Home All services
Start a project → Call Now

HIPAA compliance partner for business associates

Meet your HIPAA duties as a business associate — with the proof on file.

If your software handles patient data for a US hospital, health insurer or clinic, HIPAA treats you as a business associate. You answer to the US regulator, the HHS Office for Civil Rights (OCR), in your own name. We build the records OCR reads first: the risk analysis, the written decisions and the agreement chain.

  • Every system with patient data in scope
  • A written decision for every addressable specification
  • We reply within one working day.
  • 45 CFR Part 164
  • 164.308(a)(1)(ii)(A) risk analysis
  • 164.410 notification
  • NIST SP 800-66r2
Illustration: a clinic and an office building joined by a glass bridge, with a health record folder carried across inside a sealed glass capsule and a file box of ticked record cards in front

In brief

What it is
HIPAA help for business associates: firms that handle protected health information (PHI) for a US covered entity, such as a hospital, health insurer or clinic.
Why it matters
You answer to the regulator in your own name. A missing or thin risk analysis is the deficiency OCR cites most, and no certificate can take its place.
What you get
A dated risk analysis, a risk register your people close, a signed decision for each of the 22 addressable specifications, and a subcontractor agreement chain you can show.

What HIPAA asks of you

What you must be able to show, and where it usually fails.

The Security Rule's Appendix A to Subpart C lists 18 standards and 36 implementation specifications. 14 are Required. 22 are Addressable: you must decide what to do about each one and write the decision down. A covered entity's assessor asks for the six below first.

A risk analysis that covers everything

The first document asked for (164.308(a)(1)(ii)(A)), dated within twelve months. Most of the ones we're handed fail on scope: electronic PHI (ePHI) also lives in support tickets, logs, test databases and contractor laptops.

A risk register that gets closed

Named owners, target dates and closed items (164.308(a)(1)(ii)(B)). A register full of open rows is worse than none: it proves you knew and left it.

A written decision for every addressable specification

One for each of the 22, including both encryption entries (164.306(d)(3)). The missing document is the violation, not the missing control.

One login per person and per service

Unique user identification (164.312(a)(2)(i)) is Required, so a written reason will not excuse a shared login. Fix shared support-desk accounts before the risk analysis starts.

A signed agreement with every subcontractor

Every subcontractor that touches PHI has a signed agreement (164.308(b)(1)), and your register names the country and facility where each one processes data. Staff augmentation often fails here: engineers with production access and no agreement.

A breach procedure that starts the clock on the right day

Your notice to your client (164.410) runs from the day a breach was known, or should have been known, not the day your incident review closes. That depends partly on your logs, which our threat detection support covers.

Failure to conduct an accurate and thorough risk analysis is, by a wide margin, the most-cited deficiency in OCR enforcement. In April 2026 OCR announced four ransomware settlements totaling USD 1,165,000, and every one turned on that finding. OCR needs no new rule to act: the Security Rule has been enforceable from 20 April 2005, and its text last moved in 2013.

Test data copied from production

Refreshing a QA database from production is a disclosure. If it is called anonymized, ask which lawful route at 164.514(b) was used. Safe Harbor: all 18 identifier categories at (b)(2)(i)(A) through (R) are gone, and you have no actual knowledge that the rest identifies anyone. Expert determination: a documented statistical opinion by a qualified person. Dropping the name column is neither.

When a breach counts as discovered

Under 164.404(a)(2), a breach is discovered on the first day it is known, or would have been known with reasonable diligence, to any workforce member other than the person who caused it. 164.402(2) then presumes a breach unless you document a low probability of compromise across all four factors. Keep a completed four-factor form for every incident you decided was not a breach.

The rest of the assessor's list
  • Training records, and a sanction policy applied at least once. One nobody has used is a document, not a control.
  • The dated 164.308(a)(8) periodic evaluation, and a contingency plan with a real test report, not a template.
  • Documentation kept six years from creation or from when it was last in effect, whichever is later (164.316(b)(2)(i)).

How the obligation moves

Obligations flow down the chain. Liability flows back up.

A US health system signs a business associate agreement (BAA) with you. You sign one with your cloud host, your log service and your contractors. Each agreement pushes the same duties one step further from the patient.

Liability is not only a matter of contract. From 23 September 2013, the compliance date of the Omnibus Rule (the 2013 update to HIPAA), any subcontractor that creates, receives, maintains or transmits PHI for you is itself a business associate under 45 CFR 160.103. It answers to OCR in its own name.

Three links, each answerable to OCR

  • Covered entity. The hospital, health insurer or clinic holding the PHI, bound by 45 CFR Part 164. It passes the Security Rule to you through 164.504(e) and 164.314(a).
  • Business associate. You, if you build or host software that touches PHI. 164.308(b)(1) makes you pass the same terms to every subcontractor.
  • Subcontractor. Your hosting, your analytics, anyone you pass PHI to. Every link needs a written agreement; 164.504(e) sets its contents.

Two things travel back up the chain. 45 CFR 160.402 attributes an agent's acts to the firm that engaged it, so a subcontractor's failure can become yours. After a breach, you owe your client notice under 164.410. The assessor calls you, not your subcontractor, and asks for the risk analysis first.

Checking your own vendors' access is third-party risk management. If a HITRUST-licensed firm will assess your ePHI controls, our ePHI security controls work implements and documents them. SecWiz is not a HITRUST assessor.

What this work does not include. A HIPAA certificate, because none exists. Only OCR decides whether you comply, usually while it is already investigating. We're not a CPA firm, so we don't sign SOC 2 reports, and SecWiz isn't ISO 27001 certified itself.

What you get

The evidence pack, and who signs each part.

