HIPAA Business Associate (US)
stable hipaa-business-associate-us · v1.0The same SaaS AI provider, selling into United States healthcare. A vendor whose service creates, receives, maintains or transmits electronic protected health information on behalf of a covered-entity customer is a business associate under 45 CFR 160.103 and has been directly liable for the Security Rule since the 2013 Omnibus Rule, whatever its contract says. This overlay states what that liability adds to the base library rather than restating it: the specifications the rule names and enforces, the clocks and retention floors it fixes that no canonical control sets, and the contract terms that run upward from the vendor to its customer instead of downward to its suppliers. It is an overlay on saas-ai-provider and inherits every applicability that profile states. The covered entity's own duties, and the duties of a health care clearinghouse or a group health plan, are another seat and belong to a profile that does not exist yet; the five rows of the extract that state them carry exclude-scope dispositions rather than applicability here.
- Roles
- Provider
- Deployment models
- Cloud, multi-tenant SaaSCloud, single tenant
- Risk classes
- noneminimaltransparencyhigh-risk-annex-iiigpai
- Jurisdictions
- US-federal
- Frameworks
- SOC2ISO-27001NIST-800-53CSA-CCMCSA-AICMISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICEU-AI-ActGDPRHIPAA-SR
GOV · Governance & Risk
New row, from item 14 of the section 2 list in docs/s7-hipaa-proposals.md. 164.316(a) is a coverage test against an external instrument: every standard and implementation specification of the subpart traces to the policy or procedure that implements it, or to a 164.306(d)(3) determination. GOV-001 requires the policy to exist, be approved, be communicated and be reviewed, and holds this row as a partial because it states no trace. GOV-010 records that the obligation exists and GOV-024 that the procedures are available and kept current; neither maps a requirement to the procedure that answers it. The same gap sits on the GOV-024 row of this profile, whose note the lead may want to extend with the pointer.
164.308(a)(2) asks for one named security official responsible for developing and implementing the policies and procedures of the subpart. The named programme owner GOV-002 already requires is that person, and under this overlay the name has to be producible on request rather than merely assigned.
164.308(a)(1)(ii)(A) is the most enforced specification in the rule and the one a healthcare customer asks for by name. Two things change for GOV-005 here: its scope has to be demonstrably every system holding electronic protected health information, and 164.306(b)(2) makes the entity's size and capabilities, its technical infrastructure and the cost of a measure recorded inputs to the choice of treatment, which GOV-005 does not currently name.
164.308(a)(8) makes a periodic technical and nontechnical evaluation against the requirements of the subpart a standard in its own right. The audit plan GOV-011 requires has to name Subpart C as a checked requirement set, not only the organisation's own policies.
164.306(d)(3) is now stated. The register holds a determination against an external requirement as its own kind of entry: the specification named, the assessment of why implementing it is not reasonable and appropriate in this environment, the equivalent alternative measure or the finding that none is reasonable and appropriate, the approver and a re-assessment trigger rather than an expiry. Twenty-two addressable specifications of the extract run through it, and they no longer sit in a register that expires them. The control is renamed Exception and Requirement Determination Register.
164.310(d)(2)(iii) asks for a record of the movements of hardware and electronic media and the person responsible for each. GOV-014 records an owner and a lifecycle state, which is not a movement log.
164.316(b)(2)(i) is now stated by derivation. Each period in the schedule names the obligation it derives from, is set at or above the longest period any obligation binding that category fixes, and carries the measurement point where the obligation counts from something other than creation. For a business associate that obligation is six years from the later of creation and the date the documentation last was in effect, so a policy in force for four years is kept for ten, and it reaches every action, activity and assessment the subpart requires documented: the risk analyses, the determinations, the sanctions applied, the incident records and the evaluations.
164.308(a)(8) has a second trigger the periodic audit does not answer: an environmental or operational change affecting the security of the data. GOV-020's change-driven independent assessment is what carries it.
164.316 makes documentation availability and periodic update required specifications rather than good practice. Availability is owed to the people implementing the procedures, so a procedure held only in a compliance repository fails it.
