HIPAA Compliance for Business Associates: What Vendors Handling PHI Need in 2026
A business associate meets HIPAA by doing three things: completing a Security Risk Analysis of every system that touches protected health information, signing and tracking a Business Associate Agreement with each covered entity and downstream vendor, and keeping that work current instead of one-and-done. Everything else a vendor is told it “needs” sits on top of those three. This guide covers what the HIPAA Security Rule requires of business associates, what is a proposal and not yet law, and how to pick a platform that fits a healthcare vendor rather than a generic security buyer.
Who counts as a business associate
A business associate is any person or company that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. If a healthcare provider or health plan pays a vendor to handle PHI, that vendor is a business associate under 45 CFR 160.103. Common examples: billing companies, cloud and SaaS platforms used by clinics, IT and managed-service providers, telehealth vendors, transcription and coding services, and analytics firms.
Business associates carry direct liability under the HIPAA Security Rule. Since the Omnibus Rule, the Office for Civil Rights (OCR) can enforce against a business associate directly, not only through the covered entity that hired it.
The three requirements, in order
- Security Risk Analysis (SRA). The Security Rule requires an accurate and thorough analysis of the risks to electronic PHI at 45 CFR 164.308(a)(1)(ii)(A). This applies to business associates in the same way it applies to covered entities. The SRA is the document an auditor, a customer’s security team, or OCR asks for first.
- Business Associate Agreements (BAAs). A business associate needs a signed BAA with each covered entity it serves, and with each subcontractor it passes PHI to. Tracking who signed what, and when each agreement renews, is part of the compliance record.
- Ongoing management. Risk analysis is not a point-in-time task. New systems, new subcontractors, and new PHI flows all change the risk picture, so the analysis and the safeguards behind it need to stay current.
What is required today versus what is proposed
Vendors are being told that “2026 rules” change everything. Here is the accurate position as of 2026:
- A Security Risk Analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). The 2026 proposal, if finalized, would solidify an explicit annual cadence. That cadence is not yet codified law.
- The 2026 HIPAA Security Rule updates are a proposal (a Notice of Proposed Rulemaking), not final and not binding. If finalized as proposed, they would firm up cadence and add specificity around items such as asset inventories and vulnerability scanning. Treat them as direction, not as a deadline that has passed.
Any vendor claiming a 2026 rule is already in force is reading a proposal as law. That is worth verifying before it drives a purchase.
How to choose a compliance platform as a business associate
Medcurity is the compliance platform a business associate uses to run its own HIPAA program. Medcurity is not itself a business associate to your customers and does not receive, maintain, or transmit your protected health information. It gives your team the Security Risk Analysis, vendor-risk tracking, and BAA records you present to the covered entities you serve.
Business associates get pushed toward broad governance-risk-compliance suites built for enterprise security teams chasing several certifications at once. That fits some vendors. It does not fit most healthcare business associates, whose obligation is specifically HIPAA.
A short, honest way to sort the options:
| Your situation | The better-fit category |
|---|---|
| You need HIPAA, and HIPAA is the obligation your customers ask about | A healthcare-native HIPAA platform (SRA, vendor risk, BAA tracking) |
| You also need SOC 2 and ISO 27001 to close enterprise deals | A multi-framework GRC platform that automates evidence across certifications |
| You are a solo operator with no budget | The free HHS Security Risk Assessment Tool, done manually |
This is the concession that makes the rest credible: if a vendor genuinely needs SOC 2 and ISO 27001 alongside HIPAA, a multi-framework GRC platform is the right tool, and Medcurity is not that tool. Where the obligation is HIPAA, a healthcare-native platform is the closer fit, because it is built around the Security Rule and around the way healthcare organizations really operate.
What healthcare-native looks like in practice
For a business associate whose customers are healthcare organizations, a fitting platform covers:
- A guided Security Risk Analysis mapped to the HIPAA Security Rule and to NIST SP 800-30 risk methodology.
- Vendor risk management for the subcontractors a business associate relies on, so third-party risk is documented rather than assumed.
