A law firm becomes a HIPAA business associate when its legal services for a covered entity involve protected health information (PHI). The firm then signs a business associate agreement (BAA), is directly liable for Security Rule compliance, and needs its own BAA with any vendor that stores or transmits that PHI, including its email and file-sharing provider. Those three obligations are the core of HIPAA compliance for law firms, and each one is covered below.
When does HIPAA apply to a law firm?
HIPAA applies to a law firm when the firm provides legal services to or for a covered entity, such as a health plan, provider or clearinghouse, and the work involves PHI. The firm is then a business associate. The same applies to work for another business associate. Firm size and practice area do not change the analysis.
The definition at 45 CFR 160.103 includes a person who provides “legal, actuarial, accounting, consulting, data aggregation… management, administrative, accreditation, or financial services to or for such covered entity” where the service involves PHI. HHS’s own example is an “Attorney whose legal services to a health plan involve access to PHI.” This often includes malpractice defense, payer disputes, regulatory investigations and transactions with patient data in diligence.
What does a business associate agreement require of a law firm?
A business associate agreement requires the firm to use PHI only as the contract permits, use appropriate safeguards and comply with the Security Rule for electronic PHI, report unauthorized uses and breaches, flow the same terms to its subcontractors, and return or destroy PHI at the end of the engagement where feasible.
Those terms come from 45 CFR 164.504(e)(2)(ii), which says the contract must provide that the business associate will “Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information” and “Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware, including breaches of unsecured protected health information.” The Security Rule version at 45 CFR 164.314(a)(2)(i) adds that the business associate will “Report to the covered entity any security incident of which it becomes aware.”
Under 45 CFR 164.502(e)(2), the covered entity needs this in writing before it shares PHI, and the satisfactory assurances “must be documented through a written contract or other written agreement or arrangement.”
Is a law firm directly liable under the HIPAA Security Rule?
Yes. HHS lists “Failure to comply with the requirements of the Security Rule” among the provisions for which business associates are directly liable, citing 45 CFR 164.306, 164.308, 164.310, 164.312, 164.314 and 164.316. A firm handling a client’s electronic PHI is answerable to HHS, not only to the client under the BAA.
That means the firm needs the Security Rule basics: a risk analysis, policies, workforce training, and the technical safeguards. Two technical points matter most for email and files:
- Audit controls at 164.312(b) are a required standard: “Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.”
- Encryption at 164.312(a)(2)(iv) and transmission encryption at 164.312(e)(2)(ii) are addressable, which means the firm assesses whether they are reasonable and appropriate and documents its decision. HIPAA does not require encryption in every case, but a firm that decides against it has to record why and what it does instead.
Does a law firm’s email vendor need a BAA with the firm?
Yes, if the vendor creates, receives, maintains or transmits the client’s PHI on the firm’s behalf. That vendor is a subcontractor business associate, and 45 CFR 164.308(b)(2) allows the firm to use it only with satisfactory assurances documented in a written agreement. This holds even when the vendor cannot decrypt the data.

The definition of business associate at 160.103 includes “A subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate.” HHS’s cloud computing guidance addresses the encrypted case directly: “Lacking an encryption key for the encrypted data it receives and maintains does not exempt a CSP from business associate status and associated obligations under the HIPAA Rules.”
So the firm needs a BAA with its email and file-sharing provider for PHI matters, and it should also ask what the provider can see. HHS lists “Failure to enter into business associate agreements with subcontractors that create or receive PHI” among the business associate’s own direct liabilities.
How does encryption affect breach notification for a law firm?
Encryption can take a law firm’s PHI outside HIPAA breach notification. The duty applies to “unsecured protected health information,” which 45 CFR 164.402 defines as PHI “not rendered unusable, unreadable, or indecipherable to unauthorized persons” through a method HHS specifies, and HHS guidance names encryption, provided the key “has not been breached.”
