45 CFR 160.103 HIPAA Definitions: PHI and Business Associates

45 CFR 160.103 is the definitions section of the HIPAA regulations, and it is where the answers to “does HIPAA apply to us?” and “is this data protected?” actually live. Every enforcement action by the Office for Civil Rights and every penalty dollar traces back to whether an organization fits a definition here and whether the information in question meets the definition of protected health information. If you handle health data in any professional capacity, this is the section that decides your exposure.

Who Counts as a Covered Entity

Three kinds of organizations are covered entities and carry the primary compliance load: health plans, health care clearinghouses, and certain health care providers.1eCFR. 45 CFR 160.103 – Definitions

Health plans are individual or group plans that provide or pay for medical care. That reaches group health plans, HMOs, Medicare Parts A through D, Medicaid, CHIP, TRICARE, the Veterans health program, the Federal Employees Health Benefits Program, Indian Health Service programs, Medicare supplement insurers, and long-term care policies, along with a catch-all for any other plan that provides or pays for medical care. Plans limited to “excepted benefits” such as stand-alone vision or dental discount programs are outside the definition.

Health care clearinghouses convert health information between nonstandard and standard formats. Billing services, repricing companies, and value-added network switches all qualify when they translate data into or out of the standard electronic transaction formats HIPAA requires.

Health care providers are the trickiest category, because they are covered only when they transmit health information electronically for one of the standard transactions listed in 45 CFR Part 162: claims, eligibility inquiries, referral authorizations, claim status checks, enrollment and disenrollment requests, and electronic payment or remittance advice.2eCFR. 45 CFR Part 162 – Administrative Requirements A solo-practice dentist who submits a single electronic claim triggers the full HIPAA rulebook. A provider who handles everything on paper is not a covered entity, though that scenario has become rare.

Business Associates and Subcontractors

A business associate is any person or organization outside the covered entity’s workforce that handles protected health information on the entity’s behalf. Claims processors, data analysts, billing companies, benefits managers, and utilization reviewers all fit. So do legal, actuarial, accounting, and consulting services whenever the work requires access to protected data.

What creates business associate status is actual access to the data, not the existence of a signed contract. An IT vendor that can view patient records during a system migration is a business associate whether anyone thought to draft an agreement or not. The agreement is still legally required. Under the Privacy Rule, it must spell out exactly what uses of the data are permitted, forbid disclosures beyond what the contract or the law allows, and require appropriate safeguards.3U.S. Department of Health and Human Services. Business Associates If a covered entity finds that a business associate has materially breached the agreement, the entity has to take reasonable steps to fix the problem, terminate the contract if necessary, or report the situation to HHS.

Responsibility runs down the chain. A subcontractor that receives protected data from a business associate to perform a delegated function must sign its own business associate agreement and is directly liable for compliance. The HITECH Act made business associates and their subcontractors independently subject to enforcement, so HHS can penalize them without going through the covered entity first.4HHS.gov. Direct Liability of Business Associates

Workforce Is Not a Business Associate

The regulation draws a clean line. “Workforce” means employees, volunteers, trainees, and anyone else whose work conduct is under the direct control of the covered entity or business associate, paid or not. A medical resident rotating through a hospital is part of the hospital’s workforce even though a separate institution employs them. No business associate agreement is needed for workforce members, because they operate under the entity’s own policies and training. The reverse trap is just as real: calling a contractor a “volunteer” does not make them workforce if the entity does not actually control how they perform the work.

What Protected Health Information Covers

Protected health information is the data all of these definitions exist to protect. It is individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits in any form: electronic records, paper charts, and spoken conversations alike.

For information to qualify, three things have to be true. It must be created or received by a health care provider, health plan, employer, or clearinghouse. It must relate to an individual’s past, present, or future health, the provision of care, or payment for care. And it must either identify the individual or give a reasonable basis to believe someone could identify them from it.5GovInfo. 45 CFR 160.103 – Definitions A diagnosis with no way to connect it to a person is health information but not protected health information. Attach a name, a date of birth, or a medical record number, and it becomes protected.

Medium does not matter. Whether the data sits on an encrypted server, appears on a faxed prescription, or comes up in a hallway conversation between nurses, the same protections apply.

Protection Continues After Death

Protected health information about a deceased person remains protected for 50 years after the date of death. During that window the rules generally apply the same way they do for living individuals, with specific exceptions for disclosures to coroners, funeral directors, organ procurement organizations, and law enforcement.6HHS.gov. Health Information of Deceased Individuals After 50 years the data drops out of the definition entirely.

