For business associates
HIPAA compliance for business associates
You signed a Business Associate Agreement with a healthcare client. That signature didn’t just make them a promise — it put your business under HIPAA’s Security Rule, directly. HIPAAPath is a free, guided risk assessment in plain English: the written, dated risk analysis regulators ask for first, without a consultant.
What’s a business associate?
If your company touches protected health information (PHI) while doing work for a healthcare provider or health plan, HIPAA calls you a business associate. Medical billing and coding companies. CPA and accounting firms whose engagements include patient-level records. IT providers that manage practice systems. Attorneys who serve healthcare organizations. Records-storage and shredding vendors.
The BAA your client asked you to sign is the contract half. The federal half is that the HIPAA Security Rule applies to your business directly (45 CFR §164.104(b)) — the same safeguard standards your client is held to, enforced against business associates by name.
A signed BAA is not a compliance program
Most business associates signed the BAA years ago — the client wouldn’t share files until they did — and filed it away. But a BAA is a promise to have safeguards, not evidence that you do. When OCR (the federal HIPAA enforcer, the HHS Office for Civil Rights) investigates a breach at a business associate, the first document it requests is the risk analysis: your written, dated look at where PHI lives in your business and what could go wrong with it. Settlement after settlement against business associates cites the same gap — not exotic hacking failures, just no documented risk analysis.
Why this is getting louder
- The breach numbers moved. Business associates accounted for about 30% of the healthcare data breaches reported to HHS in 2024 (breaches affecting 500 or more people), about 36% in 2025, and 43% in the first half of 2026. Counted by people affected, the shift is starker: roughly 5% of affected individuals traced to business associates in 2015 — by 2025, the year of the Change Healthcare fallout, it was 65%. Attackers found the middle of the supply chain.
- The rules are catching up. The proposed update to the HIPAA Security Rule would require business associates to hand their healthcare clients an annual written verification of deployed safeguards, notify them within 24 hours of activating a contingency plan, and make encryption and multi-factor authentication mandatory. To be clear: it is proposed, not final — the final rule is currently expected around July 2027, and nothing new is required of you today. But the businesses that will find that paperwork easy are the ones whose documentation already exists.
- Your own insurance asks. If you carry cyber insurance, your application already asks whether you handle personal health information and how it’s protected. A documented answer beats a hopeful one.
What the Security Rule actually asks of you
- A documented risk analysis, reviewed and updated on a schedule — the artifact every enforcement action starts with.
- Administrative, physical, and technical safeguards scaled to your size — encryption, access controls, backups, and the habits around them.
- Written policies and training your staff actually follows.
- Breach duties that run upstream: if you discover a breach, you notify your affected healthcare clients without unreasonable delay — 60 days at the outside (45 CFR §164.410). Their notification clocks start after yours.
None of it requires enterprise software. All of it requires being written down.
Where HIPAAPath fits — and an honest note
HIPAAPath is a free, guided HIPAA Security Rule risk assessment: plain-English questions, one at a time, ending in a documented risk analysis and a security manual you keep. Your answers stay in your browser — they never touch our servers.
The honest note: HIPAAPath was built first for small healthcare practices, and today the walkthrough speaks in their voice — you’ll see “your patient records” where you’d say “the PHI our clients trust us with.” The safeguards it documents are the same ones the Security Rule requires of business associates. A business-associate edition that speaks your language is on our roadmap — if you want it sooner, say so: hello@hipaapath.com.
Guides for your industry
- Medical billing & coding companies→
The canonical business associate — claims, remittances, and patient records all day. What OCR settlements against billing companies keep citing, and what to have on file.
- CPA & accounting firms→
If your engagements for healthcare clients touch patient-level records, HIPAA applies to your firm. OCR has now settled with an accounting firm for the first time.
Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.