Covered Entity, Business Associate, or Subcontractor: A Guide
Short answer: Covered entity, business associate, and subcontractor are role descriptions tied to facts, functions, and data flows. Use a role-mapping worksheet before a vendor receives protected health information, but do not decide a tenant’s legal status from its title, cash-pay label, product category, or BAA alone. As of August 15, 2026, have qualified counsel review the current transaction and contract chain.
Legal question and current rule
The role map starts with the current definitions and the organisation’s actual behavior. A covered entity can include a health plan, clearinghouse, or qualifying health care provider. A business associate performs a function or service for a covered entity that involves protected health information. A subcontractor business associate sits downstream from a business associate and handles the information for that downstream service. The exact outcome depends on facts.
Use the current eCFR definitions and organizational requirements retrieved August 15, 2026. The role may change when a clinic adds an electronic payer transaction, a vendor begins storing records, a support team gains access, or a new subprocessor is introduced. A BAA can be necessary without being evidence that every role question was answered.
Do not collapse role mapping into a statement that one party “owns the data.” Ownership language may matter contractually, but the HIPAA analysis asks who performs which function, on whose behalf, with what access and disclosure. Map those facts separately.
Use a role-mapping worksheet
| Worksheet field | Question | Evidence |
|---|---|---|
| Entity | What legal organisation is acting? | Contract party, business registration, service owner. |
| Function | What service is performed and who directs it? | Statement of work, workflow, product feature. |
| Data | Which fields and records are received or created? | Schema, payload, logs, exports, backups. |
| Recipient | Who can access or receive the result? | Roles, support, subprocessor, region map. |
| Agreement | Which BAA or related term governs the path? | Effective agreement, scope, notice, exit clause. |
Fill one row per service, not one row per brand. A vendor can provide a scheduling service, support service, analytics service, and storage service with different data paths. A provider’s general BAA may cover only named services or features. Keep exclusions visible.
Use synthetic records to validate the map. Trace a booking from intake through authorization, storage, notification, support, backup, and deletion. If an event goes to a queue or log, include it. If an outbound conversion is proposed, record the destination and approval gate. Never send patient names, email addresses, phone numbers, hashed identifiers, service or treatment details, or clinical text to an advertising platform.
Roles, duties, and evidence
A covered entity needs a current role analysis and appropriate agreements with business associates. A business associate needs safeguards, permitted-use controls, incident procedures, cooperation, and the required downstream contract path. A subcontractor business associate needs obligations that match the function it performs. HHS sample provisions can help review the terms, but they are not a universal template that covers every service.
Separate four evidence sets:
- Legal evidence: definitions, transaction facts, role memo, counsel decision.
- Contract evidence: BAA, scope, effective date, permitted uses, breach clock, return or destruction.
- Technical evidence: access controls, tenant checks, encryption, logs, backups, regions, tests.
- Operational evidence: training, support approvals, incident exercise, vendor review, change record.
Use the related covered-entity test, business-associate guide, and cloud BAA checklist to deepen each evidence set.
Documentation and escalation boundary
Escalate when a party’s role is disputed, when a data path has an unnamed recipient, when the contract excludes the deployed feature, or when support or backup access is outside the reviewed region. Escalate marketing uses separately. An operational need does not automatically authorize a disclosure to an advertising destination.
| Risk | Control | Proof |
|---|---|---|
| Wrong role assumed | Fact-based role memo with counsel owner | Signed decision and review date. |
| Downstream vendor omitted | Subprocessor and service inventory | Agreement, region, purpose, change notice. |
| Scope mismatch | Feature-to-contract matrix | Current vendor documentation and configuration. |
| Excessive disclosure | Minimum necessary field and recipient review | Payload test, export test, approval record. |
Do not publish a compliance or certification claim because a provider signed a BAA. The application may still have an authorization failure, unreviewed support access, unencrypted export, or untested restore. A narrow claim about a defined contract and control scope is more accurate.
Reader decision checklist
- List each entity and service.
- Map function, purpose, fields, recipient, region, and agreement.
- Classify roles with current legal sources and qualified counsel.
