If a service creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate, a BAA may be required. HHS specifically says a cloud service provider can be a business associate even when it only stores encrypted ePHI and does not have the decryption key.
Why encryption does not end the BAA analysis
End-to-end encryption can meaningfully reduce who can read content, but HIPAA’s business-associate analysis is not limited to plaintext access. The legal relationship and whether the vendor is maintaining or transmitting PHI on behalf of a regulated entity matter.
Questions to resolve in writing
- Is the vendor acting on behalf of a covered entity or another business associate?
- Will the service create, receive, maintain, or transmit PHI/ePHI?
- Which legal entity signs the BAA?
- Which products, plans, features and subprocessors are covered?
- What uses and disclosures are permitted?
- What security-incident and breach-notification duties apply?
- What happens to PHI when the relationship ends?
- What audit, access, retention and records responsibilities remain with the customer?
AliasCloak and Murmivo
This site references AliasCloak for end-to-end encrypted mail/chat/files and Murmivo for end-to-end encrypted browser voice rooms. Those privacy features do not by themselves establish that a particular HIPAA-regulated use is authorized. Confirm current BAA availability directly before sending ePHI.