For CPA & accounting firms

HIPAA compliance for CPA firms with healthcare clients

You signed the Business Associate Agreement because your healthcare client’s checklist required it. The part nobody said out loud: that signature put your firm under HIPAA’s Security Rule — directly, as federal law, separate from anything the contract says.

A first that got the profession’s attention

OCR — the federal HIPAA enforcer — has now settled with an accounting firm for the first time. BST & Co. CPAs, a regional firm of roughly 530 people, agreed to a $175,000 settlement after a breach investigation.

Precision matters here, so, precisely: it was a settlement, not a fine. It is a first, not a pattern — one case does not mean OCR is coming for accounting firms. And the failure was ordinary: the firm had signed BAAs with healthcare clients, and the investigation found the risk analysis HIPAA requires had never been documented. What the case ends is the era when “no accounting firm has ever been cited” could quietly stand in for a compliance program.

When accounting work makes you a business associate

Not every engagement does — and firms that think in engagement scopes deserve a precise answer. Preparing a provider’s tax return from aggregate financials generally involves no patient information. But the moment an engagement touches patient-level records — audit work that samples billing detail, revenue-cycle or practice-management consulting, valuation work built on patient schedules, forensic work in a provider’s systems — your firm is handling protected health information on a covered entity’s behalf. That is the definition of a business associate, and the Security Rule’s safeguard requirements attach to your firm by name.

The awkward middle most firms are in

The typical position: BAAs signed and filed, a HIPAA question or two answered on the firm’s own cyber-insurance application, and no written program behind either. The market has mostly offered two ways out — a $15–99 training video that produces a certificate but not a program, or a consulting engagement quoted in the thousands and scoped for organizations far larger than a local firm. Between those two: not much. That gap is exactly where HIPAAPath sits — a guided, documented risk assessment, free to complete, no sales call.

What your firm needs on file

  • A documented risk analysis — the artifact the BST investigation found missing, and the first thing any investigation requests.
  • Safeguards, written down: encryption on the laptops that leave the office, multi-factor authentication, and access controls — who at the firm can open a healthcare client’s files, and why.
  • Policies and training records for the staff on those engagements, dated.
  • A breach plan that runs upstream: business associates must notify affected healthcare clients without unreasonable delay — 60 days at the outside (45 CFR §164.410).

Your own insurance already circles this: cyber and E&O applications ask whether the firm handles personal health information and how it’s protected. A documented answer beats a hopeful one. And the proposed HIPAA Security Rule update — not final, currently expected around July 2027 — would add an annual written verification of safeguards that healthcare clients collect from their business associates. More on what’s changing for business associates →

Where HIPAAPath fits — and an honest note

HIPAAPath walks you through a HIPAA Security Rule risk assessment in plain English, one question at a time, and ends in a documented risk analysis and a security manual your firm keeps. It’s free to complete, and your answers stay in your browser — they never touch our servers, which is a sentence your engagement letters will appreciate.

The honest note: HIPAAPath was built first for small healthcare practices, so today’s walkthrough says “your patient records” where you’d say “client engagement files.” The safeguards it documents are the same ones the Security Rule requires of your firm as a business associate. An edition that speaks accounting is on our roadmap — want it sooner? Tell us: hello@hipaapath.com.

Start HIPAAPath free

Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your firm’s specific obligations, talk to a healthcare attorney.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.