Does a Cloud Provider Need a HIPAA BAA If It Cannot Decrypt the ePHI?
Yes. A cloud provider can be a HIPAA business associate even when it stores only encrypted ePHI and never receives the decryption key. HHS bases the role on what the provider receives or maintains for a covered entity or another business associate. The ability to read the information is not the deciding test.
HHS calls this a “no-view” service. The label describes access to the key, not an exemption from HIPAA. The provider and customer still need a Business Associate Agreement, a documented allocation of applicable Security Rule work, and an incident process that distinguishes business-associate status from the narrower breach safe harbor.
What does “no-view” mean in the HHS cloud guidance?
HHS uses “no-view services” for a cloud service provider that maintains encrypted ePHI for a covered entity or business associate without access to the decryption key. The term describes a technical arrangement. It does not create a new category outside the Business Associate provisions.
The provider still receives and maintains ePHI on another regulated party’s behalf. HHS therefore treats the provider as a business associate even if its staff cannot view the plaintext. This role test is different from asking whether encryption was correctly configured or whether an incident exposed readable information.
Why does encryption not remove business-associate status?
Encryption protects confidentiality by making information harder to read without the key. HHS explains that this protection does not by itself preserve integrity or availability. Ciphertext can still be corrupted, deleted, held unavailable, or affected by compromised administrative systems.
That distinction explains why the legal role remains. A storage provider can affect whether the customer retrieves data during an emergency, whether backups remain available, and whether administrative tooling changes or removes resources. The provider may never see the plaintext and still perform a service that maintains ePHI.
Do not turn this into the opposite overstatement. No-view status does not mean every safeguard must be implemented twice in the same way. HHS describes the rules as flexible and scalable for the arrangement. It also says the parties can allocate certain controls according to their risk management plans and BAA.
The practical boundary is narrow: encryption without provider-held keys changes the risk and the division of work. It does not make the data cease to be ePHI, remove the provider’s role, or make the service compliant by itself. The encryption verification checklist covers key custody and technical evidence without treating encryption as a complete program.
How can the customer and cloud provider allocate Security Rule work?
HHS gives an example in which the customer controls who can view ePHI and implements user authentication, while the cloud provider handles encryption. The exact split depends on the parties’ security risk management plans and the BAA. A generic shared-responsibility diagram is not enough.
The provider remains responsible for controls that apply to its own systems. HHS specifically points to administrative tools that manage storage, memory, network interfaces, and processors. Unauthorized access to those tools can affect confidentiality, integrity, or availability even when the attacker never obtains a decryption key.
The customer also remains accountable for work assigned to it. If the contract says the customer will configure a security feature and the customer does not do so, HHS says that fact can matter in an investigation. Allocation must therefore connect each requirement to an owner, configuration, test, and escalation path.
What does the BAA need to settle for a no-view service?
HHS says a no-view provider is not exempt from otherwise applicable HIPAA requirements. Its BAA must govern permitted uses and disclosures and explain how the provider will support obligations that depend on the maintained ePHI. The agreement should reflect the actual service rather than copy an access model the provider cannot perform.
For example, the provider may make encrypted ePHI available to the customer so the customer can handle access or amendment work. That differs from promising that provider staff will open and edit records. The BAA should also address availability, return or termination, incident notice, subcontractors, and the controls each party operates.
Does encryption create an automatic HIPAA breach safe harbor?
No. Business-associate status and breach reporting are separate questions. HHS says a no-view provider remains a business associate and must follow applicable breach-notification duties. A particular incident can fall within the safe harbor only when the affected ePHI meets the encryption standards identified by HHS.
If the information was encrypted at a level that satisfies those standards, HHS says the incident can fall within the safe harbor and the provider need not report that incident to its customer as a breach. That conclusion is incident-specific. It does not cancel the BAA or the provider’s continuing Security Rule obligations.
HHS also names two important limits. If encryption does not meet the required level, or if the decryption key was compromised with the data, the incident must be reported to the customer as a breach unless an exception to the regulatory definition applies. “The files were encrypted” is therefore an incomplete incident finding.
What evidence should be collected before approving the service?
- Confirm that the provider receives or maintains ePHI on behalf of a covered entity or business associate.
- Record whether the provider can obtain a key through support, recovery, escrow, or another administrative path.
- Map authentication, encryption, integrity, availability, contingency, and incident responsibilities.
- Test access and recovery with synthetic records rather than patient information.
- Verify how the provider makes encrypted information available for customer-led HIPAA workflows.
- Review the BAA against the live configuration and named subcontractors.
- Repeat the review when keys, products, regions, support, or recovery procedures change.
Which claims should a healthcare team reject?
- “The provider cannot read the files, so it is not a business associate.”
- “The customer holds the key, so the provider has no Security Rule duties.”
- “Encryption proves integrity and availability.”
- “Every encrypted-data incident is exempt from breach reporting.”
- “The cloud contract alone proves the application complies with HIPAA.”
Each claim collapses separate tests. Role follows the service performed. Safeguards follow the real division of systems and responsibilities. Safe harbor follows the incident facts and the applicable encryption standard. Compliance depends on the regulated organization’s full program and actual operation.
Frequently asked questions
Is a cloud provider a business associate if it stores only ciphertext?
Yes, when it receives and maintains encrypted ePHI on behalf of a covered entity or another business associate. HHS says lack of a decryption key does not remove business-associate status.
Can the customer handle authentication while the provider handles encryption?
It can, depending on the service, risk management plans, and BAA. HHS allows a fact-specific allocation, while the provider remains responsible for applicable controls over its own administrative systems.
Does a BAA require provider staff to view the ePHI?
No. A no-view BAA can describe how the provider makes encrypted data available so the customer performs workflows that require access. The agreement should match technical capability and assigned duties.
Does customer-managed encryption guarantee breach safe harbor?
No. HHS ties safe harbor to qualifying encryption and the incident facts. If the encryption level is insufficient or the key was also compromised, notification duties may apply unless a regulatory exception fits.
References
- U.S. Department of Health and Human Services, “If a CSP stores only encrypted ePHI and does not have a decryption key, is it a HIPAA business associate?”, retrieved August 16, 2026, https://www.hhs.gov/hipaa/for-professionals/faq/2076/if-a-csp-stores-only-encrypted-ephi-and-does-not-have-a-decryption-key-is-it-a-hipaa-business-associate/index.html
Related articles
Does CloudWatch Logs Data Protection Permanently Redact PHI Already Stored?
No. An Amazon CloudWatch Logs data protection policy does not permanently redact PHI that was already stored before the policy took effect.…
Why Does Google Calendar events.list Return an Appointment That Starts Before timeMin?
Google Calendar can return an event that starts before timeMin because events.list uses overlap boundaries. The API defines timeMin as an…
Why Did NexHealth Book the Correct Slot with the Wrong EHR Procedure Code?
NexHealth can return the intended time and still write an appointment with the wrong EHR appointment type or procedure code. The two…