A firm that is a business associate must report breaches of unsecured PHI to its client under its BAA. If PHI in a compromised mailbox or on a vendor’s servers was encrypted consistent with HHS guidance and the keys were not compromised, that PHI is not unsecured PHI and the breach notification duty does not attach to it. Where the keys sit is therefore part of the question: if the provider holds keys that could decrypt the data, a breach of the provider can put the keys and data at risk together.
Which HIPAA requirements apply to a law firm’s email and files?
When a firm handles PHI for a client, its email and file sharing must meet the business associate terms and the Security Rule. That means a BAA with the client, a BAA with its email and file vendor, required audit controls, access control, and an encryption decision for the addressable specifications.
| Requirement | Citation | Required or addressable | How PreVeil supports it |
|---|---|---|---|
| Business associate contract with the covered entity | 45 CFR 164.502(e), 164.504(e) | Required | Firm signs with its client; PreVeil does not replace it |
| Subcontractor BAA with the firm’s email and file vendor | 45 CFR 164.308(b)(2), 164.314(a)(2)(iii) | Required | PreVeil signs a BAA with law firms when the platform is used for PHI |
| Audit controls | 45 CFR 164.312(b) | Required | Activity logs in the PreVeil admin console |
| Access control | 45 CFR 164.312(a)(1) | Required standard | Access only by users and devices holding keys |
| Encryption and decryption | 45 CFR 164.312(a)(2)(iv) | Addressable | Message contents and attachments, and files, encrypted end to end |
| Transmission encryption | 45 CFR 164.312(e)(2)(ii) | Addressable | Encrypted in transit and at rest; keys on user devices |
| Breach reporting to the client | 45 CFR 164.504(e)(2)(ii); 164.402 | Required | Encryption consistent with HHS guidance supports the unsecured PHI analysis |
How does PreVeil fit a law firm’s HIPAA work?
PreVeil signs a BAA with law firms when the work involves PHI. It encrypts message contents and attachments, and files, end to end inside Outlook, Gmail and Apple Mail, so a firm can exchange PHI with a healthcare client, opposing counsel or experts without moving to a portal. Clients reply for free from their browser, and replies stay encrypted.
PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. That does not remove the need for a BAA, and PreVeil does not claim it does. It means the vendor in the firm’s subcontractor chain cannot read the message contents, attachments or files it stores. PreVeil supports specific Security Rule requirements; the firm’s HIPAA program, risk analysis and policies remain the firm’s.
The guide to law firm security obligations for regulated clients covers HIPAA alongside NYDFS, outside counsel guidelines and CUI, and the PreVeil for law firms page summarizes the product.
Frequently asked questions
Is every law firm with a healthcare client a business associate?
No. A firm is a business associate only when its legal services for the covered entity involve PHI.
Does HIPAA require a law firm to encrypt email?
HIPAA treats encryption as addressable, not required. A firm must assess whether encryption is reasonable and appropriate, and document its decision and any alternative. Audit controls are required.
Does my email provider need to sign a BAA with my firm?
Yes, if it creates, receives, maintains or transmits PHI on the firm’s behalf. HHS says lacking the encryption key does not exempt a cloud provider from business associate status.
Does PreVeil sign a BAA with law firms?
Yes. PreVeil signs a BAA with law firms when the work involves PHI.
Can PreVeil read the PHI my firm sends?
No. Encryption keys stay on users’ devices, so PreVeil’s servers cannot decrypt message contents, attachments or files.
Is a small firm exempt from HIPAA?
The business associate definition has no size threshold. A solo practitioner whose work for a covered entity involves PHI is a business associate.
Sources
- 45 CFR 160.103: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- 45 CFR 164.308: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- 45 CFR 164.312: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- 45 CFR 164.314: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.314
- 45 CFR 164.402: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
- 45 CFR 164.502: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- 45 CFR 164.504: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
- HHS, Business associates: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
- HHS, Direct liability of business associates: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/factsheet/index.html
- HHS, Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
- HHS, Guidance to render unsecured PHI unusable, unreadable, or indecipherable: https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html
Talk to PreVeil about PHI in your matters
A demo covers the BAA, how PHI moves through the firm’s email and files, and where PreVeil fits. Request a demo