Conduit Exception HIPAA: Which Vendors Actually Qualify
A fax-to-email vendor just told your practice manager they don't sign business associate agreements because they're "a conduit under HIPAA." She forwarded the email to you with a question mark. Here's the short answer: they're almost certainly wrong, and the conduit exception HIPAA regulators actually recognize is far narrower than nearly every vendor who invokes it believes.
This explainer covers what the exception says, the transient-versus-persistent access test HHS applies, which vendors genuinely qualify, and what your file needs to look like if OCR ever asks why you never obtained a signed BAA.
What the Conduit Exception in HIPAA Actually Says
The exception does not appear as a standalone regulation you can cite by section number. It lives in the definition of "business associate" at 45 CFR 160.103 and, more usefully, in the preamble commentary HHS published with the 2013 Omnibus Rule.
HHS described the exception as applying to entities that act as "mere conduits" for the transport of protected health information but do not access the information other than on a random or infrequent basis as necessary to perform the transportation service. The agency named two examples: the U.S. Postal Service and United Parcel Service, plus their electronic equivalents such as an internet service provider providing pure data transmission.
That is the whole list of examples HHS gave. Two couriers and a dumb pipe. HHS also said explicitly that the exception is intended to be narrow. Read the agency's business associate guidance and you'll see that framing repeated.
The Transient vs. Persistent Test, in One Paragraph
A vendor qualifies for the conduit exception only if its opportunity to access PHI is transient rather than persistent. If a vendor moves PHI from point A to point B and retains no copy — no cached message, no stored file, no archive, no backup — its access is transient and it may be a conduit. If the vendor stores PHI, even briefly, even encrypted, even without ever reading it, its access is persistent and it is a business associate requiring a signed BAA. Storage is the dividing line, not whether anyone actually looked.
Vendors that generally qualify
- The U.S. Postal Service delivering a mailed records packet
- A commercial courier carrying a sealed box of charts between two offices
- A telecommunications carrier providing the circuit your VPN runs over
- An ISP providing pure connectivity with no hosting, storage, or mail handling
Vendors that do not qualify, no matter what they claim
- Cloud storage and cloud hosting providers
- Email hosting and secure-messaging platforms
- Fax-to-email and cloud fax services that retain sent or received documents
- Document-transfer and large-file services with retention windows
- Managed IT providers, remote-support tools, and backup vendors
- Transcription, billing, coding, and clearinghouse services
- Shredding and media-destruction companies that hold material before destroying it
Encryption Does Not Convert a Vendor Into a Conduit
This is the argument you will hear most often, and it is the one HHS has addressed most directly. In its cloud computing guidance, OCR stated that a cloud service provider that maintains ePHI is a business associate even if the ePHI is encrypted and the provider does not hold the decryption key. HHS calls these "no-view services." No-view does not mean no-BAA.
The reasoning is straightforward. Availability and integrity are Security Rule obligations, not just confidentiality. A vendor holding your encrypted backups can still lose them, corrupt them, or fail to make them available when you need to restore. Encryption addresses one of three properties. The BAA covers all three, plus breach notification, plus your right to get the data back when the contract ends.
Practical translation for your vendor list: if the vendor's system contains PHI at rest for any measurable period, stop analyzing and get the agreement signed.
Four Vendor Pitches That Fail the Conduit Exception
"We're an internet fax service — same as the phone company"
Ask one question: does a copy of the fax remain in a web portal or an emailed attachment after transmission? If the answer is yes, the service stores PHI. The old analog fax machine was arguably a conduit scenario. A cloud fax platform with a searchable sent-items list is not.
"We only route the message; we don't open it"
Secure messaging vendors love this line. Routing implies queuing, and queuing implies storage. Ask for the retention period in writing. Any number greater than zero ends the conversation.
"We're just the pipe between your EHR and the lab"
Interface engines and integration middleware almost always log, cache, or persist messages for error handling and replay. That is persistent access by design. Request the vendor's data-retention documentation and attach it to your determination memo.
"We're a courier, and couriers are exempt"
Sometimes true. But if the courier warehouses boxes overnight, provides offsite records storage, or scans documents en route, it has crossed from transport into custody. A courier that holds your charts in a facility for three days is a records-storage vendor wearing a delivery uniform.
What OCR Enforcement Tells You About Missing BAAs
OCR has resolved multiple investigations where the core failure was a covered entity handing PHI to a third party without an agreement in place. In 2016, a North Carolina orthopaedic practice paid $750,000 after releasing X-ray films and related PHI to a vendor that converted the images to electronic media, with no business associate agreement executed. The same year, a Minnesota health system paid $1,550,000 in a case that included failure to have a BAA in place with a major contractor.
