FaSQUAL: The BSIA-led Vetting Passport for the UK Security Industry Powered by Neotas Read More →
Generate AI-Powered Audit-Ready Due Diligence Reports instantly. Learn More →
HIPAA Vendor Risk Assessment

HIPAA Vendor Risk Assessment: What OCR Fines You For in 2026

The eight BAA provisions, OCR enforcement precedent, a six-step process and a 16-point checklist with evidence, applicable in 2026.

24 hrs
Proposed vendor breach notification deadline under the 2025 Security Rule NPRM [1]
1002%
Rise in individuals affected by large health data breaches, 2018 to 2023, per HHS [2]
$2.1M+
Annual HIPAA penalty cap per violation category after the January 2026 inflation adjustment [3]
$1.55M
OCR settlement for a missing vendor BAA and risk analysis (North Memorial) [4]

Quick answer

A HIPAA vendor risk assessment is the documented evaluation of one vendor’s ability to protect Protected Health Information, run before onboarding and at every review cycle.

It verifies Business Associate Agreement compliance under 45 CFR 164.504(e), Security Rule safeguards, the vendor’s standing with HHS Office for Civil Rights, and readiness for the 2025 Security Rule update at 90 FR 800.

Key takeaways

  • HIPAA requires a signed Business Associate Agreement before any vendor creates, receives, maintains or transmits PHI, under 45 CFR 164.504(e). [5]
  • OCR settlements for vendor oversight failures are on the public record: North Memorial paid $1.55 million and Raleigh Orthopaedic paid $750,000, both over missing vendor BAAs. [4]
  • The 2025 Security Rule NPRM (90 FR 800) proposes mandatory MFA, encryption of ePHI, and 24-hour vendor breach notification, with a 240-day compliance window once finalised. [1]
  • Individuals affected by large health data breaches rose 1002% from 2018 to 2023, reaching over 167 million people in 2023, per HHS. [2]
  • A complete assessment runs 6 checks in sequence: BAA scope, security evidence, regulatory standing, financial stability, adverse media and integrity, and subcontractor dependencies.
  • Self-completed questionnaires cannot detect beneficial ownership risk, non-English adverse media or early financial distress, so independent screening is the control that closes the gap.

What is a HIPAA vendor risk assessment?

A HIPAA vendor risk assessment is the process a covered entity or business associate uses to evaluate whether one specific vendor can protect PHI to the standard the HIPAA Privacy and Security Rules demand. It runs before onboarding, at contract renewal, and whenever the vendor’s risk profile changes. Its output is the evidence file OCR asks for when a vendor relationship fails.

The assessment works at the vendor level, not the enterprise level. Your organisation’s own security risk analysis under 45 CFR 164.308(a)(1)(ii)(A) covers your systems. The vendor assessment covers one external party: its Business Associate Agreement, its safeguards, its regulatory record, and the subcontractors sitting behind it. The two exercises are related but not interchangeable, and OCR expects both.

The scale of the problem is measured by the regulator itself. HHS reports that large health data breaches rose 102% between 2018 and 2023, the number of individuals affected rose 1002%, and 2023 set a record with over 167 million people affected, driven mainly by hacking and ransomware. [2] A large share of that exposure enters through vendors, which is why the 2025 rulemaking targets business associate oversight directly.

Most healthcare organisations run vendor assessment through an annual questionnaire. That satisfies the paperwork. It does not satisfy the standard OCR applies after an incident, which asks what the organisation could reasonably have known about the vendor at the time. The healthcare vendor risk management guide covers the full discipline; this page covers the assessment itself, ending with a working assessment checklist.

Is a HIPAA vendor risk assessment mandatory?

Yes. The Privacy and Security Rules require covered entities to obtain satisfactory assurances that a business associate will safeguard PHI, and to document those assurances in a signed BAA before any PHI changes hands (45 CFR 164.504(e)). The assessment is how those assurances are verified rather than assumed.