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
IAM · Identity & Access Management
164.312(a)(2)(i) is required rather than addressable, which removes the documented-and-justified shared account route IAM-002 otherwise leaves open for systems holding electronic protected health information.
New row, from item 13 of the section 2 list in docs/s7-hipaa-proposals.md. 164.308(a)(3)(ii)(A) offers supervision as an alternative to authorisation and reaches workforce members who work in locations where the data might be accessed without holding a grant of their own. IAM-003 states the authorisation limb and holds the row as a partial for that reason. The supervision limb is stated nowhere: no canonical control treats supervision as a substitute for a grant, and INF-018 bounds who can be in a location without saying who watches them there. The specification is addressable, so a business associate that relies on authorisation alone owes a determination under 164.306(d)(3), which is the GOV-013 register as extended in migration 056.
164.312(a)(2)(ii) is a required specification and reverses IAM-007's emphasis: the duty is to have an established route for obtaining necessary data in an emergency, not only to restrict the break-glass tooling that provides one.
164.312(a)(2)(iii) asks for the session to be terminated after a predetermined period of inactivity, which is a stronger act than locking the endpoint screen.
DAT · Data Protection
164.312(a)(2)(iv) is addressable, but the HHS guidance on rendering protected health information unsecured makes encryption at rest the safe harbour that keeps a loss outside the Breach Notification Rule. DAT-003's fixed AES-256 floor is above what the rule names.
164.312(e) reaches any electronic communications network, which since 2013 has been read to include internal service-to-service traffic. DAT-004 already states that scope, which is why it holds the full on all three transmission rows.
Customer-held keys are a commitment of a hosted service.
Location transparency is a commitment of a hosted service to its tenants.
Export and portability are commitments of a hosted service to its tenants.
Exit is executed by the provider on the customer's behalf, because the customer cannot run the transition on infrastructure it does not control.
Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.
APP · Application Security
164.312(c) makes an integrity standard and a detection mechanism explicit obligations over the data itself. APP-015's reconciliation is the mechanism; its gap under this overlay is improper destruction, which the standard names alongside alteration.
INF · Infrastructure & Cloud Security
Tenant isolation exists because the product is cloud-hosted and shared.
164.310(c) makes workstation security a required standard over every device that reaches the data, and the 164.304 definition of workstation reaches the electronic media stored around it. The disposal and media re-use specifications at 164.310(d)(2) are required rather than addressable.
164.310(a) puts facility access controls in the rule directly. One of the two gaps is closed: 164.310(a)(2)(iv) now has a home, a maintenance record of repairs and modifications to the physical components that enforce the facility boundary, with the component, the work, the date and the person or contractor on each entry, and the operator attestation covering a facility the organisation does not operate. The other gap stands: 164.310(a)(2)(i) wants an emergency route into the facility in support of restoring lost data, when the normal approval path may be unavailable, and no control states it.
MON · Monitoring & Logging
164.312(b) makes audit controls a required standard over systems that contain or use electronic protected health information, so the documented log scope has to be demonstrably complete over those systems.
164.308(a)(1)(ii)(D) is now stated: a procedure for the periodic review of the activity records themselves, naming the record sets in scope, including the audit logs, the access reports and the incident tracking records, the interval for each and who performs it, with findings carried into the incident process or into a recorded decision. 164.312(b) stays split across MON-001 for the record limb and this control for the examine limb, which is why both hold a partial on it.
The service level objective and the status channel are commitments of a hosted service.
VND · Vendor & Third-Party Risk
164.308(b)(3) and 164.314(a)(2)(iii) make the written subcontractor agreement and its terms a required specification, not a commercial preference. Assurances given in a questionnaire or a security review do not discharge it.
164.308(b)(2) runs the flow-down down the whole chain: a subcontractor of a subcontractor is itself a business associate and owes the same duty onward. The sub-processor register has to reach that far.
The shared responsibility matrix exists because the customer's workload runs on the provider's service.
Requests for customer data reach the provider because it hosts the tenant's data.
164.314(a)(1) and 164.314(a)(2)(i)(A) put the compliance undertaking in the executed business associate agreement, which is the first artefact a United States healthcare customer asks a vendor for. A published responsibility matrix states the same commitment and is not the contract the rule asks for. The register keeps the set current once the required terms change, and the equivalence of the terms flowed to a subcontractor is the 164.314(a)(2)(i)(B) duty VND-003 holds, read from the upward-facing side.
