A business associate is anyone who creates, receives, maintains or transmits protected health information on behalf of a covered entity. Viewing it is not one of the four. An ambient scribe receives audio of a clinical encounter and usually maintains it, which puts it inside the definition regardless of whether anyone at the vendor can read it, and the same test applies to whoever that vendor passes the audio to next.
Ambient documentation is the fastest-moving AI category in small practices, and it is usually bought the way software is bought: a demo, a price, a security page. The HIPAA question gets settled by a sentence in a sales conversation, and the sentence is often the wrong one. This guide covers the actual test, why the most common vendor reassurance is irrelevant to it, how far down the supply chain it reaches, and what a signed agreement still cannot tell you afterward.
The four words that decide it
Under 45 CFR 160.103, business associates are those that "create, receive, maintain or transmit" protected health information on behalf of a covered entity.[1]
Read that list again and notice what is absent. Access is not there. Viewing is not there. Understanding the contents is not there. The definition is about what an entity does with PHI in a custodial sense, not about what it perceives. That distinction is the whole of this article, because nearly every objection a vendor raises is an argument about perception.
An ambient scribe receives audio of a clinical encounter. That audio is PHI. In almost all deployments it also maintains that audio, or a transcript derived from it, for at least as long as it takes to produce a note, and frequently much longer for quality review or model evaluation. Receive and maintain are two of the four verbs.
Why "we can never see your data" is not an answer
The most common reassurance is some version of end-to-end encryption: the vendor cannot decrypt your audio, therefore it is not really handling your PHI.
OCR addressed exactly this reasoning in the cloud computing context, and rejected it. A provider that maintains ePHI qualifies as a business associate even where it provides no-view services, and lacking an encryption key does not exempt a provider from business associate status. Data storage companies qualify as business associates regardless of whether they actually view the information they hold.[1][2]
This is worth stating plainly because the argument sounds so reasonable. Not being able to read the data is a genuinely good security property, and a vendor that offers it is doing something right. It simply is not responsive to the question of whether they are a business associate, and a vendor presenting it as though it were has either misread the rule or is hoping you will not check.
An ambient scribe is not a courier
The other route out is the conduit exception, and it is narrower than its reputation.
The exception is limited to transmission services, whether digital or hard copy, including any temporary storage of transmitted data incident to such transmission.[1] HHS has described it as a narrow exception intended to exclude only entities providing mere courier services.[1] The postal service carrying a paper chart and a pure internet service provider moving packets are the model cases.
The hinge is persistence. A courier holds your material only as an unavoidable side effect of moving it. A scribe holds audio so that it can generate a note, and often keeps a transcript afterward so the note can be reviewed, the model evaluated, or a dispute investigated. That is not storage incidental to transmission. It is the point of the product.
Which means a CSP that maintains ePHI for the purpose of storing it qualifies as a business associate and not a conduit, even where it does not actually view the information.[1][2] A scribe is further from the courier case than a storage provider is, not closer.
The chain nobody maps
Here is the part that survives a good procurement process and still goes unexamined.
HHS has said that the same interpretations that apply to determining whether a first-tier contractor is a business associate also apply to determining whether a subcontractor is a business associate.[1] The test does not stop at the party you contracted with. It follows the PHI.
So the real picture is a chain: your practice, the scribe vendor, whatever model host that vendor sends audio or transcripts to, the cloud infrastructure underneath that, and anything further down. Every link that creates, receives, maintains or transmits PHI is caught by the same four verbs.
Your BAA with the vendor is necessary and it is not sufficient, because it does not by itself place the rest of that chain under agreement. That is the vendor's obligation to arrange downstream, and it is a fair question to ask them to evidence rather than assert. It is also why the honest version of the question is not "do you sign a BAA" but "who else touches this audio, and what is your agreement with them."
What to ask before signing
Five questions, and the last two are the ones that usually reveal a longer chain than the sales conversation described.
Is a BAA executed before any PHI flows, rather than after go-live. Which subcontractors touch PHI, and are they under BAAs with the vendor. Is audio or transcript retained once the note is produced, and for exactly how long. Is any of it used for model training, tuning or evaluation. And what happens to all of it on termination.
The retention and training answers matter most because they determine whether you are dealing with a transient processing step or a durable copy of your patients' encounters sitting somewhere else. They also tend to be the answers that require someone technical to join the call.
What the agreement still cannot tell you
Suppose all of that goes well. The BAA is signed, the chain is mapped, retention is bounded.
Months later a note is questioned. A BAA cannot tell you which model version produced it, whether the model was the one you approved, or whether the record of that note has been altered since. A contract allocates duties between parties. It is not a record of events, and no amount of contractual care converts it into one.
That is a different kind of question, and it needs something made at the time rather than signed in advance. We covered the mechanics in proving an AI scribe note is genuine, and the separate obligation to put the scribe into your risk analysis in adding your AI scribe to your SRA. Business associate status, risk analysis, and per-note provenance are three distinct duties that people routinely collapse into one, and satisfying any of them leaves the other two open.
What we are careful never to claim
Business associate status is a legal determination and it belongs to your counsel, not to a vendor page and not to this article. Nothing here is legal advice, and a specific product's facts can change the analysis.
RankShieldMD is not a medical device, does not render or score clinical decisions, and never sees PHI. It does not make anyone HIPAA compliant, does not negotiate your agreements, and does not decide who in your chain is a business associate. What it does is narrow and checkable: it binds a model version to an output at the moment it happens, in a tamper-evident, PHI-free record a third party can verify without trusting us. That supports the evidentiary question a contract cannot reach.
References
- [1] Holland & Hart Health Law Blog. HIPAA, Business Associates, and the Conduit Exception. Collects the 45 CFR 160.103 definition, the transmission-services limit on the conduit exception, HHS's "mere courier services" characterization, the no-view cloud position, and the subcontractor interpretation. hhhealthlawblog.com
- [2] U.S. Department of Health and Human Services. Guidance on HIPAA & Cloud Computing. OCR's position that a CSP creating, receiving, maintaining or transmitting ePHI is a business associate, including where it provides no-view services and does not hold the encryption key. hhs.gov
- [3] U.S. Department of Health and Human Services. Business Associates. The definition and the covered-entity relationship. hhs.gov