- HIPAA
- Healthcare
HIPAA vendor risk assessment: vetting business associates under the Security Rule
Updated 8 min read
If you are a covered entity or a business associate, every vendor that touches protected health information on your behalf extends your HIPAA exposure. The Security Rule does not let you hand ePHI to a vendor on trust: it asks for written assurances, and your own risk analysis has to account for where that data goes. A HIPAA vendor risk assessment is how you decide, and later show, that those assurances were reasonable.
This guide covers who counts as a business associate, what the regulations require, what a business associate agreement must say, a checklist by risk tier, the evidence worth requesting, breach notification timing and reassessment. It is general information, not legal advice; have counsel review your BAA template and anything unusual.
Who is a business associate
Under 45 CFR 160.103, a business associate is a person or entity that, on behalf of a covered entity, creates, receives, maintains or transmits protected health information for a regulated function, or provides certain services (legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial) that involve disclosure of PHI. Typical examples:
- EHR, practice management, billing and claims processing platforms;
- cloud hosting, backup and storage providers holding ePHI;
- managed IT and security providers with access to systems that hold ePHI;
- transcription, coding, collections and patient communication services;
- law firms, accountants and consultants who see PHI in the course of their work.
Some parties are not business associates: your own workforce, providers receiving PHI for treatment, and conduits that only transmit data without storing it (a courier, an internet service provider). The conduit exception is narrow. A vendor that stores ePHI is a business associate even if the data is encrypted and it holds no key.
Subcontractors are business associates too
When a business associate delegates work involving PHI to another company, that subcontractor is itself a business associate, directly liable for complying with the Security Rule. Your billing vendor’s cloud host, its offshore support contractor and its email provider may all sit in the chain. You contract with your business associate; your business associate must contract with its subcontractors on equivalent terms. Your assessment should ask who they are.
What the Security Rule requires
Three provisions carry most of the weight.
| Provision | What it says | What it means for vendors |
|---|---|---|
| 45 CFR 164.308(b) | A covered entity may let a business associate create, receive, maintain or transmit ePHI only with satisfactory assurances that it will appropriately safeguard the information. A business associate must obtain the same from its subcontractors. | No ePHI flows to a vendor before assurances are in place, and they must be documented. |
| 45 CFR 164.314(a) | The assurances take the form of a contract (or, between government entities, another arrangement) meeting specific requirements. | The BAA is the required documentation, and its terms are prescribed, not optional. |
| 45 CFR 164.308(a)(1)(ii)(A) | Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI you hold. | Your risk analysis should cover ePHI sent to or held by vendors, not just your own systems. |
The regulations do not require you to audit each business associate. They do require assurances you can stand behind, and under the Privacy Rule (45 CFR 164.504(e)(1)(ii)), if you know of a pattern of activity that amounts to a material breach of the BAA, you must take reasonable steps to cure it or end the arrangement. A documented assessment is what makes “satisfactory” defensible.
What a BAA must contain
At a high level, 45 CFR 164.504(e) and 164.314(a) require the agreement to:
- establish the permitted and required uses and disclosures of PHI;
- bar other uses or disclosures except as the contract permits or law requires;
- require appropriate safeguards, including compliance with the Security Rule for ePHI;
- require reporting of uses or disclosures not permitted by the contract, security incidents, and breaches of unsecured PHI;
- require subcontractors to agree to the same restrictions and conditions;
- support individuals’ rights of access, amendment and an accounting of disclosures;
- make internal practices, books and records available to HHS;
- require return or destruction of PHI at termination, where feasible;
- allow termination if the business associate violates a material term.
HHS publishes sample BAA provisions, which are a reasonable baseline. The terms worth negotiating are usually the ones the regulation leaves open: a shorter breach reporting window, notice before new subcontractors are engaged, data location, and cooperation with your investigation.
Assessment checklist by risk tier
Not every business associate deserves the same depth. Tier on the volume and sensitivity of PHI, the level of system access and how hard the vendor would be to replace (the method in Vendor risk tiering: how to classify third parties and set a review cadence works unchanged).
All business associates
- A signed BAA is on file before any PHI is shared.
- The PHI shared is limited to the minimum necessary for the service.
- The vendor names a security or privacy contact and a breach reporting channel.
- The vendor confirms it has conducted its own Security Rule risk analysis.
- The vendor lists subcontractors that will handle PHI and confirms BAAs with them.
High tier (adds)
- Security questionnaire covering access control, encryption at rest and in transit, audit logging, and workforce training.
- Multi-factor authentication for all access to systems holding ePHI.
- Documented incident response plan with named roles.
- Backup, contingency and data restoration procedures, with test dates.
- Independent evidence (see the next section) covering the service you use.
Critical tier (adds)
- Current SOC 2 Type II or HITRUST validated report, read for scope, exceptions and complementary user entity controls.
- Recent penetration test summary with remediation status of significant findings.
- Data flow description: where ePHI is stored, processed and replicated, including subcontractor locations.