What Is Carved Out of PHI

Four categories of data are excluded from the definition of protected health information even when they contain individually identifiable health details:

  • Education records governed by FERPA, including immunization records and counseling notes held by a school.
  • Student treatment records described at 20 U.S.C. 1232g(a)(4)(B)(iv) for students 18 and older who are treated by a university health center.
  • Employment records held by a covered entity in its role as an employer. A hospital’s HR file containing an employee’s drug test result is an employment record, not a clinical record, even though the same hospital handles patient data all day.
  • Information about a person who has been dead for more than 50 years.

These exclusions turn on the role of the entity holding the data and the purpose of the record, not on the type of information itself.

De-Identification Takes Data Out of HIPAA

Data that has been properly de-identified is no longer protected health information and can be used or disclosed without HIPAA restrictions. The regulations at 45 CFR 164.514 offer two routes.7eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information

Expert Determination

A qualified statistician or scientist examines the data set and certifies that the risk is “very small” that anyone could use the information, alone or combined with other reasonably available data, to identify an individual. The expert must document the methods and results that support the conclusion. The regulation does not define “very small,” leaving that to the expert’s judgment about the data and the intended recipients. Experts often attach time limits to their certifications, because new outside data sources can raise re-identification risk over time.

Safe Harbor

Safe Harbor is more mechanical. The organization strips 18 categories of identifiers from the data set and confirms it has no actual knowledge that the remaining information could identify anyone. The categories are:

  • Names
  • Geographic data smaller than a state (street address, city, county, zip code, though the first three digits of a zip code may be kept if the corresponding area contains more than 20,000 people)
  • Dates tied to an individual such as birth, admission, discharge, and death (year alone may be kept, but all ages over 89 must be grouped into a “90 or older” category)
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate or license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers such as fingerprints and voiceprints
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

Safe Harbor is more common because it does not require hiring a statistical expert, but it is also more conservative. Some data sets lose too much research value once every category has been stripped.

Genetic Information

45 CFR 160.103 defines genetic information to include an individual’s genetic tests, the genetic tests of family members, the manifestation of a disease or disorder in family members, and any request for or receipt of genetic services. It also extends to the genetic information of a fetus or an embryo held through assisted reproductive technology. Information about sex and age is expressly excluded.

Genetic information is treated as health information under HIPAA, so it gets the full set of protections when held by a covered entity or business associate. The Genetic Information Nondiscrimination Act adds another layer for group health plans: they cannot use genetic information for underwriting, including setting premiums, determining eligibility, or computing contribution amounts, and they cannot collect genetic information, including family medical history, before enrollment or at any time for underwriting purposes.8U.S. Department of Labor. Frequently Asked Questions Regarding the Genetic Information Nondiscrimination Act One wrinkle worth knowing: a plan can raise premiums for a group based on a member’s manifested disease, because a manifested condition in that individual is not considered genetic information about them.

Hybrid Entities and Organized Health Care Arrangements

Not every part of every organization handles health data. A university may run a student health clinic (a covered function) alongside an athletics department (not covered). An organization that qualifies as a covered entity but performs a mix of covered and non-covered activities can designate itself a “hybrid entity,” which limits HIPAA obligations to the health care components rather than the whole organization.9eCFR. 45 CFR 164.105 – Organizational Requirements The designation is not automatic; the organization must formally document which components are health care components, and that documentation must include every part that would independently meet the definition of a covered entity or business associate.

The regulation also defines “organized health care arrangements,” which let multiple covered entities share protected health information for joint operations without each disclosure requiring a business associate agreement. A common example is a hospital and its affiliated physician group jointly performing utilization review, quality assessment, or shared payment activities. A group health plan and its health insurer can also qualify. The arrangement has to involve a clinically integrated setting, a joint public-facing identity, or shared financial risk.

What Getting the Definitions Wrong Costs

Civil penalties scale with the violator’s level of awareness and whether the problem was corrected. The 2026 inflation-adjusted amounts fall into four tiers:10Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Did not know, and could not have known through reasonable diligence: $145 to $73,011 per violation, up to $2,190,294 per calendar year for identical violations.
  • Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, same annual cap.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
  • Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, same annual cap.

The gap between the first and last tiers is the whole point. An entity that genuinely could not have known faces a minimum penalty of $145. An entity that knew and did not fix it faces a floor of $73,011 per violation, and a calendar year of repeated identical violations can approach $2.2 million.

Criminal penalties are separate and apply to individuals who knowingly obtain or disclose protected health information in violation of the rules. Under 42 U.S.C. 1320d-6, basic wrongful disclosure carries up to a $50,000 fine and one year in prison; obtaining the data under false pretenses raises the ceiling to $100,000 and five years; and doing it with intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm reaches $250,000 and ten years.11GovInfo. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information Criminal cases are handled by the Department of Justice, not HHS, and they target individuals. A hospital employee who snoops through celebrity medical records and sells information to a tabloid sits at the top tier.