Business associates of covered entities (health care plans and certain health care providers) are directly liable for HIPAA violations. HHS has a Fact Sheet laying out the violations that can trigger liability (e.g., taking retaliatory action against an individual filing a HIPAA complaint). Business associates are persons or entities that perform certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity (e.g., a CPA firm whose accounting services to a health care provider involve access to protected health information).