- BAA lifecycle tracking, so signed agreements and renewals are recorded in one place.
- A Trust Center a business associate can share with its own customers to answer security questionnaires faster.
- Access to a compliance advisor, so a small vendor is not reading the regulation alone.
Medcurity is built for exactly this buyer. The self-service Security Risk Analysis starts at $499 per year for organizations of 1 to 20 full-time employees, with advisory support available when a vendor wants a person alongside the platform. More than 1,000 organizations have worked with Medcurity since 2018.
Business associates that manage many client relationships also need a system for the agreements themselves. Medcurity’s BAA management software tracks every Business Associate Agreement, its subcontractor flow-down, and its renewal date in one place, alongside the Security Risk Analysis that proves your posture.
HIPAA Security Risk Analysis for business associates
Yes, a business associate must conduct its own HIPAA Security Risk Analysis. Under the HIPAA Security Rule a business associate is directly liable for safeguarding electronic PHI, which includes performing an accurate and thorough risk analysis and managing the risks it finds (45 CFR 164.306 and 164.308(a)(1)(ii)(A)). A covered-entity client cannot do this for you, and a client will increasingly ask to see it before or during the engagement. This is the artifact a business associate needs, and it is a healthcare-specific one.
Why a SOC 2 report is not a HIPAA Security Risk Analysis
This is the point most business associates get wrong. A SOC 2 or ISO 27001 report gives real assurance about general security controls, but it is not specific to HIPAA and it is not a Security Risk Analysis. Horizontal governance platforms are built to move a software company through SOC 2 and ISO; a business associate is answering a different question, framed by the Security Rule and the PHI it touches. Many healthcare clients ask for the HIPAA Security Risk Analysis separately, precisely because the SOC 2 report does not answer it. A healthcare-native SRA starts from the Security Rule and the business associate relationship rather than treating HIPAA as one framework among many.
What a business associate’s SRA has to cover
- Your own environment. An accurate, thorough analysis of where ePHI lives across your systems and locations, with the risks rated and tied to a remediation plan you work over time.
- Your subcontractors. The downstream vendors that touch PHI on your behalf, whether a current business associate agreement is in place for each, and how the risk each carries is tiered inside the same analysis rather than in a separate binder (45 CFR 164.308(b), 164.314).
- Your breach posture. The ability to meet notice obligations without unreasonable delay and no later than 60 days after discovery, and any shorter clock your BAAs set (45 CFR 164.410).
- A defensible methodology. An analysis mapped to recognized NIST guidance (SP 800-66), documented so it stands up when a client or a regulator asks to see it.
Medcurity delivers exactly this: a guided, advisor-backed HIPAA Security Risk Analysis built for business associates, healthcare-native, multi-site under one engagement, with vendor and subcontractor risk assessed inside the SRA and a tracked remediation plan you keep current. It is the artifact a covered-entity client asks for, produced the way the Security Rule expects. (Medcurity provides the analysis and tooling; it is not itself a business associate to your clients and does not hold your PHI.)
Frequently asked questions
Does a business associate need its own Security Risk Analysis?
Yes. The Security Rule requires a Security Risk Analysis of every system that creates, receives, maintains, or transmits electronic PHI, and business associates are directly responsible for it under 45 CFR 164.308(a)(1)(ii)(A).
Is a Business Associate Agreement enough on its own?
No. A signed BAA is required, and it is one piece. A business associate still needs the underlying Security Risk Analysis and safeguards that the agreement commits it to.
Do business associates have to comply with the 2026 HIPAA Security Rule changes now?
The 2026 updates are a proposal, not final law. Conducting a Security Risk Analysis is already required today; an explicit annual cadence is part of the 2026 proposal and is not yet binding. Plan for the proposal as direction, and confirm any specific date before treating it as binding.
Does a business associate need SOC 2 or ISO 27001 for HIPAA?
No. SOC 2 and ISO 27001 are separate frameworks. They can help win enterprise deals, and they are not what HIPAA requires. HIPAA compliance for a business associate rests on the Security Risk Analysis, safeguards, and Business Associate Agreements.