Scope
Who it applies to.
HIPAA reaches two groups, both defined at 45 CFR § 160.103. A covered entity is one of three things: a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a covered transaction. A business associate is a person who, on a covered entity’s behalf and other than as a member of its workforce, creates, receives, maintains, or transmits protected health information — or provides legal, accounting, consulting, or management services involving PHI. Subcontractors of business associates are themselves business associates.
- Business associate agreements
- Before an outside party may create, receive, maintain, or transmit PHI for you, you must obtain satisfactory assurances that it will safeguard the information, documented in a written contract (45 CFR §§ 164.502(e) and 164.504(e); the Security Rule counterpart is § 164.308(b)). A business associate must in turn obtain the same assurances from its own subcontractors, so the chain extends past your direct vendor.
- The three safeguard categories
- The Security Rule requires administrative (§ 164.308), physical (§ 164.310), and technical (§ 164.312) safeguards for electronic PHI, measured against the general rules at § 164.306: ensure confidentiality, integrity, and availability, and protect against reasonably anticipated threats. Implementation specifications are marked Required or Addressable. Addressable does not mean optional — you must implement it, or document why it is not reasonable and appropriate and adopt an equivalent alternative.
- Risk analysis
- Section 164.308(a)(1)(ii)(A) requires an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of electronic PHI you hold. It is a Required specification, not addressable, and it feeds the risk-management specification that follows it. Every system that stores or indexes PHI — including a search or AI tool — belongs in that assessment’s scope.
- Minimum necessary
- When using, disclosing, or requesting PHI, you must make reasonable efforts to limit it to the minimum necessary to accomplish the intended purpose (§ 164.502(b)). The implementation specifications at § 164.514(d) require you to identify which workforce members or classes need access to what PHI, and limit their access accordingly. Treatment disclosures to providers and several other categories are excepted.
- Breach notification
- Subpart D of Part 164 presumes that an impermissible acquisition, access, use, or disclosure of unsecured PHI is a breach unless you demonstrate a low probability of compromise (§ 164.402). Notify affected individuals no later than 60 calendar days after discovery (§ 164.404(b)), notify the Secretary (§ 164.408), and notify prominent media outlets when a breach affects more than 500 residents of a State or jurisdiction (§ 164.406).
The vendor & sub-processor obligation
What it puts on you.
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate and must sign a Business Associate Agreement — and their subcontractors must too. Cloud and AI providers in the data path each pull you into another BAA to negotiate and stand behind.
[A covered entity] may allow a business associate to create, receive, maintain, or transmit protected health information on its behalf, if the covered entity obtains satisfactory assurance… that the business associate will appropriately safeguard the information.
How self-hosting addresses it
Remove the third party, remove the burden.
If PHI never leaves your network, no outside party becomes a business associate for that data, so there is no BAA — or downstream subcontractor — to execute, track, or be breached on your behalf.
How FileFerret applies
FileFerret indexes and answers questions entirely inside your network, so in normal operation no outside party creates, receives, maintains, or transmits PHI on your behalf — no BAA, no subcontractor chain. Note that support access you invite is still access: if a support engineer can view PHI, that relationship needs a BAA. Your own Security Rule safeguards, risk analysis, and minimum-necessary duties apply unchanged. See how it’s built →
Full, current text is maintained at the official source: 45 CFR Parts 160 & 164 — U.S. HHS.
Enforcement
Who enforces it, and how.
HHS’s Office for Civil Rights investigates complaints (§ 160.306) and runs compliance reviews, and may first seek resolution by informal means such as a corrective action plan (§ 160.312). Civil money penalties follow four culpability tiers: no knowledge; reasonable cause; willful neglect corrected within 30 days; and willful neglect not corrected (§ 160.404(b)(2)). The dollar amounts are inflation-adjusted annually and published at 45 CFR Part 102 — check there, not the figures printed in § 160.404. Knowing wrongful disclosure is separately criminal under 42 U.S.C. 1320d-6.
Common questions
Questions firms ask.
Is a cloud storage or backup provider a business associate if it never reads our files?
Very likely yes. The definition at § 160.103 turns on whether the vendor creates, receives, maintains, or transmits PHI on your behalf, and “maintains” covers storage whether or not anyone reads it. The definition also expressly names data-transmission services that require access to PHI on a routine basis. Encryption and a no-access policy do not by themselves put a storage vendor outside the definition.
If the data was encrypted, do we still have to send breach notices?
Possibly not. Subpart D is triggered only by a breach of unsecured PHI, defined at § 164.402 as PHI not rendered unusable, unreadable, or indecipherable through a technology or methodology the Secretary specifies in guidance. Encryption counts only if it matches that guidance and the keys were not also compromised. Check the current HHS guidance before concluding no notice is required.
Do we need a BAA for a tool our own IT staff runs in-house?
No. The § 160.103 definition of business associate expressly excludes persons acting as members of your workforce, so your own employees running your own systems are not business associates and no agreement is required. The obligation attaches to outside parties. Your Security Rule duties over that system are unchanged — internally operated does not mean out of scope.