HealthcarePrivacy and Data Security
HIPAA Business Associates and Cloud Computing
Almost every cloud service that touches electronic protected health information is a HIPAA business associate, and the 2016 HHS cloud guidance closed the door on the comfortable myth that a vendor who only stores encrypted data—or never looks at it—escapes the rules. This guide explains who counts as a covered entity, a business associate, and a subcontractor; why the "conduit exception" almost never saves a cloud provider; and exactly what a compliant business associate agreement must contain under 45 C.F.R. 164.504(e). It walks through the Privacy, Security, and Breach Notification Rules as they apply to the cloud, the encryption-based breach safe harbor, and the shared-responsibility model that determines who is on the hook when something goes wrong. It covers OCR enforcement and the steep tiered penalties, the sweeping 2024–2025 Security Rule overhaul proposal that would make encryption and multifactor authentication mandatory, and the special problems of pushing PHI into AI and analytics pipelines. The aim is a single, readable map a hospital administrator, a SaaS founder, a privacy lawyer, and a curious patient can all follow.