Procurement asks who wrote each document and who answers for it. "Our consultant did" is a poor answer for anything your security official must sign.

Who produces and who signs each document.
DocumentCited atWho produces it, who signs it
ePHI asset inventory and data flow mapPrerequisite to 164.308(a)(1)(ii)(A)SecWiz builds it. Your system owners confirm ownership and location.
Security risk analysis report164.308(a)(1)(ii)(A)SecWiz produces it. It isn't a certificate, and its cover page says so.
Risk management plan and risk register164.308(a)(1)(ii)(B)SecWiz drafts it. Your named owners close the items, which is the part that counts.
Addressable specification decision log, 22 entries164.306(d)(3)SecWiz drafts each determination. Your security official signs them.
Subcontractor BAA template and signed-BAA register164.504(e), 164.314(a)SecWiz drafts. Your counsel and each subcontractor sign.
Breach risk assessment form, four factors164.402(2), 164.410SecWiz produces the form. You run it, on your own clock.
Recognized Security Practices evidence filePub. L. 116-321SecWiz assembles it. It can lower a penalty, but only after twelve months of your own evidenced operation.
A HIPAA certificateNowhereNobody. HHS has never created or endorsed one, so any badge claiming it is marketing.

To keep this evidence current between audits, see compliance as a service. For our wider work with health software, see healthcare.

How an engagement runs

Five steps, starting with where your data really is.

After scoping comes the ePHI inventory. Every later step depends on it.

  1. Scoping

    You tell us what you build, who for, and where the data sits. We agree the scope and say plainly how long it will run.

  2. ePHI inventory

    We map every system that holds or moves ePHI, and how data flows between them. Your system owners confirm each entry.

  3. Risk analysis

    We assess every system in the inventory and date the report. An offshore location counts as a factor.

  4. Register and decisions

    We draft the risk management plan, the register and a decision for each of the 22 addressable specifications. Your owners close the items and your security official signs.

  5. Agreement chain and breach readiness

    We reconcile your subcontractors against signed BAAs and hand over the breach assessment form. Where the work includes fixes, we check each one.

FAQ

Questions business associates ask.

Certificates, SOC 2, data in India and timelines. For anything else, ask us directly.

No, and neither can anyone else. HHS has never created, endorsed or recognized a HIPAA certification program, there's no accreditation body, and no private certificate absolves you of anything. What carries weight with OCR is the work itself: a dated risk analysis, a risk register with closed items, and a written decision for every addressable specification. We produce that, and state in writing that it isn't a certificate. We'll also ask you to keep "HIPAA certified" off your website, since no such certification exists.

It doesn't. A SOC 2 Type II is a restricted-use attestation report from a licensed CPA firm on controls you selected against the Trust Services Criteria, with an optional HIPAA Security Rule mapping section. It isn't a certificate, and SecWiz doesn't sign one because we're not a CPA firm. Also, 164.308(b) and 164.314(a) put the duty on you. A report scoped to your platform won't produce a breach procedure, a subcontractor BAA register, or a risk analysis of the systems outside that scope.

Not as of today. It sits in the Security Rule overhaul proposed on 6 January 2025 under RIN 0945-AA22. Comments closed on 7 March 2025, and HHS has moved the proposal to its long-term actions list with July 2027 as the target for final action. None of it is law: not MFA, not mandatory encryption, not the six-monthly vulnerability scanning or annual technical testing it proposes. Today, encryption at 164.312(a)(2)(iv) and (e)(2)(ii) is addressable: you must decide, and write the decision down.

Yes. HIPAA has no data localization requirement, so say so plainly in a bid. The offshore location becomes a factor in the risk analysis, and your BAA should carry three things a domestic one usually skips: a geographic processing disclosure naming countries and facilities, an agreed position on whether that location can change, and a full subcontractor map. Separately, some US health systems and most state Medicaid programs restrict offshoring themselves. Those are contract and state-law terms, not HIPAA.

Yes, and the chain has no depth limit. A subcontractor handling PHI for a business associate is itself a business associate, directly liable for the whole Security Rule and the notification duty at 164.410. Being outside the United States changes nothing. The conduit exception won't help either: it covers pure transmission, such as a courier or an ISP, not a provider that stores the data, even encrypted data it can't read.

Eight to twelve weeks for a single-product SaaS business associate with one cloud environment, done properly. Four to seven months for a mid-sized organization. The risk analysis alone takes six to ten weeks, and it can't start until the ePHI inventory is complete, which is where projects overrun. Start one more clock early: the Recognized Security Practices mitigation under Pub. L. 116-321 needs twelve months of evidenced operation before HHS must take it into account, and it lowers a penalty rather than stopping the case.

They run side by side. Processing US PHI from India typically makes you a Data Processor under the Digital Personal Data Protection Act 2023 and a business associate under HIPAA at once, with two sets of breach duties that don't share a clock. The DPDP Act commences in tranches, and the breach duty you would carry as a Data Processor sits in the last one, so the two clocks don't even start in the same year.

Yes, if you handle substance use disorder records for a covered entity, and that deadline has passed. The Part 2 alignment rule's compliance date was 16 February 2026, and OCR opened a civil enforcement program for those records on 13 February 2026. Related: the 2024 reproductive health privacy rule was vacated nationwide in Purl v. HHS on 18 June 2025, and the appeal was dismissed on 10 September 2025. A Notice of Privacy Practices that still cites it is inaccurate, and notice accuracy is enforceable under 164.520.

Let's talk

Start with the risk analysis. It's the document you get asked for.

Tell us what you build, who for, and where the data sits. You get a scope, an approach to the ePHI inventory and a straight answer on how long it runs. We reply within one working day.