HIPAA Security Risk Assessment for Business Associates

If your company signs Business Associate Agreements with healthcare clients, you are directly liable under the HIPAA Security Rule, and a signed BAA is not proof that you have met that obligation. MSPs, billing companies, SaaS vendors, telehealth platforms, IT providers, and consultants who touch protected health information all carry this exposure. This page covers what the Security Rule requires of a business associate, what covered entities are starting to ask for before they will sign, and how Medcurity’s self-serve Business Associate Security Risk Assessment gets you documented before year-end.

Why business associates are liable directly, not just by contract

Since the 2013 Omnibus Rule, the HIPAA Security Rule applies to business associates directly. The Office for Civil Rights (OCR) can investigate and enforce against a business associate on its own, not only through the covered entity that hired it. The requirement that drives most enforcement findings is a Security Risk Analysis: an accurate and thorough assessment of the risks to electronic protected health information, required at 45 CFR 164.308(a)(1)(ii)(A). That requirement applies to a business associate’s own systems and vendors, the same way it applies to a covered entity’s.

A Business Associate Agreement is the contract. The Security Risk Analysis, along with the administrative, physical, and technical safeguards it points to, is the work the contract commits you to actually doing.

What covered entities are asking vendors to produce

A signed BAA used to be where a security review stopped. Increasingly, it is where the review starts. Covered entities, especially hospitals and health systems with a formal vendor risk program, are asking business associates for evidence: a current Security Risk Analysis, documented safeguards, and a posture they can verify without another round of emails. A vendor that can produce that evidence closes procurement faster than one that promises to get to it.

That shift is also where the 2026 proposed HIPAA Security Rule update points. The Notice of Proposed Rulemaking (NPRM) published by the HHS Office for Civil Rights would, among other changes, require covered entities to obtain written verification that their business associates have actually implemented required technical safeguards. The NPRM has not been finalized. Treat it as the direction vendor oversight is heading, not as a requirement in force today.

Medcurity’s Business Associate Security Risk Assessment

Medcurity offers a self-serve Business Associate SRA with policies starting at $799 per year for organizations with 1 to 20 employees, priced separately from the $499 Small Practice SRA, which is built for covered entities rather than vendors. You work through the assessment on your own schedule, on the same methodology and policy library Medcurity’s compliance specialists use with hospitals and health centers, with a specialist available when a question about your environment does not have a clean answer.

Start self-serve today: Register for the Business Associate SRA and begin your assessment immediately.

Want a specialist alongside you instead? For larger vendor teams or organizations that want a guided, expert-led engagement, request a demo and we will scope the right option for your size and complexity.

Show your posture without answering the same questionnaire twice

Once your SRA is complete, the next question is how you prove it to every covered entity you serve. Medcurity’s Trust Center lets a business associate publish its posture once and share a single link, backed by the real assessment behind it rather than a spreadsheet a customer’s security team has to take on faith. When your program changes, the Trust Center updates with it.

Track every BAA in one place, including the ones behind you

A business associate needs a signed BAA with every covered entity it serves, and with every subcontractor it passes protected health information to. Vendor risk management keeps that inventory in one place: which agreements are current, which are expiring, and which subcontractors sit behind you, so nothing lapses quietly and nothing has to be reconstructed from email when a customer asks.

Start this week. Audit-ready before December 31.

A self-serve Business Associate SRA started today is realistic to finish before the calendar turns. Register now, work through the assessment at your own pace, and go into next year’s contract renewals and security reviews with documentation in hand instead of a promise to get to it.

Register for the Business Associate SRA or request a demo to talk through timing first.

Frequently asked questions

Does signing a BAA make my company HIPAA compliant?

No. A Business Associate Agreement is a required contract, and it is one piece. It does not, by itself, demonstrate that you have conducted a Security Risk Analysis or implemented the safeguards the Security Rule requires. Compliance is the work behind the agreement, not the agreement itself.

Do business associates need their own Security Risk Analysis?

Yes. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough risk analysis of every system that creates, receives, maintains, or transmits electronic protected health information, and business associates have been directly responsible for meeting it since the 2013 Omnibus Rule.

What do covered entities typically ask a vendor to produce?

Most commonly: a signed BAA, evidence of a current Security Risk Analysis, documented policies and safeguards, and increasingly a way to verify that posture without a lengthy back-and-forth, such as a published Trust Center profile.

How fast can a business associate finish an SRA?

The self-serve Business Associate SRA is built to be worked through on your own schedule, with a specialist available for questions along the way. A small vendor starting now can reasonably finish and be documented well ahead of year-end.

Do we need SOC 2 or ISO 27001 instead of a HIPAA SRA?

Not for HIPAA. SOC 2 and ISO 27001 are separate frameworks that can help close enterprise deals, but they are not what the Security Rule requires. A business associate’s HIPAA obligation rests on the Security Risk Analysis, safeguards, and Business Associate Agreements, regardless of what other certifications you also pursue.