Compliance libraryHIPAA

Why HIPAA decides whether healthcare will even talk to you

If protected health information touches your systems you're a business associate. That comes with a signed BAA, a Security Rule risk analysis and direct liability.

KoComply Research·May 2026·7 min read
Key takeaways
  • A signed BAA is a legal precondition to handling PHI — no BAA, no deal.
  • The Security Rule risk analysis is the most cited deficiency in enforcement actions.
  • HIPAA is not certifiable; buyers rely on SOC 2 plus a HIPAA mapping instead.

Business associate status is not optional

If you create, receive, maintain or transmit PHI on behalf of a covered entity you are a business associate and directly liable under HITECH. Your customer must have a Business Associate Agreement in place before PHI flows — and their compliance officer will not sign one without evidence of administrative, physical and technical safeguards.

What the Security Rule expects

  • A documented, current risk analysis and a management plan that shows remediation.
  • Access controls with unique user identification, automatic logoff and emergency access.
  • Audit controls that record and examine activity in systems containing ePHI.
  • Encryption in transit and at rest, or documented justification of an equivalent measure.
  • Workforce training, a sanction policy and breach notification procedures.

How to prove it without a certificate

There is no official HIPAA certification. In practice buyers accept a SOC 2 Type II with a HIPAA Security Rule mapping, plus your risk analysis and policies. Building the control set once and mapping it to both frameworks is what makes that affordable.

Let an agent do this part for you

Free forever on Questionnaire, Infra Health and Codebase Health. Upgrade when you're ready for the full program.

Start free

Keep reading

Put an agent on this instead
Free forever on Questionnaire, Infra Health and Codebase Health.