{"id":9583,"date":"2025-11-13T14:38:00","date_gmt":"2025-11-13T14:38:00","guid":{"rendered":"https:\/\/medical-article.com\/?p=9583"},"modified":"2025-11-13T14:38:00","modified_gmt":"2025-11-13T14:38:00","slug":"when-your-cloud-provider-doesnt-understand-hipaa-a-cautionary-tale","status":"publish","type":"post","link":"https:\/\/medical-article.com\/?p=9583","title":{"rendered":"When Your Cloud Provider Doesn\u2019t Understand HIPAA: A Cautionary Tale"},"content":{"rendered":"<p>By JACOB REIDER &amp; JODI DANIEL<\/p>\n<div class=\"wp-block-image\">\n<\/div>\n<div class=\"wp-block-image\">\n<\/div>\n<p><strong>Jacob:<\/strong> I recently needed to sign a Business Associate Agreement (BAA) with one of the large hosting providers for a new health IT project. What should have been straightforward turned into a multi-week educational exercise about basic HIPAA compliance. And when I say \u201cbasic,\u201d I mean really basic, like the definitions in the statute itself.<\/p>\n<p>Here\u2019s what happened and why you need to watch out for this if you\u2019re building health care technology.<\/p>\n<p>I\u2019m building a system that automates clinical data extraction for research studies. Like any responsible health care tech company, I need HIPAA-compliant infrastructure. The company (I\u2019ll call them Hosting Company or HC) is good technically, and they\u2019re hosting our development environment, so I signed up for their enhanced support plan (which they require before they\u2019ll even consider a BAA) and requested their standard agreement.<\/p>\n<p><em>The Problem<\/em><\/p>\n<p>HC\u2019s BAA assumes every customer is a \u201cCovered Entity.\u201d That means a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically.<\/p>\n<p>But that\u2019s not me. I\u2019m not a Covered Entity. I\u2019m a Business Associate (BA). I handle protected health information on behalf of Covered Entities. When I need cloud infrastructure, I need my vendors to sign subcontractor BAAs with me.<\/p>\n<p><em>The Back and Forth<\/em><\/p>\n<p>When I told HC that I couldn\u2019t sign their BAA as written, they escalated to their legal department. Days later, a team lead came back with this response:<\/p>\n<p>\u201cTo HC, even if you are a subcontracted or a down the line subcontracted association. It would still be an agreement between the covered entity within the agreement and HC\u2026 So even being a business associate, it would still be considered a covered entity since it is your business that is being covered.\u201d<\/p>\n<p>I had to read it twice. This is simply wrong.<\/p>\n<p><strong>Jodi:<\/strong> Let me chime in here with the legal perspective, because this confusion is more common than it should be.<\/p>\n<p>The terms \u201cCovered Entity\u201d and \u201cBusiness Associate\u201d aren\u2019t interchangeable marketing terms. They have specific legal definitions in 45 CFR \u00a7 160.103. You can\u2019t just redefine them because it\u2019s administratively convenient. Generally\u2026 covered entities are (most) health care providers, health plans, and health care clearinghouses; business associates are those entities that have access to protected health information to perform services on behalf of covered entities; and subcontractors are persons to whom a business associate delegates a function, activity, or service.<\/p>\n<p>Here\u2019s what the regulations actually say:<\/p>\n<p><span><\/span><\/p>\n<p>Covered entities are required to have BAAs with the entities that use protected health information to provide services on their behalf (i.e., their business associates or BAs) under 45 CFR \u00a7 164.502(e).\u00a0 Under 45 CFR \u00a7 164.502(e)(1)(ii) and \u00a7 164.308(b)(2), BAs are not just permitted but <em>required<\/em> to execute subcontractor BAAs with other vendors that create, receive, maintain, or transmit PHI on their behalf.<\/p>\n<p>When that happens, the subcontractor <em>also<\/em> becomes a BA (sometimes called a \u201cBusiness Associate of a Business Associate\u201d or a \u201cSubcontractor\u201d). The HIPAA obligations cascade down the chain. Covered entities are <em>not<\/em> required to have BAAs with Subcontractors. 45 CFR \u00a7 164.502(e)(1)(i).<\/p>\n<p>That\u2019s exactly what\u2019s happening in Jacob\u2019s situation:<\/p>\n<p>The Covered Entities (the health care providers in the research study) have BAAs with Jacob\u2019s company (making him a BA).<\/p>\n<p>Jacob\u2019s company, in turn, must have BAAs with any Subcontractors like HC that may handle PHI on behalf of Jacob\u2019s company.<\/p>\n<p>HC becomes a BA through this subcontractor relationship.<\/p>\n<p>The distinction matters for compliance and audit purposes. OCR, SOC 2 auditors, and HITRUST assessors all expect the <em>contractual chain<\/em> to mirror the actual data flow. Getting the terminology wrong isn\u2019t just semantically annoying\u2014it is misrepresenting the regulations and the relationship between the parties in a legal document.<\/p>\n<p><strong>Jacob:<\/strong> Yup\u2026 and here\u2019s the practical problem: I could not legally sign a document stating that my company is a Covered Entity when it\u2019s not.<\/p>\n<p>I explained this to HC, cited the specific CFR sections Jodi just mentioned, and even sent them examples from Google Cloud\u2019s BAA, which handles both Covered Entities and BAs in the same document.<\/p>\n<p>HC\u2019s team said they\u2019d request the language change, and I\u2019m pleased to convey that (after nearly three weeks of back-and-forth) we have executed a proper BAA.