- Verify technical and operational safeguards.
- Review minimum necessary, logs, backups, support, and deletion.
- Document vendor and subprocessor changes.
- Keep outbound conversion paths generic, off by default, and tenant-approval gated.
The stop condition is an incomplete arrow in the map. Do not permit protected-data access until every recipient, agreement, and owner is visible.
Map one customer through one complete workflow
A role worksheet is easier to review when it follows one synthetic record. Start with the customer legal entity and its purpose. Add the booking form, API, database, notification worker, support tool, backup, log destination, and any downstream provider. For every arrow, name the function, fields, recipient, region, agreement, and owner. Then repeat for a second workflow that uses a different feature, such as an export or report.
This method exposes hidden roles. A vendor can be a business associate for storage, a different service can be a subcontractor for support, and a reporting destination can be an unaffiliated recipient. The same corporate group may operate separate legal entities. Keep legal party names and service names distinct from product brand names.
Use role evidence to set product boundaries
| Role question | Product boundary | Approval evidence |
|---|---|---|
| Who directs the function? | Limit API and worker behavior to the approved purpose. | Service description and customer approval. |
| Who receives data? | Reject unlisted destinations and fields. | Data-flow and recipient register. |
| Who supports it? | Use time-bound, audited reveals. | Support policy and access test. |
| Who deletes it? | Implement return, destruction, and backup expiry. | Exit test and deletion evidence. |
The product gate should not make a legal determination. It should enforce that an approved role record exists, that the current BAA or related agreement is attached where required, and that the technical path matches the record. If the role is disputed, fail closed and route the question to counsel.
Review role changes as migrations
A new feature can change a vendor’s role without changing its company name. Adding a support search, a full-record export, an AI assistant, or a payer integration changes the function and perhaps the data category. A new region or remote support team can change the transfer and subprocessor analysis. Treat those changes like a migration: map before enablement, test with synthetic data, update contracts, and record approval.
Keep the outbound conversion path separate from operational booking. If tenant-specific counsel approves a generic event, the payload must exclude patient name, email, phone, hashed identifiers, service or treatment details, and clinical text. A click signal tied to an appointment remains a separate review question. Keep it off by default and log the approval reference, not the underlying record.
Do not let a brand name hide a data recipient
Record legal party, service, feature, field category, region, and agreement for each destination. The same provider may appear in several roles, and one product name may hide support, backup, and analytics services.
FAQ
What is the first verification step for covered entity, business associate, or subcontractor?
Name the legal entity and describe the function it performs, the party directing it, the data received, and every downstream recipient.
Can a vendor have more than one role?
Different services or relationships can create different role questions. Map each function and contract separately rather than assigning one label to the whole vendor brand.
Does a BAA settle the role decision?
No. It allocates obligations for a defined relationship. Counsel still needs the current transaction and service facts.
What must be approved before a production claim or outbound action?
Approve the role memo, contract scope, controls, and exact payload. Keep any advertising event disabled until tenant-specific legal approval is recorded.
References
- Electronic Code of Federal Regulations, “45 CFR 160.103 Definitions,” retrieved August 15, 2026: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- Electronic Code of Federal Regulations, “45 CFR 164.502 Uses and Disclosures,” retrieved August 15, 2026: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- Electronic Code of Federal Regulations, “45 CFR 164.504 Organizational Requirements,” retrieved August 15, 2026: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
- U.S. Department of Health and Human Services, “Sample Business Associate Agreement Provisions,” retrieved August 15, 2026: https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html
Related articles
How to Run a Tabletop Exercise for Breach Notification
A breach-notification tabletop should test roles, facts, evidence, risk assessment, communications, recovery, and post-exercise actions…
Proposed HIPAA Security Rule Changes for Incident Plans
As of August 15, 2026, distinguish the HIPAA Security Rule currently in effect from proposed modifications. Prepare incident,…
HIPAA Contingency Plans: Backup, Restore, and Testing
A HIPAA contingency plan should cover backup, disaster recovery, emergency mode, restore testing, recovery objectives, and evidence. The…