This site provides independent HIPAA compliance cost estimates for informational purposes only. We are not affiliated with HHS, OCR, or any compliance vendor. This is not legal or regulatory advice. Consult a qualified HIPAA compliance professional for guidance specific to your organization.

HIPAA Compliance for Business Associates in 2026

Most HIPAA guidance is written for covered entities, which leaves business associates reading around a document that is not about them. The differences are real and they are set by the regulation rather than by your contract. This page maps them line by line, and is explicit that the cost question has no published answer.

Business associates are more than half of the population HIPAA reaches: HHS counts 1,000,000 of them against 822,600 covered entity establishments in its own analysis of the 2026 proposal.

Where the Security Rule is concerned, there is no BA discount

The intuition that a business associate has an easier time of HIPAA is half right, and the wrong half is the expensive one. The Security Rule applies to a BA in full and essentially identically: the same safeguards, the same risk analysis, the same security official, the same documentation. What a BA sheds is the patient-facing Privacy Rule apparatus, which is genuinely less work but is also the cheaper half. So the reduction in scope is real and it is smaller than it sounds, and it lands on the part of the programme that was never the cost driver.

What applies to whom

Set by the CFR rather than by any particular BAA, which is why this table holds across contracts. Where your BAA imposes more than the regulation does, that is a commercial term you agreed to rather than a HIPAA obligation, and it is worth knowing which is which when you negotiate.

RequirementCovered entityBusiness associateWhere it comes from
Security Rule, in fullAppliesAppliesNo BA discount exists. Identical obligation, 45 CFR 164.302-318
Risk analysisAppliesAppliesYour own, covering your own ePHI. 164.308(a)(1)(ii)(A)
Security officialAppliesAppliesMust be identified. 164.308(a)(2)
Workforce trainingAppliesApplies164.308(a)(5). No frequency is stated for either
Privacy Rule, in fullAppliesPartialA BA is bound by its BAA terms plus the provisions made directly applicable in 2013
Minimum necessaryAppliesAppliesDirectly applicable to BAs since the Omnibus Rule
Notice of Privacy PracticesAppliesDoes not applyA patient-facing obligation. A BA has no patients
Patient access requestsAppliesIndirectA BA must make PHI available so the covered entity can answer. 164.504(e)(2)(ii)(E)
BAA with every PHI subcontractorAppliesApplies164.502(e)(1)(ii). A BA's subcontractors are BAs too, and the chain runs down
Breach notificationTo individuals and HHSTo the covered entityBA notifies under 164.410; the covered entity notifies under 164.404
Direct OCR liabilityAppliesAppliesSince HITECH 2009, implemented 2013. Same four-tier penalty structure

Your BAA is the smaller of your two liabilities

Before the HITECH Act of 2009, a business associate's HIPAA exposure was contractual. Your covered entity client could sue you under the BAA; OCR could not touch you. The 2013 Omnibus Rule implemented HITECH and made business associates directly liable for Security Rule violations and for the Privacy Rule provisions applicable to them, enforceable by OCR under the same four-tier penalty structure that applies to covered entities.

The practical consequence is that a single incident now produces two kinds of claim from one set of facts: an OCR enforcement action against you directly, and contractual indemnity claims from every covered entity client whose PHI was involved. The second is frequently the larger number, and it is the one your BAA portfolio determines. Reading your indemnity and liability-cap terms is therefore a compliance activity and not just a legal one. See penalties and enforcement for the tier structure and OCR's published record.

What you can price, and what you cannot

Priced from a published card

  • GRC platform subscriptions, though Drata, Vanta, Secureframe and Sprinto each price on a different axis
  • Identity, MFA and endpoint tooling, each on its own unit
  • Cloud security services at ordinary published rates
  • Workforce training, per course or bundled into a platform

Quoted per engagement, published by nobody

  • The risk analysis
  • Policy and procedure development
  • Penetration testing
  • The SOC 2 assessor, bundled or separate
  • Healthcare counsel and BAA negotiation

The right-hand column is where a BA's first-year money goes, and no firm selling any of it publishes a rate. This page used to print a six-line budget for a 50-person SaaS BA, with a first-year total underneath it. Every line in it was a guess at one of those quotes, and the total was a sum of guesses. It is gone rather than relabelled. What you can do instead is take the split above and the published rates below into your own procurement, and ask each quote which column it belongs in.

The BAA chain runs downward too

The obligation most business associates underestimate is not the BAA with the client. It is the BAAs with their own subcontractors. Under 45 CFR 164.502(e)(1)(ii), a business associate must obtain satisfactory assurances from any subcontractor that creates, receives, maintains or transmits PHI on its behalf, and that subcontractor is itself a business associate with its own direct liability. The chain does not stop at the first link.

In practice this catches the infrastructure a BA never thinks of as touching PHI: the cloud provider, the email service, the backup vendor, the log aggregator, the error-tracking service that captures request payloads, the support desk tool where a customer pastes a screenshot, the analytics on an authenticated page. Error tracking and support tooling are the two that most often turn out to hold PHI nobody intended to put there.

This site publishes no BAA management cost, because the previous figures here were invented and the work is mostly counsel time and internal tracking, neither of which has a rate card. What is true and useful: missing and expired BAAs are a recurring finding in OCR's published enforcement record, and the ones that go missing come from that long tail rather than from the obvious contracts.

SOC 2 and HIPAA together

Nearly every BA ends up doing both, and it is worth being precise about why, because the two are not the same kind of thing. HIPAA is the law that binds you. SOC 2 is what your covered entity clients ask for in procurement, and the reason they ask is that HIPAA gives them nothing to ask for instead: HHS states there is no standard or implementation specification requiring certification of compliance, and that it does not endorse or recognise private organisations' certifications regarding the Security Rule. The SOC 2 report exists in your sales cycle precisely because HIPAA declines to issue one.

