, employer-sponsored health plans, Medicare, Medicaid, and similar programs that pay for healthcare.
  • Healthcare Clearinghouses: Entities that process nonstandard health information into standard formats (or vice versa), such as billing services that reformat claims data.
  • Healthcare Providers: Any provider that transmits health information electronically in connection with a HIPAA-covered transaction — this includes hospitals, physician practices, dentists, pharmacies, and even some telehealth platforms.

A critical nuance: a healthcare provider only becomes a covered entity if it conducts covered transactions electronically. A solo therapist who accepts only cash and never submits electronic claims is technically not a covered entity — though most compliance professionals recommend treating PHI with HIPAA-level care regardless, given state law requirements and evolving OCR interpretations.

Common Covered Entity Mistakes

  • Assuming that being a small practice exempts you from HIPAA (it does not — size affects certain administrative requirements, not the core rules).
  • Failing to recognize that a health plan subsidiary of a large employer is a covered entity even if the parent company is not.
  • Overlooking that telehealth platforms that bill insurance electronically are covered entities, not merely business associates.

What Is a HIPAA Business Associate? Scoping the Modern Definition

A business associate is any person or organization — other than a member of a covered entity's workforce — that creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a function or activity regulated by HIPAA. The Omnibus Rule of 2013 extended direct liability to business associates, meaning OCR can now audit and fine them independently, without going through the covered entity first.

In 2025, the business associate category is broader than most organizations expect. Here is a practical breakdown:

Organization Type Likely Classification Key Trigger
Cloud storage provider hosting EHR data Business Associate Maintains PHI on behalf of a covered entity
Medical billing company Business Associate Processes PHI to perform billing functions
Healthcare IT consultant with system access Business Associate Accesses PHI during system maintenance
AI diagnostic tool vendor Business Associate Analyzes PHI to generate clinical insights
Shredding company destroying paper records Business Associate Receives PHI for destruction services
General janitorial service Not a Business Associate No routine access to PHI
Internet service provider (conduit only) Not a Business Associate Transmits but does not access PHI content

Subcontractors: The Often-Missed Layer

One of the most overlooked aspects of HIPAA scoping is the subcontractor rule. If your organization is a business associate and you engage a third party that will access PHI to perform services for you, that third party becomes a business associate of a business associate — and must also sign a Business Associate Agreement (BAA) and comply with the HIPAA Security Rule. This chain of accountability means that a cloud infrastructure provider like AWS or Azure, when used by a healthcare SaaS company, must sign a BAA — and they do offer them, but you must actively request and execute one.

Business Associate Agreements: What Must Be in Your BAA in 2025

A Business Associate Agreement is not just a checkbox — it is a legally binding contract that defines the permissible uses of PHI, establishes security obligations, and allocates breach liability. According to OCR's official BAA guidance, every BAA must include provisions that:

  1. Describe the permitted and required uses of PHI by the business associate.
  2. Prohibit the business associate from using or disclosing PHI in ways not permitted by the Privacy Rule.
  3. Require the business associate to implement appropriate safeguards (administrative, physical, and technical).
  4. Require reporting of breaches and security incidents to the covered entity.
  5. Ensure subcontractors are bound by the same restrictions through their own BAAs.
  6. Allow the covered entity to terminate the contract if the business associate violates a material term.
  7. Require return or destruction of PHI upon contract termination.

In 2025, OCR has signaled increased scrutiny of BAAs that are overly vague about incident reporting timelines. Best practice is to specify that security incidents must be reported within 72 hours of discovery — aligning with GDPR's breach notification standard and making your compliance posture internationally coherent.

How to Conduct a HIPAA Scoping Analysis for Your Organization

Before you can build a compliant program, you need to answer four foundational questions:

Step 1: Map Your PHI Flows

Document every system, process, and vendor that touches PHI. This includes data at rest (databases, backups), data in transit (APIs, email, file transfers), and data in use (analytics platforms, AI models). Many organizations are surprised to discover PHI flowing through tools they considered purely operational — like customer support ticketing systems or internal Slack channels.

Step 2: Classify Each Entity in Your Ecosystem

For each vendor or partner in your PHI flow map, determine whether they are a covered entity, a business associate, or neither. Use the table above as a starting framework, but consult the specific facts of each relationship. The key question is always: Does this party create, receive, maintain, or transmit PHI on our behalf?

Step 3: Audit Your BAA Inventory

Cross-reference your PHI flow map against your executed BAAs. Any gap — a vendor with PHI access and no signed BAA — is an active compliance violation. Prioritize closing these gaps immediately, as OCR treats missing BAAs as a per-violation penalty trigger.

Step 4: Determine Your Rule Applicability

Covered entities must comply with the Privacy Rule, Security Rule, and Breach Notification Rule. Business associates are directly subject to the Security Rule and Breach Notification Rule, and contractually bound to Privacy Rule requirements through their BAA. Subcontractors carry the same obligations as business associates. Mapping your classification to your rule obligations tells you exactly which policies, procedures, and technical controls you need to build.

HIPAA Covered Entity vs Business Associate: Compliance Obligations Compared

Obligation Covered Entity Business Associate
Privacy Rule compliance Direct obligation Contractual (via BAA)
Security Rule compliance Direct obligation Direct obligation
Breach Notification Rule Direct obligation Direct obligation
Notice of Privacy Practices Required Not required
Patient rights management Required Must support covered entity
Risk Analysis Required Required
BAA execution with subcontractors Required Required
OCR audit exposure Yes Yes (since 2013 Omnibus Rule)

How ComplyGuard Simplifies HIPAA Scoping and Program Management

Manually mapping PHI flows, auditing BAA inventories, and building Security Rule controls from scratch is a months-long project that typically requires expensive outside counsel and compliance consultants. ComplyGuard's AI-powered compliance platform automates the most time-consuming parts of this process — from generating your initial risk analysis to tracking BAA execution status across your entire vendor ecosystem.

Our platform includes pre-built HIPAA policy templates aligned to the 2025 enforcement environment, automated evidence collection for Security Rule controls, and real-time gap analysis that tells you exactly where your program falls short relative to OCR's audit protocols. Whether you are a covered entity building your first compliance program or a business associate preparing for a client security review, see how ComplyGuard compares to traditional compliance approaches in terms of speed, cost, and audit readiness.

The NIST Cybersecurity Framework, which NIST continues to update and which OCR explicitly references in its audit protocols, forms the backbone of ComplyGuard's control mapping — ensuring that your HIPAA program also strengthens your broader security posture.

Conclusion

Correctly identifying whether your organization is a HIPAA covered entity vs business associate — and understanding the compliance obligations that flow from that classification — is not a one-time exercise. As your product evolves, as you onboard new vendors, and as OCR updates its enforcement priorities, your scope must be revisited. The organizations that get penalized are rarely those that knowingly ignored HIPAA; they are the ones that scoped their program incorrectly at the start and never caught up. Build your compliance foundation on accurate scoping, airtight BAAs, and a continuous monitoring posture — and you will be positioned to win healthcare clients, pass audits, and scale with confidence in 2025 and beyond.

Ready to scope your HIPAA program the right way without spending months or six figures on consultants? Talk to a ComplyGuard compliance specialist today or explore our pricing plans to see how quickly you can achieve audit-ready HIPAA compliance with AI-powered automation.

#hipaa#compliance#phi#business associate agreement#covered entity

Frequently Asked Questions

Ready to automate your compliance?

Achieve SOC 2, HIPAA, ISO 27001, GDPR & PCI-DSS compliance 10x faster with ComplyGuard's AI-powered platform.

Related Articles