Skip to main content

Business Associate

« Back to Glossary Index

A person or organization, other than a member of a HIPAA covered entity’s workforce, that performs certain functions or activities on behalf of, or provides certain services to, a covered entity that involve the use or disclosure of Protected Health Information (PHI). Business associate functions or activities on behalf of a covered entity include claims processing, data analysis, utilization review, and billing. Business associate services to a covered entity are limited to legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services. However, persons or organizations are not considered business associates if their functions or services do not involve the use or disclosure of PHI, and where any access to PHI by such persons would be incidental, if at all. A covered entity can be the business associate of another covered entity. HIPAA: Summary of the HIPAA Privacy Rule


« Back to Glossary Index