- Disaster recovery test results against stated recovery objectives.
- Termination plan: how PHI is returned or destroyed, and how you get it back in a usable format.
Evidence to request
| Evidence | What it tells you | What to check |
|---|---|---|
| SOC 2 Type II report | An auditor tested controls over a period, not just on a date. | The system in scope matches the service you buy; the period is recent; exceptions and CUECs are read. A HIPAA mapping is helpful but optional. |
| HITRUST validated assessment (i1 or r2) | Controls assessed against a framework that incorporates HIPAA requirements. | Assessment type, scope, date, and any corrective action plans. |
| Penetration test summary | Exposure to external and application-level attack. | Date, scope, tester independence, and whether high findings were fixed. |
| Security Rule risk analysis summary | The vendor knows its own risks to ePHI. | That it exists and is recent. Few vendors share the full document. |
| Policies and training records | Workforce awareness and sanctions. | Annual training cadence and coverage of staff with PHI access. |
Reports from other frameworks carry over well: a SOC 2 or ISO 27001 review follows the same logic described in SOC 2 vendor management: what auditors expect from your third-party programme. What they do not cover is HIPAA-specific: the BAA terms, subcontractor agreements, and breach reporting. Ask for those directly.
Breach notification obligations of business associates
Under 45 CFR 164.410, a business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and in no case later than 60 calendar days after discovery. A breach counts as discovered on the first day it is known to the business associate, or would have been known with reasonable diligence, by any workforce member or agent other than the person who caused it. The notice should identify each affected individual where possible and include the information the covered entity needs for its own notifications.
Two practical points. First, 60 days is a ceiling, and a vendor that waits for it can leave you with little time for your own obligations; set a shorter contractual window in the BAA. Second, if the business associate acts as your agent under the federal common law of agency, its discovery may be treated as yours, which starts your own clock. Your assessment should confirm the vendor can actually meet the window it signed.
Reassessment
HIPAA requires you to review and update security measures as needed and to keep your risk analysis current. For vendors, a workable cadence is annual for critical and high tiers and every two to three years for the rest, with an early review whenever:
- the vendor reports a security incident or breach;
- the scope of PHI or system access you give it changes;
- it adds or changes a subcontractor that handles PHI;
- it is acquired, merges, or shows signs of financial distress;
- the SOC 2 or HITRUST report you relied on expires.
Keep each assessment with its date, evidence and conclusion. HIPAA requires Security Rule documentation to be retained for six years from creation or last effective date, which is a sensible floor for vendor files too. If you run assessments in VendorVett, a HIPAA question pack is available on the Growth plan and up, and each completed review keeps its evidence and next due date together.
Where to go next
The HIPAA assessment sits inside the broader process in Vendor due diligence: a practical guide for small and mid-sized businesses, and the question set in Vendor risk assessment questionnaire: what to ask, and how to score the answers covers the security domains a business associate questionnaire draws on.
Frequently asked questions
- Does HIPAA require a risk assessment of each business associate?
- Not in those words. The Security Rule requires satisfactory assurances, documented in a business associate agreement, that a business associate will appropriately safeguard ePHI (45 CFR 164.308(b) and 164.314(a)), and a risk analysis covering the ePHI you create, receive, maintain or transmit (164.308(a)(1)(ii)(A)). A documented assessment of the vendor is the most practical way to show that your assurances were reasonable and that your risk analysis accounts for data held outside your walls.
- Is a vendor that stores only encrypted PHI still a business associate?
- Generally yes. HHS guidance on cloud computing says a cloud service provider that creates, receives, maintains or transmits ePHI on behalf of a covered entity or business associate is a business associate even if it stores only encrypted data and holds no decryption key. The narrow conduit exception covers transmission-only services such as a courier or an internet service provider, not storage.
- How quickly must a business associate report a breach?
- Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. Sixty days is an outer limit, not a safe harbor, and many BAAs set a shorter contractual window so the covered entity has time to meet its own notification duties.
- Is there an official HIPAA certification a vendor can show me?
- No. HHS does not certify or endorse any HIPAA compliance certification. A SOC 2 report mapped to HIPAA, a HITRUST validated assessment or a third-party HIPAA attestation can all be useful evidence, but none of them transfers your obligations or proves compliance on its own. Read the scope and the exceptions, not just the logo.
Related guides
- Fundamentals
- Checklist
Vendor due diligence: a practical guide for small and mid-sized businesses
The end-to-end process — scoping, questionnaires, evidence, scoring, review cadence — sized for a team of one.
9 min read
- Questionnaires
- Scoring
Vendor risk assessment questionnaire: what to ask, and how to score the answers
The questions that matter by risk tier, mapped to the controls auditors recognise, with a scoring method you can explain.
8 min read
- Programme design
- SMB
Third-party risk management for small businesses: a programme without a GRC team
Enterprise TPRM assumes a department. This is the version for a company with none — and what it still must not skip.
7 min read