Vertical guide

HIPAA for business associates & vendors

You handle PHI for healthcare customers — which makes you directly liable under HIPAA. Here's the vendor playbook.

Your reality

Since HITECH, business associates are directly liable for Security Rule compliance and can be audited and penalized by OCR themselves. "We're just the vendor" is not a defense — and your customers' assessors will examine your controls as part of their program.

The vendor playbook

  1. Sign BAAs before touching PHI — with every customer, and with every one of your subcontractors that touches it.
  2. Run your own risk analysis. Your customers' analysis doesn't cover your systems. You need your own, current, documented.
  3. Build the evidence pack once. Risk analysis, policies, training records, pen test, SOC 2 if customers require it — one package answers every security questionnaire.
  4. Publish your subprocessor list. Enterprise customers ask; having it ready shortens every security review.
  5. Don't promise customers compliance. You can't certify them — and there's no HIPAA certification anyway. Sell safeguards and evidence, not outcomes.
The flow-down rule. Your customers flow HIPAA requirements to you; you must flow them to your subcontractors. A break anywhere in the chain is a finding everywhere above it.

Deeper explainer: Business Associate Agreements, done right.

Get quotes for your BA program

Matched assessors experienced with vendor environments. Free, 2 minutes.

Get a free quote