The enforcement record removes any doubt. OCR settled with North Memorial Health Care for $1.55 million over a missing vendor BAA and an incomplete risk analysis, and with Raleigh Orthopaedic for $750,000 after PHI went to a vendor with no BAA at all. [4] The full precedent set is in the enforcement section below.

Who counts as a business associate under HIPAA?

Any vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate, and the HITECH Act extends the same obligations to that vendor’s own subcontractors. [6] The test is function, not job title: if the vendor touches PHI to do its work, it is in scope.

EHR and clinical software

Hold PHI at scale and run clinical operations. Always a business associate, always Tier 1.

Cloud and SaaS providers

A business associate even where data is encrypted and the provider never views it, per HHS cloud guidance.

Billing and revenue cycle

Process PHI and payment data together. Financial distress here is a patient-care risk, not just a commercial one.

Telehealth platforms

Handle live patient data and also sit under the FTC Health Breach Notification Rule.

Diagnostic labs and imaging

PHI plus CLIA certification and accreditation status to verify alongside the BAA.

IT services and MSPs

Remote access to ePHI systems makes them business associates. The Change Healthcare entry point was a remote access portal.

The rule that follows is simple and absolute: no BAA, no PHI access. Vendors with no PHI access sit outside BAA scope but still carry operational, financial and integrity risk, which the vendor due diligence questionnaire layer should still cover.

The 8 BAA provisions you verify, not just sign

45 CFR 164.504(e) sets 8 mandatory provisions for every Business Associate Agreement, and a missing provision is a direct compliance gap whether or not a breach ever happens. [5] The assessment’s job is to test each clause against what the vendor actually does.

The diagram below maps the eight provisions every BAA must contain.

Provisions 5 and 6, breach notification and subcontractor flow-through, are the clauses OCR enforcement and the 2025 NPRM both target.

Provision What the clause requires What the assessment verifies
1. Permitted uses PHI uses and disclosures defined specifically, not “all services contemplated by the agreement”. Data flows in practice match the clause. Shadow uses (analytics, model training) are the common breach.
2. No unauthorised disclosure Use beyond the BAA or the law is prohibited. Access logging exists and can evidence who saw what.
3. Minimum necessary The vendor accesses only the PHI its function requires. Role-based access controls are configured, not just documented.
4. Safeguards Administrative, physical and technical safeguards. The 2025 NPRM adds specificity: MFA, encryption, vulnerability scanning. Independent evidence: SOC 2 Type II or ISO 27001, penetration test within 12 months, MFA enforcement.
5. Breach notification timeline Current rules allow up to 60 days. The 2025 NPRM proposes 24 hours. The contracted timeline is specific, and the vendor’s incident process can actually meet it.
6. Subcontractor flow-through Equivalent safeguards must be imposed on any subcontractor handling PHI, under HITECH. The flow-through happened operationally. Most BAAs contain the clause; almost nobody verifies it.
7. HHS audit cooperation Internal practices and records are made available to HHS for compliance review. The vendor accepts the clause. A vendor that refuses cannot serve as a business associate.
8. Return or destruction PHI is returned or destroyed on termination, with documented evidence. Destruction certificates exist for past offboarded relationships. Verbal assurance fails this test.

A signed BAA is the floor, not the control

OCR’s own settlement record, detailed below, shows covered entities paying 6 and 7 figure amounts where the vendor paperwork failed or the oversight behind it did. The affected health systems in the Change Healthcare incident held compliant BAAs. What they lacked was verification.

What OCR enforcement says about vendor oversight

OCR has settled repeatedly, and publicly, over vendor oversight failures, and the resolution agreements are on HHS.gov for any auditor to read. Four cases define the precedent a compliance team should be able to quote.

