Short answer: Healthcare consultants are generally subject to HIPAA, but as business associates rather than covered entities — a distinct legal category. If a consultant creates, receives, maintains, or transmits protected health information on behalf of a medical practice or other covered entity, they need a signed Business Associate Agreement with that practice and are directly liable under HIPAA for how they handle that data, even though they're not the covered entity themselves.
Why "covered entity" and "business associate" aren't the same thing
HIPAA draws a real distinction between the two categories, and it matters for consultants specifically. A covered entity is generally the health care provider, health plan, or clearinghouse itself — the party providing care or handling claims directly. A business associate is anyone else who handles PHI on that covered entity's behalf, without providing care directly. A healthcare consultant advising a medical practice on operations, compliance, billing, or IT typically falls into this second category — a business associate, not a covered entity.
What determines whether a specific consultant is a business associate
The deciding factor isn't the job title "consultant" itself — it's whether the work involves actual access to PHI. Some examples:
Likely a business associate: A consultant reviewing patient records to advise on billing accuracy. An IT consultant with access to systems storing PHI. A compliance consultant reviewing actual patient files as part of an audit. A revenue cycle consultant handling claims data tied to individual patients.
Likely not a business associate: A management consultant advising purely on staffing structure or general business strategy with no access to patient records. A marketing consultant working only with aggregate, de-identified data. A consultant providing general training or education without ever touching actual patient information.
The test is functional: does the engagement involve actually creating, receiving, maintaining, or transmitting PHI, not just working in a healthcare-adjacent context.
What being a business associate actually requires
If a consultant is a business associate, they need:
- A signed Business Associate Agreement with each covered entity client before accessing PHI
- Their own reasonable safeguards protecting any PHI they handle
- A process for reporting any breach involving PHI they were entrusted with back to the covered entity
- To ensure any subcontractors they use who also touch PHI are similarly bound by agreement
Critically, business associates are directly liable under HIPAA for their own violations — this isn't a technicality where only the covered entity faces consequences. A consultant who mishandles PHI can face direct enforcement action, independent of what happens to their client.
Why this matters for consultants specifically
A consultant who assumes "HIPAA is my client's problem, not mine" because they're not technically a covered entity is working from an outdated or incorrect understanding. Since the 2013 Omnibus Rule, business associates have carried direct HIPAA liability, not just contractual obligations to their clients. Operating without proper BAAs in place, or without your own reasonable safeguards for any PHI you handle, is a real compliance exposure — for you personally or for your consulting business, not just the practices you work with.
What to do if you're a healthcare consultant
If your work involves any access to actual patient data, make sure you have signed BAAs with every client before that access begins, and that you have your own documented safeguards for how you handle, store, and eventually dispose of any PHI you're entrusted with. This is worth treating as seriously as if you were the covered entity yourself, because under HIPAA, you carry real, direct responsibility either way.