Compliance Colleague · Answers · HIPAA

Is a SaaS vendor that stores encrypted ePHI and never views it a HIPAA business associate?

Standard: HIPAA · Answered by Compliance Colleague on September 30, 2026

Question as asked: We're a SaaS vendor that stores a hospital's ePHI in encrypted form and never views it. Are we a HIPAA business associate?

Yes — under the current HIPAA rules, a SaaS vendor that stores a hospital's ePHI in encrypted form, even without viewing it, is a business associate, not an exempt "conduit."

Why encryption/no-key doesn't remove BA status: The "conduit exception" is narrow and applies only to entities that provide mere transmission of PHI on a transient basis (e.g., a telecom carrier or ISP passing data through), where any storage is incidental to the transmission (45 CFR § 160.103, definition of "business associate"). A SaaS provider that stores ePHI — even encrypted, even without access to the decryption key — falls under the "maintains" prong of the definition ("creates, receives, maintains, or transmits protected health information on behalf of a covered entity"). HHS's guidance on cloud computing (Guidance on HIPAA & Cloud Computing Services) confirms this directly: a cloud service provider that only stores encrypted ePHI and lacks the decryption key is still a business associate; the conduit exception is limited to transmission-only services, not storage.

Practical consequence:

  • The hospital (covered entity) may disclose ePHI to your platform only with "satisfactory assurances," documented in a written Business Associate Agreement — § 164.502(e)(1) and § 164.308(b)(1).
  • As a BA, you are directly subject to most of the Security Rule (administrative, physical, and technical safeguards, §§ 164.308, 164.310, 164.312) and the applicable Breach Notification Rule obligations (§ 164.410 — notify the covered entity without unreasonable delay, no later than 60 days after discovery).
  • "We never view the data" does not change this analysis; it may be a relevant fact for your own risk profile (e.g., a zero-knowledge architecture reduces certain risks and may support treating some incidents as lower-risk under the § 164.402 breach risk assessment factors), but it does not remove BA status or the BAA requirement.

The one scenario where you would not be a BA is if your service is purely a transmission pipe with no storage beyond what's incidental to moving data through (true conduit) — but "stores ePHI" as described in your question places you outside that exception.

Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.

This is one answer from Compliance Colleague, which answers questions like this against 30+ security, privacy and AI governance standards, with the clause cited, and reviews your policies against them. Ask your own question free, no card required →

More answers