Case Settlement What went wrong The lesson
North Memorial Health Care [4] $1.55 million No BAA with a major contractor that had access to patient data, plus no organisation-wide risk analysis, surfaced after a breach at the vendor. The vendor’s breach exposed the covered entity’s own compliance gaps. Both were penalised in the outcome.
Raleigh Orthopaedic Clinic [7] $750,000 Handed the PHI of 17,300 patients (X-ray films) to a vendor on an informal arrangement, with no BAA executed first. OCR’s words at the time: the BAA obligation is more than a check-the-box paperwork exercise. Informal vendor arrangements count.
CHSPSC LLC [8] $2.3 million A business associate providing IT and health information management to hospitals suffered a breach affecting over 6 million people. Business associates are penalised directly under HITECH. Your vendor’s exposure is also its own.
Catholic Health Care Services [9] $650,000 A business associate failed to safeguard nursing home residents’ PHI. Small vendor populations and vulnerable patient groups draw enforcement too. Tier by data sensitivity, not vendor size.

Read together, the precedent is consistent: OCR penalises the paperwork gap, the oversight gap and the vendor itself, and it does so whether the covered entity is a health system or a clinic. The assessment process in the next section is built to survive exactly this scrutiny, and the wider governance context sits in the healthcare third-party risk management guide.

Neotas | Chartis FCC50 Market Disruptor Winner 2026

Find out which of your BAAs would fail the 24-hour test

An independent gap review of one critical vendor against the 8 BAA provisions and the 90 FR 800 requirements. Findings within 5 working days, reviewed with a risk intelligence expert, not a sales rep.

Request a vendor gap review

How to run a HIPAA vendor risk assessment in 6 steps

A complete assessment on a Critical (Tier 1) vendor works through 6 checks in sequence, from BAA scope through to the subcontractors the vendor depends on. Steps 1 to 3 confirm the compliance baseline. Steps 4 to 6 find the risks that produce actual incidents.

The diagram below shows the six checks in the order they run.

Checks 4 to 6 are where questionnaire-only programmes stop and where the incident-producing risks actually sit.

1

Confirm scope and the BAA

Establish whether the vendor creates, receives, maintains or transmits PHI. If yes, a BAA covering all 8 provisions must be signed before access begins. No BAA, no PHI. No exceptions, including pilots and trials: Raleigh Orthopaedic’s $750,000 settlement came from an informal, verbal vendor arrangement.

2

Collect independent security evidence

SOC 2 Type II or ISO 27001, a penetration test dated within 12 months, MFA enforcement, encryption at rest and in transit, and data residency. For connected medical devices, add a current MDS2 and an SBOM per FDA’s 2023 cybersecurity guidance.

3

Check regulatory standing independently

HIPAA enforcement history, FDA status for device and pharma vendors (registration, 483 observations, warning letters, recalls via the FDA device databases), and actions in every jurisdiction the vendor operates in. Never accept self-certification as the source.

4

Test financial stability and concentration

Audited financials, credit signals, and the share of a critical function this one vendor represents. A revenue cycle operator in financial trouble threatens patient care, not just a contract.

5

Screen adverse media, ownership and integrity

Adverse media across languages, beneficial ownership traced to the ultimate owner, sanctions and PEP proximity, and executive connections. Self-reporting cannot run this check; independent enhanced due diligence can.

6

Verify the subcontractor chain

Identify the subcontractors and infrastructure the vendor depends on, and confirm the HITECH flow-through was operationalised rather than merely written into the contract. Two critical vendors sharing one cloud region is a concentration risk neither will volunteer; the method sits in supply chain risk management.

How to tier HIPAA vendors for assessment depth

Tier by 5 criteria read together: PHI access, BAA requirement, clinical criticality, FDA category and integrity exposure. The tier sets how many of the 6 checks run and how often, inside the governance model described in the healthcare TPRM programme guide. One rule holds across every tiering model: no PHI-handling vendor gets Standard-tier treatment.

