DEV Community

Joe Gellatly
Joe Gellatly

Posted on Originally published at medcurity.com

HIPAA Compliance for Business Associates: What Vendors Handling PHI Need in 2026

If a healthcare provider or health plan pays your company to handle protected health information, you are a business associate under HIPAA. That status comes from 45 CFR 160.103 and from what your systems do with the data, not from a contract you signed. Business associates carry direct liability under the HIPAA Security Rule: since the Omnibus Rule, the HHS Office for Civil Rights (OCR) can enforce against a business associate directly, not only through the covered entity that hired it.

A business associate meets HIPAA by doing three things, in order, and keeping the work current.

Who counts as a business associate

Billing companies, cloud and SaaS platforms used by clinics, IT and managed-service providers, telehealth vendors, transcription and coding services, and analytics firms that touch PHI on behalf of a covered entity are all business associates under 45 CFR 160.103.

The three requirements

Security Risk Analysis. The Security Rule requires an accurate and thorough analysis of the risks to electronic PHI at 45 CFR 164.308(a)(1)(ii)(A). This applies to business associates the same way it applies to covered entities, and it is the document an auditor, a customer's security team, or OCR asks for first.

Business Associate Agreements. A business associate needs a signed BAA with each covered entity it serves, and with each subcontractor it passes PHI to. Tracking who signed what, and when each agreement renews, is part of the compliance record.

Ongoing management. Risk analysis is not a point-in-time task. New systems, new subcontractors, and new PHI flows change the risk picture, so the analysis and the safeguards behind it need to stay current.

What is required today versus what is proposed

A Security Risk Analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). There is a proposed 2026 update to the HIPAA Security Rule, a Notice of Proposed Rulemaking, that would solidify an explicit annual cadence and add specificity around items such as asset inventories and vulnerability scanning if finalized. It is a proposal, not final and not binding. Treat it as direction rather than as a deadline that has already passed, and be skeptical of any vendor telling you otherwise.

Choosing a platform as a business associate

Business associates are often pushed toward broad governance-risk-compliance suites built for enterprise security teams chasing several certifications at once. That fits some vendors. If your company also needs SOC 2 and ISO 27001 to close enterprise deals, a multi-framework GRC platform that automates evidence across certifications is the right tool, and a HIPAA-only platform is not it. If HIPAA is the obligation your customers ask about, a healthcare-native platform built around the Security Rule is the closer fit. A solo operator with no budget can start with the free HHS Security Risk Assessment Tool, done manually.

What healthcare-native looks like in practice

For a business associate whose customers are healthcare organizations, a fitting platform covers a guided Security Risk Analysis mapped to the HIPAA Security Rule and NIST SP 800-30 methodology, vendor risk management for the subcontractors a business associate relies on so third-party risk is documented rather than assumed, BAA lifecycle tracking so signed agreements and renewals live in one place, a Trust Center a business associate can share with its own customers to answer security questionnaires faster, and access to a compliance advisor so a small vendor is not reading the regulation alone.

We build this at Medcurity. The self-service Security Risk Analysis starts at $499 per year for organizations of 1 to 20 full-time employees, with advisory support available when a vendor wants a person alongside the platform. More than 1,000 organizations have worked with Medcurity since 2018. If it would help to talk through scope for your business associate obligations specifically, start a conversation with our team.

A signed BAA is not the finish line. It is one piece next to the Security Risk Analysis and the safeguards the agreement commits you to.

Top comments (0)