HIPAA Compliance for Business Associates in 2026
Most HIPAA guidance is written for covered entities, which leaves business associates reading around a document that is not about them. The differences are real and they are set by the regulation rather than by your contract. This page maps them line by line, and is explicit that the cost question has no published answer.
Business associates are more than half of the population HIPAA reaches: HHS counts 1,000,000 of them against 822,600 covered entity establishments in its own analysis of the 2026 proposal.
Where the Security Rule is concerned, there is no BA discount
The intuition that a business associate has an easier time of HIPAA is half right, and the wrong half is the expensive one. The Security Rule applies to a BA in full and essentially identically: the same safeguards, the same risk analysis, the same security official, the same documentation. What a BA sheds is the patient-facing Privacy Rule apparatus, which is genuinely less work but is also the cheaper half. So the reduction in scope is real and it is smaller than it sounds, and it lands on the part of the programme that was never the cost driver.
What applies to whom
Set by the CFR rather than by any particular BAA, which is why this table holds across contracts. Where your BAA imposes more than the regulation does, that is a commercial term you agreed to rather than a HIPAA obligation, and it is worth knowing which is which when you negotiate.
| Requirement | Covered entity | Business associate | Where it comes from |
|---|---|---|---|
| Security Rule, in full | Applies | Applies | No BA discount exists. Identical obligation, 45 CFR 164.302-318 |
| Risk analysis | Applies | Applies | Your own, covering your own ePHI. 164.308(a)(1)(ii)(A) |
| Security official | Applies | Applies | Must be identified. 164.308(a)(2) |
| Workforce training | Applies | Applies | 164.308(a)(5). No frequency is stated for either |
| Privacy Rule, in full | Applies | Partial | A BA is bound by its BAA terms plus the provisions made directly applicable in 2013 |
| Minimum necessary | Applies | Applies | Directly applicable to BAs since the Omnibus Rule |
| Notice of Privacy Practices | Applies | Does not apply | A patient-facing obligation. A BA has no patients |
| Patient access requests | Applies | Indirect | A BA must make PHI available so the covered entity can answer. 164.504(e)(2)(ii)(E) |
| BAA with every PHI subcontractor | Applies | Applies | 164.502(e)(1)(ii). A BA's subcontractors are BAs too, and the chain runs down |
| Breach notification | To individuals and HHS | To the covered entity | BA notifies under 164.410; the covered entity notifies under 164.404 |
| Direct OCR liability | Applies | Applies | Since HITECH 2009, implemented 2013. Same four-tier penalty structure |
Your BAA is the smaller of your two liabilities
Before the HITECH Act of 2009, a business associate's HIPAA exposure was contractual. Your covered entity client could sue you under the BAA; OCR could not touch you. The 2013 Omnibus Rule implemented HITECH and made business associates directly liable for Security Rule violations and for the Privacy Rule provisions applicable to them, enforceable by OCR under the same four-tier penalty structure that applies to covered entities.
The practical consequence is that a single incident now produces two kinds of claim from one set of facts: an OCR enforcement action against you directly, and contractual indemnity claims from every covered entity client whose PHI was involved. The second is frequently the larger number, and it is the one your BAA portfolio determines. Reading your indemnity and liability-cap terms is therefore a compliance activity and not just a legal one. See penalties and enforcement for the tier structure and OCR's published record.
What you can price, and what you cannot
Priced from a published card
- GRC platform subscriptions, though Drata, Vanta, Secureframe and Sprinto each price on a different axis
- Identity, MFA and endpoint tooling, each on its own unit
- Cloud security services at ordinary published rates
- Workforce training, per course or bundled into a platform
Quoted per engagement, published by nobody
- The risk analysis
- Policy and procedure development
- Penetration testing
- The SOC 2 assessor, bundled or separate
- Healthcare counsel and BAA negotiation
The right-hand column is where a BA's first-year money goes, and no firm selling any of it publishes a rate. This page used to print a six-line budget for a 50-person SaaS BA, with a first-year total underneath it. Every line in it was a guess at one of those quotes, and the total was a sum of guesses. It is gone rather than relabelled. What you can do instead is take the split above and the published rates below into your own procurement, and ask each quote which column it belongs in.