Tier Typical vendors Checks that run Review cycle
Tier 1: Critical EHR, cloud and SaaS holding ePHI, connected medical devices, revenue cycle operators All 6, with independent screening at step 5 and subcontractor verification at step 6 Annual full assessment plus continuous monitoring between cycles
Tier 2: High Diagnostic labs, telehealth, pharma and device suppliers without direct ePHI system access Checks 1, 2, 3 and a lighter version of 5 Annual, with event-driven reassessment on any adverse signal
Tier 3: Standard No PHI access: facilities, logistics, general suppliers Questionnaire plus confirmation that no BAA is required At renewal, or on scope change that introduces PHI

Tier on scope change, not just on schedule

A Tier 3 facilities vendor that wins an IT support contract becomes a business associate the day it gains system access. The trigger for reassessment is the scope change, not the next annual review date.

The HIPAA vendor risk assessment checklist

The checklist below covers the 16 items a defensible vendor file contains, split by lifecycle phase, with the evidence an OCR reviewer would expect against each. It condenses the 6-step process and the 8 BAA provisions into one working document; the vendor risk assessment template gives it a documented structure, and reassessment triggers belong in your third-party risk management policy.

# Check Evidence on file
Before onboarding
1 PHI scope determined: does the vendor create, receive, maintain or transmit PHI Scoping memo with the data flows named
2 BAA signed covering all 8 provisions of 45 CFR 164.504(e), before any PHI access Executed BAA, provision-mapped
3 Breach notification timeline specified and 24-hour-capable (90 FR 800 readiness) BAA clause reference plus the vendor’s incident process
4 SOC 2 Type II or ISO 27001 held and current Report or certificate on file
5 Penetration test dated within 12 months Summary letter with date and scope
6 MFA enforced and ePHI encrypted at rest and in transit Configuration evidence, not attestation alone
7 FDA standing checked for device and pharma vendors (483s, warning letters, recalls) Database extract with the check date
8 Beneficial ownership traced to the ultimate owner, sanctions and PEP proximity screened Independent screening report
9 Adverse media screened across languages, not English-only Screening report with source coverage stated
10 Financial stability reviewed for critical vendors Audited financials or credit assessment
11 Subcontractor list obtained and HITECH flow-through confirmed operationally Subcontractor register with flow-through confirmations
12 Tier assigned and review cycle set Tiering record with the 5 criteria scored
Ongoing
13 Continuous monitoring live on Tier 1 vendors between review cycles Alert configuration and sample alerts
14 Reassessment triggers defined: ownership change, adverse media, scope change Policy clause reference
15 Annual verification of vendor controls documented (NPRM readiness) Audit evidence per vendor per year
Offboarding
16 PHI returned or destroyed at termination Destruction or return certificate on file

Items 8, 9, 10 and 11 cannot be completed from the vendor’s own answers, which is the structural point the next section covers. The third-party risk management framework shows where this checklist sits in the wider lifecycle.

6 risks a HIPAA vendor questionnaire cannot find

A questionnaire surfaces what a vendor is willing and able to disclose, and nothing else. The risks below sit outside self-reporting by design, and in healthcare they are the ones that produce serious incidents. For questionnaire structure itself, see the TPRM questionnaire guide.

The comparison below shows where self-reporting stops and independent screening starts.

Every category in the left column has produced a real healthcare vendor incident that a completed questionnaire failed to flag.

Adverse media in non-English press

A pharma supplier’s GMP violations covered in its home-country press reach structured databases weeks later, if at all.

Beneficial ownership opacity

No questionnaire asks about the full ownership chain. A sanctioned party 3 holding companies deep is still your OFAC exposure.

Financial distress before disclosure

Payment delays, executive departures and credit pressure appear months before public filings do.

Regulatory actions elsewhere

An FDA 483 observation or a foreign enforcement action left off the self-certification stays invisible until checked independently.

Subcontractor concentration

Two critical vendors on the same infrastructure provider is a shared point of failure neither discloses as proprietary information.

Executive integrity risks

Undisclosed connections between vendor executives and public officials create FCPA exposure a conflict-of-interest question will not surface.

