DEV Community

Joe Gellatly
Joe Gellatly

Posted on

Third-Party Risk Management for Healthcare Vendors: Running the BAA Lifecycle, Not Just Signing It

Search for compliance tooling for business associates and the results fill with horizontal vendor-risk and governance platforms built to run third-party risk for software companies chasing SOC 2 and ISO 27001. Those tools are good at what they were made for. A healthcare vendor, though, is answering a different question than a general SaaS company, and the difference shows up the moment a covered-entity client stops asking "will you sign a Business Associate Agreement?" and starts asking "show me your current Security Risk Analysis, your subcontractor list, and what you have done since the last one."

That shift is why a signature is no longer the deliverable. The deliverable is a lifecycle.

A Business Associate Agreement is the start of the work, not the end of it

A signed Business Associate Agreement is a promise. A BAA is a contract that documents a promise to safeguard PHI (45 CFR 164.308(b)). It does not verify that the safeguards exist, it does not perform your risk analysis, and it does not track the subcontractors who touch the data after you do. Treating the signature as the finish line is the single most common reason a healthcare vendor gets caught flat at renewal.

The vendors who keep their clients run the agreement as a lifecycle with four repeating stages: collect the BAA and the vendor, assess the risk each one carries, monitor the safeguards between assessments, and renew before the coverage or the risk picture goes stale. Generic tooling tends to handle the first stage, store the document, and go quiet on the other three.

Business associates carry the Security Rule directly

A business associate is not covered by a client's compliance program. Business associates are directly responsible for complying with the HIPAA Security Rule, including implementing administrative, physical, and technical safeguards for ePHI (45 CFR 164.306). That includes a real Security Risk Analysis. HIPAA requires a current Security Risk Analysis, updated after any significant change to your environment, and it does not set an annual deadline (45 CFR 164.308(a)(1)(ii)(A)).

Vendor risk sits inside that obligation rather than beside it. The subcontractors you rely on, the AI scribe you added last quarter, the cloud service that now stores a copy of a client's records: each is a place PHI can reach, and each belongs in the same risk picture as your own systems. The cleanest programs make third-party risk one chapter of the Security Risk Analysis rather than a parallel binder nobody opens.

Third-party risk for a healthcare vendor is not a generic questionnaire

Horizontal vendor-risk management scores suppliers against a general control library. Healthcare third-party risk has to answer a narrower question: does this subcontractor's handling of PHI keep you defensible under the Security Rule, and is that risk tiered and documented well enough to hand a client on request. That means tracking which subcontractors touch PHI, whether each downstream BAA is current, and how you rank the risk each one carries, all tied back to the assessment rather than kept in a separate spreadsheet.

A healthcare-native approach starts from the Security Rule and the business associate relationship instead of bolting HIPAA on as one framework among many.

SOC 2 is a strong report. It is not a HIPAA Security Risk Analysis.

This is the place healthcare vendors most often assume they are covered when they are not. SOC 2 provides valuable assurance about an organization's controls, but it is not specific to HIPAA. Many healthcare clients request a HIPAA Security Risk Analysis separately. A platform built to shepherd a SaaS company through SOC 2 and ISO 27001 is built for a different question than "does this BAA cover our new subcontractor, and where does that vendor sit in our HIPAA risk picture?"

A defensible breach posture across your vendors

Your obligations do not stop at your own perimeter. A business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery (45 CFR 164.410). A business associate agreement may set a shorter contractual clock, and many require notice within 24 hours, so your process has to be built for the tightest clock you have signed, not the statutory maximum. When the breach originates with a subcontractor, the vendor tracking you kept all year is what lets you find the exposure and meet that clock instead of reconstructing the relationship under pressure.

On the 2026 Security Rule

The proposed 2026 HIPAA Security Rule updates would, if finalized as proposed, strengthen several requirements, including firmer expectations around vendor and subcontractor management. As of this writing the proposal is not final and is not law. The risk analysis and the safeguards described above are already required under the current Security Rule, so a business associate acting today is meeting a present obligation rather than preparing for a hypothetical one. Any vendor telling you the 2026 changes are already mandatory is describing a proposal as settled law.

Where the honest lines fall

No single tool is right for every vendor. A software company whose first and hardest audit is SOC 2, with no healthcare clients yet, is well served by a horizontal governance platform built for that path. A very small vendor with almost no budget can begin with the free HHS Security Risk Assessment Tool and the plain text of the Security Rule and grow from there.

For a healthcare vendor whose clients are covered entities, who carries the Security Rule directly, and who has to show subcontractor risk and evidence on demand, the fit is a healthcare-native program that treats the BAA as a lifecycle rather than a stored PDF.

Where Medcurity fits

Medcurity is built for healthcare organizations and the business associates that serve them. It is not itself a business associate and holds no PHI. In one place a business associate gets a guided HIPAA Security Risk Analysis designed for business associates, vendor and BAA tracking as a real part of the assessment rather than a side workstream, third-party risk management scoped to healthcare, and a Business Associate Trust Page that shows clients what you are doing between assessments. The report documents your work rather than presenting a certificate or a pass, which is the artifact a covered-entity client is asking to see.

If you want the business associate walkthrough, it lives at the business associate Security Risk Analysis on medcurity.com. If you would rather talk it through, reach us through the contact page at medcurity.com.

The healthcare vendors who win the next renewal are not the ones with the most signatures in a drawer. They are the ones who can show, on any given day, exactly what they are doing to protect the data their clients handed them, and where every downstream vendor sits in that picture.


Authority references (outbound, nofollow): HHS Office for Civil Rights guidance on the Security Rule and business associates; the Security Rule text at eCFR 45 CFR Part 164; NIST SP 800-66.

Top comments (0)