Direct answer

If a service creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate, a BAA may be required. HHS specifically says a cloud service provider can be a business associate even when it only stores encrypted ePHI and does not have the decryption key.

Why encryption does not end the BAA analysis

End-to-end encryption can meaningfully reduce who can read content, but HIPAA’s business-associate analysis is not limited to plaintext access. The legal relationship and whether the vendor is maintaining or transmitting PHI on behalf of a regulated entity matter.

!
Do not infer a BAA from encryption marketing.

Before routing ePHI through AliasCloak, Murmivo, a conventional email provider, cloud storage, or another service, confirm whether that vendor will sign the agreement your organization requires and whether the agreement covers the actual service and data flow.

Questions to resolve in writing

  • Is the vendor acting on behalf of a covered entity or another business associate?
  • Will the service create, receive, maintain, or transmit PHI/ePHI?
  • Which legal entity signs the BAA?
  • Which products, plans, features and subprocessors are covered?
  • What uses and disclosures are permitted?
  • What security-incident and breach-notification duties apply?
  • What happens to PHI when the relationship ends?
  • What audit, access, retention and records responsibilities remain with the customer?

AliasCloak and Murmivo

This site references AliasCloak for end-to-end encrypted mail/chat/files and Murmivo for end-to-end encrypted browser voice rooms. Those privacy features do not by themselves establish that a particular HIPAA-regulated use is authorized. Confirm current BAA availability directly before sending ePHI.

Primary HHS sources