Is a SaaS vendor that stores encrypted ePHI and never views it a HIPAA business associate?
Question as asked: We're a SaaS vendor that stores a hospital's ePHI in encrypted form and never views it. Are we a HIPAA business associate?
Yes — under the current HIPAA rules, a SaaS vendor that stores a hospital's ePHI in encrypted form, even without viewing it, is a business associate, not an exempt "conduit."
Why encryption/no-key doesn't remove BA status: The "conduit exception" is narrow and applies only to entities that provide mere transmission of PHI on a transient basis (e.g., a telecom carrier or ISP passing data through), where any storage is incidental to the transmission (45 CFR § 160.103, definition of "business associate"). A SaaS provider that stores ePHI — even encrypted, even without access to the decryption key — falls under the "maintains" prong of the definition ("creates, receives, maintains, or transmits protected health information on behalf of a covered entity"). HHS's guidance on cloud computing (Guidance on HIPAA & Cloud Computing Services) confirms this directly: a cloud service provider that only stores encrypted ePHI and lacks the decryption key is still a business associate; the conduit exception is limited to transmission-only services, not storage.
Practical consequence:
- The hospital (covered entity) may disclose ePHI to your platform only with "satisfactory assurances," documented in a written Business Associate Agreement — § 164.502(e)(1) and § 164.308(b)(1).
- As a BA, you are directly subject to most of the Security Rule (administrative, physical, and technical safeguards, §§ 164.308, 164.310, 164.312) and the applicable Breach Notification Rule obligations (§ 164.410 — notify the covered entity without unreasonable delay, no later than 60 days after discovery).
- "We never view the data" does not change this analysis; it may be a relevant fact for your own risk profile (e.g., a zero-knowledge architecture reduces certain risks and may support treating some incidents as lower-risk under the § 164.402 breach risk assessment factors), but it does not remove BA status or the BAA requirement.
The one scenario where you would not be a BA is if your service is purely a transmission pipe with no storage beyond what's incidental to moving data through (true conduit) — but "stores ePHI" as described in your question places you outside that exception.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)