HIPAA Times news | Concise, reliable news and insights on HIPAA compliance and regulations

Is Automation Anywhere HIPAA compliant? (2025 update)

Written by Caitlin Anthoney | Sep 17, 2025 9:21:51 PM

Based on our research, Automation Anywhere is HIPAA compliant because it meets the requirements set by the U.S. Department of Health and Human Services (HHS) to safeguard protected health information (PHI).

 

What is Automation Anywhere?

Automation Anywhere is a robotic process automation (RPA) platform that helps organizations automate workflows, reduce manual tasks, and improve efficiency across industries, including healthcare.

 

Will Automation Anywhere sign a business associate agreement (BAA)?

Yes, Automation Anywhere will sign a business associate agreement, which can be reviewed here.

 

What does the Automation Anywhere BAA cover?

Automation Anywhere provides a formal Business Associate Agreement that governs its handling of PHI. 

The agreement states, “This Business Associate Agreement (the ‘Agreement’) is made and entered into by and between (‘Covered Entity’) and Automation Anywhere, Inc. (‘Business Associate’) as of the effective date of the Agreement. The business relationship between Business Associate and Covered Entity may involve the use and disclosure of health information that is considered PHI (as defined below) and is protected by federal law. Therefore, to the extent that such PHI is shared between the parties, this Agreement shall apply and shall set forth the party’s obligations with respect to such PHI.”

Their BAA covers:

  • Protection of PHI.
  • Use and disclosure of PHI only as permitted by law or contract.
  • Application of minimum necessary standards.
  • Implementation of administrative, physical, and technical safeguards.
  • Compliance with the HIPAA Privacy, Security, and Breach Notification Rules.
  • Breach reporting within 30 days.
  • Subcontractor compliance requirements.
  • Access and amendment rights for PHI.
  • Return or destruction of PHI upon termination of the agreement.

 

What does the Automation Anywhere BAA exclude?

The Automation Anywhere BAA does not appear to exclude common HIPAA obligations. However, like many BAAs, it does not permit use of the platform for activities outside of legal or contractual requirements. The agreement also clarifies, “Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule or the Security Rule if done by Covered Entity.”

Therefore, while the platform can process PHI, it cannot be used for direct treatment functions or for purposes not allowed under HIPAA.

 

Conclusion

Automation Anywhere signs a BAA, and as a result, is HIPAA compliant.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a business associate agreement?

A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.

 

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI). HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.