DEV Community

Joe Gellatly
Joe Gellatly

Posted on Originally published at medcurity.com

If You're a Healthcare Vendor, a Signed BAA Is the Start of Your HIPAA Job, Not the End

If your company handles protected health information for healthcare clients, you are a business associate, and your clients are starting to ask a harder question than "will you sign a BAA?" They want to see your current HIPAA Security Risk Analysis, your safeguards, and your evidence between assessments. That shift is why the vendors who used to compete on "we're compliant" are now competing on "here is proof, on demand."

This is where a lot of horizontal compliance tooling quietly stops fitting the healthcare vendor.

Business associates carry the Security Rule directly, not by reflection

A business associate is not covered by a client's compliance program. Business associates are directly responsible for complying with the HIPAA Security Rule, including implementing administrative, physical, and technical safeguards for ePHI (45 CFR 164.306). That includes a real Security Risk Analysis: HIPAA requires a current Security Risk Analysis, updated after any significant change to your environment, and it does not set an annual deadline (45 CFR 164.308(a)(1)(ii)(A)).

A signed Business Associate Agreement sits on top of that obligation. A BAA is a contract that documents a promise to safeguard PHI (45 CFR 164.308(b)). It does not verify that the safeguards exist, and it does not perform your risk analysis for you. The vendors losing deals right now are the ones who treated the signature as the finish line.

SOC 2 is a strong report. It is not a HIPAA Security Risk Analysis.

This is the most common place healthcare vendors get caught flat. Does SOC 2 replace a HIPAA Security Risk Analysis? No. SOC 2 provides valuable assurance about an organization's controls, but it is not specific to HIPAA. Many healthcare clients request a HIPAA Security Risk Analysis separately. A tool built to shepherd a SaaS company through SOC 2 and ISO 27001 is built for a different question than "does this BAA cover our new AI scribe, and where does that vendor sit in our HIPAA risk picture?"

Healthcare-native tooling starts from the Security Rule and the business associate relationship instead of bolting HIPAA on as one framework among many.

The four things a healthcare client now expects a business associate to show

  1. A current, HIPAA-specific Security Risk Analysis of the ePHI you hold or move, documented well enough to hand over on request.
  2. Vendor and BAA tracking, so you can answer who your own subcontractors are, whether each BAA is current, and how you tier that risk. Third-party risk management is not a side binder; the cleanest programs make vendor risk one chapter of the SRA rather than a parallel workstream nobody opens.
  3. Evidence between assessments, not just at renewal. A business associate that can show external scanning, a branded trust page, and questionnaire-response support looks materially different from one that goes quiet for eleven months.
  4. A defensible breach posture. A business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery (45 CFR 164.410). Your BAA may set a shorter contractual clock, and many require notice within 24 hours, so your process has to be built for the tightest clock you have signed, not the statutory maximum.

Where Medcurity fits

Medcurity is built for healthcare organizations specifically, including the business associates that serve them. In one place a business associate gets a guided HIPAA Security Risk Analysis designed for business associates, vendor and BAA tracking, policy management, and a Business Associate Trust Page that shows clients what you are doing between assessments. The report documents your work rather than presenting a certificate or pass, which is exactly the artifact a covered-entity client is asking to see.

If you want the business associate walkthrough, it lives here: https://medcurity.com/hipaa-compliance-solutions/business-associate-sra/. If you would rather talk it through, reach us at https://medcurity.com/contact/explore-medcurity-solutions/.

The healthcare vendors who win the next renewal are not the ones with the most signatures in a drawer. They are the ones who can show, on any given day, exactly what they are doing to protect the data their clients handed them.

Top comments (0)