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.
INC · Incident Response
The band is now in the taxonomy. An attempted unauthorised access, use, disclosure, modification or destruction carries a band of its own, as does an interference with system operations that changed nothing, which is the reach of the 164.304 definition and the precondition for reporting such an event to the covered entity under 164.314(a)(2)(i)(C).
The heaviest single addition in the overlay, now stated. The process names the notification triggers owed under each customer commitment and each regulation binding the service, expressly including an attempt that changed nothing, and names the period owed for each measured from the point of awareness, with every notification recorded against it. For a business associate those entries are 164.314(a)(2)(i)(C), every security incident it becomes aware of reported to the covered entity on the wide 164.304 definition, and the 164.410 clock it imports, without unreasonable delay and in no case later than 60 days after discovery. The control text carries the discipline; this row carries the figure.
BCM · Business Continuity
164.308(a)(7)(ii)(C) makes the emergency mode operation plan a required specification, and its object is the security of the data during degraded operation rather than the availability of the service. BCM-001's clause naming which controls stay in force, and the compensating measure for any suspended, is what answers it.
164.308(a)(7)(ii)(A) makes retrievable exact copies a required specification, and 164.310(d)(2)(iv) adds the pre-movement copy, which continuous backup at the defined RPO satisfies.
164.308(a)(7)(ii)(E) is the business impact analysis in the rule's own vocabulary, and it exists to order the recovery sequence the three required contingency specifications execute.
AIG · AI Governance
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.5 binds every provider, whatever the risk class of its other systems.
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
The provider is also a user of AI systems, including the models beneath its product. The use register covers both.
The statement on customer data in training and the opt-out are the provider's to give.
Any organisation that trains, fine-tunes or evaluates a production model runs the pipeline this control secures. A provider that only calls a third-party model records that no pipeline exists against the inventory entry.
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
HRS · Human Resources Security
164.308(a)(3)(ii)(B) makes a clearance determination before a grant an addressable specification, so a decision not to screen for a role that reaches the data is a written determination rather than a silent choice.
164.308(a)(1)(ii)(C) makes the sanction policy a required specification, and asks for sanctions applied rather than only a policy written. The evidence is the application record.
164.310(b) adds a limb HRS-011 does not carry: the physical attributes of the surroundings of a specific workstation or class of workstation. That is a siting requirement per class, and it is what governs a home desk facing a shared room.
AIG · AI Governance
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii
Conformity assessment, the declaration and the CE marking (Art.43, 47, 48) bind providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii and the organisation is established outside the Union
Art.22 binds providers of high-risk systems established outside the Union. The Art.54 arm for general-purpose model providers belongs to the gpai-model-provider profile.
Condition: ai_risk_class in high-risk-annex-iii
Art.20 and Art.21 bind providers of high-risk systems. The Art.53.5 cooperation duty on general-purpose model providers belongs to the gpai-model-provider profile.
AIG · AI Governance
Worker notification before a system is put into use at a workplace is an employer's duty under Art.26(7). A provider placing the system on the market owes it for its own workforce only where it is also the deployer, which is the enterprise-ai-deployer seat.
Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.
The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.
Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.
The public training content summary is the gpai-provider seat (ADR-046). A provider that fine-tunes a third-party model for its product records provenance under AIG-013 and is not the models provider.
The copyright policy and crawler conduct of a general-purpose model provider are the gpai-provider seat (ADR-046). A SaaS providers own licensed assets and training data licences are GOV-015 and AIG-013.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
Evaluation under standardised protocols attaches to a designated general-purpose model (ADR-046). A SaaS provider evaluates the systems it operates under AIG-026 and AIG-008.
Protection of a designated models weights to a stated security goal is the gpai-provider seat (ADR-046). A SaaS providers development assets and training pipeline are IAM-014 and AIG-055.
Reporting to the AI Office about a designated model is the gpai-provider seat (ADR-046). A SaaS provider reports a systems serious incident to the competent authority under AIG-021.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
Published 2026-09-14