Running them together genuinely costs less than running them apart. The mechanism is explainable without a price: shared control testing, a single evidence-collection pass, one fieldwork mobilisation, aligned observation windows, common readiness work, and the client-side coordination time that never appears on an invoice. The limits are equally real. A SOC 2 Type II needs its observation period regardless. The Privacy Rule, the minimum necessary standard and the PHI-specific parts of your obligation have no SOC 2 counterpart and remain discrete work.

This site prints no percentage for the overlap and no figure for either engagement. No authority publishes a control-overlap ratio between HIPAA and SOC 2: OCR, NIST, AICPA, HITRUST and the PCI Security Standards Council all publish relationships rather than ratios, and NIST says its own mapping was intentionally broad and includes indirect alignments, so counting its entries would overstate the overlap. No assessment firm publishes an engagement fee either. See cross-framework for the published crosswalks and what they do and do not support.

What actually drives a BA's bill

The 2026 proposals reach BAs equally

HHS's denominator in the proposed rule's impact analysis is 1,822,600 regulated entities: 822,600 covered entity establishments plus 1,000,000 business associates. The proposed obligations do not differentiate between them. HHS published no per-segment or per-size cost for any of it, and the rule remains a proposal with no final text and no compliance date. Source: 90 FR 898, 6 January 2025, the proposed rule on the Federal Register. See the 2026 rule changes.

Frequently Asked Questions

What does HIPAA compliance cost a business associate?
This page prints no figure, and the reason is the same one that applies to a covered entity: the expensive half of the work is quoted per engagement and published by nobody. What you can price from published cards is the platform and tooling layer, and those rates are on this site's vendor pages, attributed and dated. What you cannot price is the risk analysis, the policy work, the penetration test, the assessor and the counsel time. A BA has a narrower Privacy Rule surface than a covered entity, which genuinely reduces scope, but nobody publishes what that reduction is worth in dollars and this site previously printed a percentage for it that had no source. If someone quotes you an all-in BA number, ask which parts of it came off a rate card. The answer is usually the small parts.
Which HIPAA rules actually apply to a business associate?
The Security Rule applies to a business associate in full and essentially identically to a covered entity: administrative, physical and technical safeguards, the risk analysis, the security official, the documentation. There is no BA discount in the Security Rule. The Privacy Rule applies only in part. A BA must comply with the terms of its BAA and with the provisions the 2013 Omnibus Rule made directly applicable, including the minimum necessary standard, the prohibition on uses and disclosures not permitted by its BAA, and the obligation to make PHI available for a covered entity to meet access and amendment requests. What a BA does not carry is the patient-facing apparatus: no Notice of Privacy Practices, no direct patient access request handling, no directory listings. Breach Notification applies, but the route differs: a BA notifies the covered entity under 45 CFR 164.410, and the covered entity notifies individuals and HHS under 164.404.
Can a business associate be fined directly?
Yes. The HITECH Act of 2009, implemented by the 2013 Omnibus Rule, made business associates directly liable for Security Rule violations and for the Privacy Rule provisions that apply to them, enforceable by OCR under the same four-tier penalty structure that applies to covered entities. Before that, a BA's exposure was contractual: the covered entity could sue you, but OCR could not penalise you. That changed, and it is the single most important thing for a BA to understand about its position. Your BAA is now the smaller of your two liabilities. On top of federal enforcement, a BA typically carries contractual indemnities to every covered entity client, so a single incident can produce an OCR action and a stack of contract claims from the same facts.
Do business associates need a risk assessment?
Yes, and it is your own, not your client's. A business associate must conduct a risk analysis covering all ePHI it creates, receives, maintains or transmits, under the same 45 CFR 164.308(a)(1)(ii)(A) obligation a covered entity has. The scope is often narrower, because a BA typically handles a defined subset of PHI rather than complete records, but the methodology and documentation requirements are identical and the narrowness is not a discount you can claim in advance. This site publishes no price for it, because no firm that performs risk analyses publishes a rate card. OCR's Risk Analysis Initiative focuses selected investigations on this exact provision, and it applies to BAs as squarely as to covered entities.
Do business associates need SOC 2 as well as HIPAA?
Usually, but for commercial reasons rather than legal ones, and the distinction is worth being precise about. HIPAA is the law that applies to you. SOC 2 is what your covered entity clients ask for in procurement, because HIPAA has no certification for them to ask for instead: HHS states there is no standard requiring a covered entity to certify compliance and that it does not recognise private certifications regarding the Security Rule. So the SOC 2 report fills a gap HIPAA deliberately leaves. Pursuing both together does cost less than doing them separately, through shared control testing, one evidence-collection pass and a single fieldwork mobilisation. This site puts no percentage on that saving and no figure on either engagement, because no assessment firm publishes a fee and no authority publishes a control-overlap ratio.
How do the 2026 proposals affect business associates?
They apply equally, and BAs are the majority of the affected population rather than a footnote. HHS's denominator in the proposed rule's impact analysis is 1,822,600 regulated entities, made up of 822,600 covered entity establishments plus 1,000,000 business associates, so more than half of the entities the rule reaches are BAs. The proposed obligations do not differentiate: the same MFA mandate, the same technology asset inventory, the same scanning cadence, the same annual penetration testing, the same 72-hour restoration and the same compliance audit. HHS published no per-segment or per-size cost for any of it, and the rule is still a proposal with no final text and no compliance date.

Updated 2026-07-17