<\/p>\n<p><em>What This Means for You<\/em><\/p>\n<p><strong>Jodi:<\/strong> You\u2019re right, Jacob. It\u2019s not appropriate to sign a document that says you are a covered entity when you\u2019re not one. If you\u2019re building health care technology, here\u2019s what you need to know:<\/p>\n<p><em>Understand your role in the HIPAA framework.<\/em> Are you a Covered Entity or a BA? Most tech companies are BAs. If you\u2019re providing services to health care providers, health plans, or clearinghouses and you handle PHI in the process, you\u2019re almost certainly a BA (or a subcontractor BA), not a CE.\u00a0<\/p>\n<p><em>Read the BAA carefully before signing.<\/em> The terminology matters. If a vendor\u2019s BAA only contemplates Covered Entities as customers, that\u2019s a red flag that they haven\u2019t thought through the subcontractor scenario. (And the detailed requirements of the BAA matter too, but that is a topic for another blog).<\/p>\n<p><em>Don\u2019t be afraid to push back.<\/em> If a vendor insists you sign something that mischaracterizes your role, ask them to revise the language or show you to an attorney who understands HIPAA.<\/p>\n<p><strong>Jacob:<\/strong> And so \u2026\u00a0<\/p>\n<p><em>Be prepared to educate.<\/em> Many cloud providers\u2019 legal teams (and their attorneys) don\u2019t fully understand HIPAA\u2019s cascade requirements. You may need to walk them through it. Point them to examples from AWS, Google Cloud, or Microsoft Azure, all of which have dealt with this thousands of times.<\/p>\n<p><em>Budget time for this process.<\/em> What should take a day can take a week or more if you hit legal confusion. Plan accordingly, especially if you have a launch deadline.<\/p>\n<p><strong>The Bigger Picture<\/strong><\/p>\n<p><strong>Jacob:<\/strong> HC isn\u2019t unique. I\u2019ve seen this same confusion at smaller hosting providers, SaaS companies, and even some larger tech firms. The health care industry\u2019s regulatory complexity means vendors often copy BAA templates without really understanding them.<\/p>\n<p>The irony? HC makes you pay extra for the \u201cprivilege\u201d of signing their BAA. They charge for enhanced support as a prerequisite. Not all cloud providers or other technology platforms charge more.<\/p>\n<p><strong>Jodi:<\/strong> From a legal perspective, this situation highlights a broader issue in health tech. As more non-health care companies enter the space (cloud providers, AI companies, SaaS platforms), many are encountering HIPAA requirements for the first time. Their legal teams may be excellent at tech transactions or general commercial law but unfamiliar with health care regulatory nuance.<\/p>\n<p>The good news is that this is fixable. The BAA template changes HC made aren\u2019t complex. They just needed to add language that accommodates both scenarios: customers who are Covered Entities and customers who are BAs.<\/p>\n<p><a href=\"https:\/\/cloud.google.com\/terms\/hipaa-baa?hl=en\">Google Cloud\u2019s BAA<\/a> does this elegantly in a single sentence: \u201cThis BAA applies to the extent Customer is acting as a Covered Entity or a Business Associate.\u201d That\u2019s it. Problem solved.<\/p>\n<p>Of course\u2026 it makes sense to have counsel who understands HIPAA take a look at the BAA before you sign, as there are a host of other issues that may impact your business and use of PHI.<\/p>\n<p><strong>Jacob:<\/strong> Bottom line: if you\u2019re in a similar situation, cite the specific CFR sections (45 CFR \u00a7 160.103, \u00a7 164.502(e)(1)(ii), and \u00a7 164.308(b)(2)), show them working examples from major cloud providers, and be ready to walk away if they won\u2019t fix it.<\/p>\n<p><em> Jacob Reider MD is <\/em><em>CEO of Huddle Health Solutions, Chief Health Officer at WavelyDx,<\/em> and former Deputy National Coordinator for Health IT at the Office of the National Coordinator. <em>Jodi Daniel is a partner at Wilson Sonsini Goodrich &amp; Rosati, was the founding director of the Office of the National Coordinator for Health IT. <\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>By JACOB REIDER &amp; JODI DANIEL Jacob: I recently needed to sign a Business Associate Agreement (BAA) with one of the large hosting providers for a new health IT project. What should have been straightforward turned into a multi-week educational exercise about basic HIPAA compliance. And when I say \u201cbasic,\u201d I mean really basic, like&#8230;<\/p>\n","protected":false},"author":0,"featured_media":9580,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-9583","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/medical-article.com\/index.php?rest_route=\/wp\/v2\/posts\/9583"}],"collection":[{"href":"https:\/\/medical-article.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/medical-article.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/medical-article.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9583"}],"version-history":[{"count":0,"href":"https:\/\/medical-article.com\/index.php?rest_route=\/wp\/v2\/posts\/9583\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/medical-article.com\/index.php?rest_route=\/wp\/v2\/media\/9580"}],"wp:attachment":[{"href":"https:\/\/medical-article.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/medical-article.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/medical-article.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}