HIPAA Compliance for Business Associates: What Vendors Handling PHI Need in 2026

A business associate meets HIPAA by doing three things: completing a Security Risk Analysis of every system that touches protected health information, signing and tracking a Business Associate Agreement with each covered entity and downstream vendor, and keeping that work current instead of one-and-done. Everything else a vendor is told it “needs” sits on top of those three. This guide covers what the HIPAA Security Rule requires of business associates, what is a proposal and not yet law, and how to pick a platform that fits a healthcare vendor rather than a generic security buyer.

Who counts as a business associate

A business associate is any person or company that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. If a healthcare provider or health plan pays a vendor to handle PHI, that vendor is a business associate under 45 CFR 160.103. Common examples: billing companies, cloud and SaaS platforms used by clinics, IT and managed-service providers, telehealth vendors, transcription and coding services, and analytics firms.

Business associates carry direct liability under the HIPAA Security Rule. Since the Omnibus Rule, the Office for Civil Rights (OCR) can enforce against a business associate directly, not only through the covered entity that hired it.

The three requirements, in order

  1. Security Risk Analysis (SRA). The Security Rule requires an accurate and thorough analysis of the risks to electronic PHI at 45 CFR 164.308(a)(1)(ii)(A). This applies to business associates in the same way it applies to covered entities. The SRA is the document an auditor, a customer’s security team, or OCR asks for first.
  2. Business Associate Agreements (BAAs). A business associate needs a signed BAA with each covered entity it serves, and with each subcontractor it passes PHI to. Tracking who signed what, and when each agreement renews, is part of the compliance record.
  3. Ongoing management. Risk analysis is not a point-in-time task. New systems, new subcontractors, and new PHI flows all change the risk picture, so the analysis and the safeguards behind it need to stay current.

What is required today versus what is proposed

Vendors are being told that “2026 rules” change everything. Here is the accurate position as of 2026:

Any vendor claiming a 2026 rule is already in force is reading a proposal as law. That is worth verifying before it drives a purchase.

How to choose a compliance platform as a business associate

Business associates get pushed toward broad governance-risk-compliance suites built for enterprise security teams chasing several certifications at once. That fits some vendors. It does not fit most healthcare business associates, whose obligation is specifically HIPAA.

A short, honest way to sort the options:

Your situationThe better-fit category
You need HIPAA, and HIPAA is the obligation your customers ask aboutA healthcare-native HIPAA platform (SRA, vendor risk, BAA tracking)
You also need SOC 2 and ISO 27001 to close enterprise dealsA multi-framework GRC platform that automates evidence across certifications
You are a solo operator with no budgetThe free HHS Security Risk Assessment Tool, done manually

This is the concession that makes the rest credible: if a vendor genuinely needs SOC 2 and ISO 27001 alongside HIPAA, a multi-framework GRC platform is the right tool, and Medcurity is not that tool. Where the obligation is HIPAA, a healthcare-native platform is the closer fit, because it is built around the Security Rule and around the way healthcare organizations really operate.

What healthcare-native looks like in practice

For a business associate whose customers are healthcare organizations, a fitting platform covers:

Medcurity is built for exactly this buyer. The self-service Security Risk Analysis starts at $499 per year for organizations of 1 to 20 full-time employees, with advisory support available when a vendor wants a person alongside the platform. More than 1,000 organizations have worked with Medcurity since 2018.

Frequently asked questions

Does a business associate need its own Security Risk Analysis?

Yes. The Security Rule requires a Security Risk Analysis of every system that creates, receives, maintains, or transmits electronic PHI, and business associates are directly responsible for it under 45 CFR 164.308(a)(1)(ii)(A).

Is a Business Associate Agreement enough on its own?

No. A signed BAA is required, and it is one piece. A business associate still needs the underlying Security Risk Analysis and safeguards that the agreement commits it to.

Do business associates have to comply with the 2026 HIPAA Security Rule changes now?

The 2026 updates are a proposal, not final law. Conducting a Security Risk Analysis is already required today; an explicit annual cadence is part of the 2026 proposal and is not yet binding. Plan for the proposal as direction, and confirm any specific date before treating it as binding.

Does a business associate need SOC 2 or ISO 27001 for HIPAA?

No. SOC 2 and ISO 27001 are separate frameworks. They can help win enterprise deals, and they are not what HIPAA requires. HIPAA compliance for a business associate rests on the Security Risk Analysis, safeguards, and Business Associate Agreements.