HIPAA Compliance for Business Associates: What Vendors Handling PHI Need in 2026
A business associate meets HIPAA by doing three things: completing a Security Risk Analysis of every system that touches protected health information, signing and tracking a Business Associate Agreement with each covered entity and downstream vendor, and keeping that work current instead of one-and-done. Everything else a vendor is told it “needs” sits on top of those three. This guide covers what the HIPAA Security Rule requires of business associates, what is a proposal and not yet law, and how to pick a platform that fits a healthcare vendor rather than a generic security buyer.
Who counts as a business associate
A business associate is any person or company that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. If a healthcare provider or health plan pays a vendor to handle PHI, that vendor is a business associate under 45 CFR 160.103. Common examples: billing companies, cloud and SaaS platforms used by clinics, IT and managed-service providers, telehealth vendors, transcription and coding services, and analytics firms.
Business associates carry direct liability under the HIPAA Security Rule. Since the Omnibus Rule, the Office for Civil Rights (OCR) can enforce against a business associate directly, not only through the covered entity that hired it.
The three requirements, in order
- Security Risk Analysis (SRA). The Security Rule requires an accurate and thorough analysis of the risks to electronic PHI at 45 CFR 164.308(a)(1)(ii)(A). This applies to business associates in the same way it applies to covered entities. The SRA is the document an auditor, a customer’s security team, or OCR asks for first.
- Business Associate Agreements (BAAs). A business associate needs a signed BAA with each covered entity it serves, and with each subcontractor it passes PHI to. Tracking who signed what, and when each agreement renews, is part of the compliance record.
- Ongoing management. Risk analysis is not a point-in-time task. New systems, new subcontractors, and new PHI flows all change the risk picture, so the analysis and the safeguards behind it need to stay current.
What is required today versus what is proposed
Vendors are being told that “2026 rules” change everything. Here is the accurate position as of 2026:
- A Security Risk Analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). The 2026 proposal, if finalized, would solidify an explicit annual cadence. That cadence is not yet codified law.
- The 2026 HIPAA Security Rule updates are a proposal (a Notice of Proposed Rulemaking), not final and not binding. If finalized as proposed, they would firm up cadence and add specificity around items such as asset inventories and vulnerability scanning. Treat them as direction, not as a deadline that has passed.
Any vendor claiming a 2026 rule is already in force is reading a proposal as law. That is worth verifying before it drives a purchase.
How to choose a compliance platform as a business associate
Business associates get pushed toward broad governance-risk-compliance suites built for enterprise security teams chasing several certifications at once. That fits some vendors. It does not fit most healthcare business associates, whose obligation is specifically HIPAA.
A short, honest way to sort the options:
| Your situation | The better-fit category |
|---|---|
| You need HIPAA, and HIPAA is the obligation your customers ask about | A healthcare-native HIPAA platform (SRA, vendor risk, BAA tracking) |
| You also need SOC 2 and ISO 27001 to close enterprise deals | A multi-framework GRC platform that automates evidence across certifications |
| You are a solo operator with no budget | The free HHS Security Risk Assessment Tool, done manually |
This is the concession that makes the rest credible: if a vendor genuinely needs SOC 2 and ISO 27001 alongside HIPAA, a multi-framework GRC platform is the right tool, and Medcurity is not that tool. Where the obligation is HIPAA, a healthcare-native platform is the closer fit, because it is built around the Security Rule and around the way healthcare organizations really operate.
What healthcare-native looks like in practice
For a business associate whose customers are healthcare organizations, a fitting platform covers:
- A guided Security Risk Analysis mapped to the HIPAA Security Rule and to NIST SP 800-30 risk methodology.
- Vendor risk management for the subcontractors a business associate relies on, so third-party risk is documented rather than assumed.
- BAA lifecycle tracking, so signed agreements and renewals are recorded in one place.
- A Trust Center a business associate can share with its own customers to answer security questionnaires faster.
- Access to a compliance advisor, so a small vendor is not reading the regulation alone.
Medcurity is built for exactly this buyer. The self-service Security Risk Analysis starts at $499 per year for organizations of 1 to 20 full-time employees, with advisory support available when a vendor wants a person alongside the platform. More than 1,000 organizations have worked with Medcurity since 2018.
Frequently asked questions
Does a business associate need its own Security Risk Analysis?
Yes. The Security Rule requires a Security Risk Analysis of every system that creates, receives, maintains, or transmits electronic PHI, and business associates are directly responsible for it under 45 CFR 164.308(a)(1)(ii)(A).
Is a Business Associate Agreement enough on its own?
No. A signed BAA is required, and it is one piece. A business associate still needs the underlying Security Risk Analysis and safeguards that the agreement commits it to.
Do business associates have to comply with the 2026 HIPAA Security Rule changes now?
The 2026 updates are a proposal, not final law. Conducting a Security Risk Analysis is already required today; an explicit annual cadence is part of the 2026 proposal and is not yet binding. Plan for the proposal as direction, and confirm any specific date before treating it as binding.
Does a business associate need SOC 2 or ISO 27001 for HIPAA?
No. SOC 2 and ISO 27001 are separate frameworks. They can help win enterprise deals, and they are not what HIPAA requires. HIPAA compliance for a business associate rests on the Security Risk Analysis, safeguards, and Business Associate Agreements.