A medical practice I consulted for once handed a box of patient records to a local shredding company. No contract. No Business Associate Agreement. No questions asked. Six months later, a jogger found intact patient files in a dumpster behind a strip mall. That shredding company was a business associate — and nobody had treated it like one.

If you've ever wondered what counts as an example of business associate under HIPAA, you're asking the right question. Getting this wrong doesn't just create legal exposure — it creates the kind of breach that ends up on the HHS Wall of Shame. Let me walk you through the real-world scenarios, the enforcement actions, and the steps your organization needs to take.

What Exactly Is a Business Associate?

A business associate is any person or organization — other than a member of a covered entity's workforce — that performs functions or activities on behalf of a covered entity involving the use or disclosure of protected health information (PHI). That's the definition straight from HHS. But definitions don't stick. Examples do.

The key phrase is on behalf of. If a company touches, stores, transmits, or could reasonably access PHI while doing work for a healthcare provider, health plan, or clearinghouse, that company is almost certainly a business associate. And the covered entity is legally obligated to execute a Business Associate Agreement (BAA) before any PHI changes hands.

HHS maintains a detailed FAQ on business associate requirements on its official guidance page. If you haven't reviewed it recently, now is the time.

Seven Real-World Examples of Business Associates

Here's where things get concrete. These are the scenarios I encounter most often in my consulting work — and the ones that trip organizations up the most.

1. IT Service Providers and Cloud Hosting Companies

If your IT vendor manages servers that store electronic protected health information (ePHI), they're a business associate. Period. This includes cloud hosting platforms, managed service providers, and even the company that handles your email if it contains patient data. I've seen small practices assume their "tech guy" doesn't count. He does.

2. Medical Billing Companies

This is the most textbook example of business associate you'll find. A third-party billing company processes claims on behalf of a physician's office. They handle diagnosis codes, patient names, insurance IDs — all PHI. A BAA is non-negotiable.

3. Document Shredding and Destruction Services

Remember my dumpster story? A shredding company that picks up bins of paper records containing PHI is a business associate. They may never look at the records, but they have access. Access triggers the requirement.

4. Answering Services

Medical answering services that take after-hours calls often collect patient names, callback numbers, and reason-for-call details. That's PHI. I've worked with clinics that had been using the same answering service for a decade without a BAA in place.

5. EHR Software Vendors

Your electronic health record vendor stores, processes, and transmits ePHI. They are a business associate. Most reputable EHR companies will proactively offer a BAA, but I've reviewed contracts where the BAA language was buried in an addendum nobody signed.

6. Attorneys and Accountants

An attorney who provides legal services to a hospital and, in doing so, accesses patient records is a business associate. Same goes for an accounting firm that handles billing audits involving PHI. The nature of the professional relationship doesn't create an exemption.

7. Community Health Workers and Outreach Organizations

This one catches people off guard. When a covered entity contracts with a community health organization to conduct outreach, care coordination, or patient follow-up, that organization may handle PHI. Every individual involved needs proper training. Our HIPAA training for community health workers was built specifically for this scenario — because these partnerships are growing fast, and compliance hasn't kept up.

The $4.3 Million Mistake: When BAAs Don't Exist

In 2016, the HHS Office for Civil Rights (OCR) settled with Advocate Health Care Network for $5.55 million — at the time one of the largest HIPAA settlements ever. Among the findings: Advocate failed to obtain a BAA from a business associate that handled ePHI. That single oversight was part of a cascade of violations.

More recently, in 2018, OCR settled with Advanced Care Hospitalists (ACH) for $500,000 after a billing company working for ACH uploaded PHI of over 9,000 patients to a public website. ACH had no BAA in place with the billing vendor. The case is documented on the OCR enforcement page.

These aren't hypotheticals. These are organizations that thought their vendor relationships were fine — right up until OCR came knocking.

How Do You Know If Someone Is a Business Associate?

This is the question I get asked most. Here's a quick test I use with my clients:

  • Does the person or company perform a service for your organization? (Billing, IT, legal, consulting, data analysis, etc.)
  • Does that service involve creating, receiving, maintaining, or transmitting PHI?
  • Is that person or company outside your direct workforce?

If the answer to all three is yes, you're looking at a business associate. Get a BAA signed before work begins.

One important distinction: a covered entity's own employees are part of its workforce, not business associates. But a staffing agency that supplies temporary nurses? Business associate. The line matters.

What About Subcontractors?

Under the HIPAA Omnibus Rule of 2013, subcontractors of business associates are also business associates if they handle PHI. So if your billing company outsources data entry to a firm overseas, that firm needs a BAA with the billing company. Your organization should verify this chain exists. In my experience, it rarely does without prompting.

What a Business Associate Agreement Must Include

A BAA isn't a handshake. It's a legally required contract with specific provisions mandated by the HIPAA Privacy Rule and Security Rule. At minimum, a BAA must:

  • Describe the permitted uses and disclosures of PHI
  • Require the business associate to implement appropriate safeguards
  • Require reporting of breaches or unauthorized disclosures
  • Ensure the business associate's subcontractors agree to the same restrictions
  • Authorize termination if the business associate violates the agreement

Template language is available in the HHS sample BAA provisions, and I strongly recommend using it as your starting point.

The Training Gap Most Organizations Miss

Here's what keeps me up at night: organizations sign BAAs and then assume compliance is handled. But a BAA is a legal document, not a training program. Your business associates' workforce still needs to understand how to handle PHI. They need to know what constitutes a breach. They need to know what the breach notification requirements look like.

I've audited business associates whose employees couldn't tell me the difference between PHI and directory information. That's a ticking clock.

If your organization works with external partners — especially community-based organizations, outreach teams, or contracted clinical staff — workforce training is where compliance either holds or falls apart. Browse our full HIPAA training catalog to find courses tailored to different roles within the business associate relationship.

Stop Guessing, Start Mapping

Every covered entity should maintain an up-to-date inventory of its business associates. I call it a BA Map. It should include:

  • The vendor or partner name
  • The type of PHI they access
  • The date the BAA was executed
  • The date it was last reviewed
  • The subcontractor chain, if applicable

I've walked into organizations with over forty business associate relationships and zero documentation. That's not unusual — it's the norm. And that norm is what OCR enforcement actions are made of.

If you take one action after reading this, make it this: pull your vendor list tomorrow and ask one question about each entry — do they touch PHI? If the answer is yes and you don't have a signed BAA, you have a compliance gap that needs to close today.

Not next quarter. Today.