Neither case turned on the conduit exception specifically. That is exactly the point. When the agreement is missing, OCR does not spend much time debating vendor taxonomy — it asks why you disclosed PHI without satisfactory assurances. You can review resolution agreements on the HHS enforcement page and breach patterns on the OCR breach portal, where business-associate-involved incidents remain a steady share of large reported breaches.
Also worth remembering: your obligation under 45 CFR 164.502(e) and 164.308(b) is to obtain the agreement. A vendor's refusal is not a defense. It is a procurement decision you now have to make.
The Script for the Vendor Who Says "We're Just a Pipe"
Send this, in writing, from whoever owns vendor contracts at your practice:
Our records indicate your service transmits and/or stores protected health information on behalf of our practice. Please confirm in writing: (1) whether PHI is stored on your systems at any point, (2) the retention period for that data, (3) whether your personnel or subcontractors can access it, and (4) whether you will execute a business associate agreement. If you believe the conduit exception applies, please state the basis. Absent a signed agreement, we will need to suspend transmission of PHI through your service.
Most vendors sign within two weeks. A small number produce a genuine, defensible conduit answer — usually carriers and ISPs. A few go silent, which tells you everything you need to know about their compliance program.
Your Documented Evidence: The Conduit Determination Memo
If you decide a vendor is a conduit and skip the BAA, the decision must exist on paper. An auditor's question is never "was your reasoning sound?" It is "show me the analysis."
A one-page memo per vendor is enough. Include:
- Vendor name, service description, and contract date.
- Data flow. What PHI touches the vendor, in what direction, in what volume.
- Storage finding. Whether PHI persists on vendor systems, with the source — a written vendor statement, a contract clause, or documentation you can attach.
- Access finding. Whether vendor staff or subcontractors can view PHI, and under what circumstances.
- Conclusion and citation. Your determination, referencing the transient-versus-persistent standard from the Omnibus Rule preamble.
- Signature and date. Privacy Officer or Security Officer, with an annual review date.
Review these memos every year, and immediately whenever a vendor changes its product. A carrier that launches a document-scanning add-on is no longer the vendor you assessed.
A 45-Day Workflow to Close the Gap
Days 1–10 — Build the real vendor list. Pull accounts payable for the last 24 months. Pull the list of every SaaS login your staff uses. Interview the front desk, billing, and whoever manages the fax number. Shadow IT is where most missing BAAs live. Assign: Practice Administrator.
Days 11–20 — Triage. Sort each vendor into three buckets: BAA on file, BAA needed, conduit claim to evaluate. Note the execution date and whether the agreement predates 2013 — old agreements often lack the required Omnibus provisions. Assign: Privacy Officer.
Days 21–35 — Send agreements and questionnaires. Every vendor in bucket two gets an agreement. Every conduit claim gets the four-question script above. Track responses in a single spreadsheet with a due date column. If you don't have a template ready, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which is usually faster than waiting for a vendor to route their own paper through legal.
Days 36–45 — Resolve and document. File executed agreements. Write determination memos for confirmed conduits. For non-responders, decide: escalate, replace, or stop sending PHI. Record the decision either way. Assign: Privacy Officer, with sign-off from the practice owner on any vendor you plan to terminate.
Edge Cases Worth Ruling On This Quarter
Patient-directed email. When a patient asks you to email records to their personal Gmail address, that consumer email provider is not your business associate — the patient directed the disclosure. Document the request. This is not a conduit analysis at all, and conflating the two causes real errors.
Your own email host. Different story entirely. The company hosting your practice's mailboxes stores PHI and is a business associate. Confirm you are on a plan that includes a BAA, not a consumer tier.
Answering services and virtual receptionists. They take messages containing PHI and hold them. Business associate.
Website form and appointment-request tools. If a form collects symptoms or insurance details and stores submissions, the vendor is a business associate. Analytics and advertising trackers on pages that handle PHI raise separate and more serious issues worth their own review.
Once your vendor inventory is clean, the same underlying data feeds your risk analysis and policy set — a full HIPAA compliance document set and risk analysis should reference the vendor list you just built, not a generic one.
Where to Start Tomorrow Morning
Open accounts payable, pick the ten vendors most likely to touch PHI, and check whether a signed agreement exists for each. You will probably find two or three gaps. Send those vendors an agreement the same day, and write a determination memo for anyone who pushes back with a conduit claim.
If drafting the paper is the bottleneck, build your BAA in six steps and export it for signature — then spend your time on the harder work of chasing signatures and documenting the calls you made.