The BAA chain runs downward too
The obligation most business associates underestimate is not the BAA with the client. It is the BAAs with their own subcontractors. Under 45 CFR 164.502(e)(1)(ii), a business associate must obtain satisfactory assurances from any subcontractor that creates, receives, maintains or transmits PHI on its behalf, and that subcontractor is itself a business associate with its own direct liability. The chain does not stop at the first link.
In practice this catches the infrastructure a BA never thinks of as touching PHI: the cloud provider, the email service, the backup vendor, the log aggregator, the error-tracking service that captures request payloads, the support desk tool where a customer pastes a screenshot, the analytics on an authenticated page. Error tracking and support tooling are the two that most often turn out to hold PHI nobody intended to put there.
This site publishes no BAA management cost, because the previous figures here were invented and the work is mostly counsel time and internal tracking, neither of which has a rate card. What is true and useful: missing and expired BAAs are a recurring finding in OCR's published enforcement record, and the ones that go missing come from that long tail rather than from the obvious contracts.
SOC 2 and HIPAA together
Nearly every BA ends up doing both, and it is worth being precise about why, because the two are not the same kind of thing. HIPAA is the law that binds you. SOC 2 is what your covered entity clients ask for in procurement, and the reason they ask is that HIPAA gives them nothing to ask for instead: HHS states there is no standard or implementation specification requiring certification of compliance, and that it does not endorse or recognise private organisations' certifications regarding the Security Rule. The SOC 2 report exists in your sales cycle precisely because HIPAA declines to issue one.
Running them together genuinely costs less than running them apart. The mechanism is explainable without a price: shared control testing, a single evidence-collection pass, one fieldwork mobilisation, aligned observation windows, common readiness work, and the client-side coordination time that never appears on an invoice. The limits are equally real. A SOC 2 Type II needs its observation period regardless. The Privacy Rule, the minimum necessary standard and the PHI-specific parts of your obligation have no SOC 2 counterpart and remain discrete work.
This site prints no percentage for the overlap and no figure for either engagement. No authority publishes a control-overlap ratio between HIPAA and SOC 2: OCR, NIST, AICPA, HITRUST and the PCI Security Standards Council all publish relationships rather than ratios, and NIST says its own mapping was intentionally broad and includes indirect alignments, so counting its entries would overstate the overlap. No assessment firm publishes an engagement fee either. See cross-framework for the published crosswalks and what they do and do not support.
What actually drives a BA's bill
- How much PHI you actually touch. A BA processing a narrow field set is a far smaller risk analysis than one holding complete records. Scope drives assessment cost more than headcount does, and BAs vary on this more than covered entities do.
- Whether PHI is in your product or only in your support path. Many BAs discover their real exposure is the second: logs, error traces, screenshots in tickets. It is also the exposure least likely to be in the architecture diagram.
- Your subcontractor count. Every vendor in the PHI path needs a BAA and each is a BA in its own right.
- Client contract terms. Frequently more demanding than HIPAA itself: audit rights, notification windows shorter than 164.410 requires, uncapped indemnities. This is where BA compliance cost actually escalates, and none of it is regulatory.
- Whether you need SOC 2 for the sales cycle. A commercial decision that lands in the compliance budget.
- Workforce headcount. Training and identity meter on it, and per-employee platform fees scale on it directly.
The 2026 proposals reach BAs equally
HHS's denominator in the proposed rule's impact analysis is 1,822,600 regulated entities: 822,600 covered entity establishments plus 1,000,000 business associates. The proposed obligations do not differentiate between them. HHS published no per-segment or per-size cost for any of it, and the rule remains a proposal with no final text and no compliance date. Source: 90 FR 898, 6 January 2025, the proposed rule on the Federal Register. See the 2026 rule changes.