The Change Healthcare lesson

Security researchers had raised concerns about Change Healthcare’s architecture before the February 2024 attack, in publicly available sources, per Dallas Fed research (2025). [10] Affected health systems held compliant BAAs and current questionnaires. An annual self-reporting cycle could not surface what continuous independent monitoring would have.

What the 2025 Security Rule NPRM changes for vendor assessment

HHS published the proposed rule at 90 FR 800 on 6 January 2025, the largest Security Rule overhaul in over 20 years, and covered entities and business associates get 240 days to comply once it finalises. [1] HHS justified the overhaul with its own breach data: a 102% rise in large breaches and a 1002% rise in individuals affected between 2018 and 2023. [2] For vendor assessment, 5 changes matter most.

The card below condenses the proposed rule’s changes that hit vendor assessment hardest.

The 240-day clock starts at final publication, which is less time than most organisations need to renegotiate BAA templates across a vendor population.

Requirement Current rule Proposed under 90 FR 800
Vendor breach notification Up to 60 days 24 hours from discovery
MFA on ePHI access points Addressable Mandatory, including vendor portals
Encryption of ePHI Addressable Mandatory at rest and in transit
Technology asset inventory Not specified Annual, covering vendor systems with ePHI access
Verification of vendor controls Self-attestation accepted in practice Annual compliance audits and documented verification

Check your BAA templates now

BAA templates that promise notification “without unreasonable delay”, or within 48 hours, are unlikely to satisfy the 24-hour standard once the rule finalises. The 240-day clock starts at publication of the final rule, and template renegotiation across a vendor population takes longer than that. A final rule is expected in 2026.

Neotas | Chartis FCC50 Market Disruptor Winner 2026

You have the 16-point checklist. The template gives it structure.

Document the 6 checks, the tiering decision and the evidence trail on every PHI-handling vendor, in a format an OCR reviewer can follow. Items 8 to 11 are the ones to hand to an independent screening provider.

Get the assessment template

Common mistakes in HIPAA vendor risk assessments

Four failures recur across the healthcare vendor files Neotas reviews, and each one is avoidable at assessment stage rather than at incident stage.

1. Treating the signed BAA as the control

The BAA records obligations. It verifies nothing. North Memorial’s $1.55 million settlement paired the missing vendor BAA with the missing risk analysis behind it: the paperwork gap and the oversight gap were penalised together.

2. Assessing only cybersecurity

A SOC 2 report says nothing about ownership, financial health, foreign regulatory actions or labour practices in the supply chain. The highest-impact vendor incidents start in the domains the security questionnaire never asks about.

3. Skipping subcontractor verification

The HITECH flow-through clause appears in almost every BAA and gets verified in almost none. Fourth-party exposure was the structural gap in the Change Healthcare incident and is a direct target of the 2025 NPRM.

4. Reassessing on the calendar, not on risk

An annual cycle misses everything that happens in the other 11 months: an acquisition, a sanctions designation, a foreign enforcement action. Reassessment triggers should include ownership change, adverse media and scope change, not just the review date.

How Neotas supports HIPAA vendor risk assessments

Neotas is an intelligence-led third-party risk provider, named a Chartis FCC50 Market Disruptor winner in 2026 for Know Your Third Party and Supply Chain Excellence. Healthcare teams use it for steps 5 and 6 of the assessment, and for checklist items 8 to 11: the checks a questionnaire structurally cannot run.

Capability What it gives you on a vendor Evidence
OSINT-led due diligence Adverse media across 200+ languages, surfacing foreign regulatory actions and reputational risk before structured databases record them. Pharma partnership stopped pre-contract
Beneficial ownership analysis Ownership traced through holding-company layers to the ultimate owner, with sanctions and PEP proximity mapped. Sanctions proximity found 3 layers deep
ESG and supply chain screening Labour practice and environmental risk across the vendor’s own suppliers, supporting Modern Slavery Act evidence for UK organisations. Tier 2 supplier violations identified
Continuous monitoring Alerts on adverse media, sanctions changes and regulatory actions between review cycles, closing the annual-cycle gap the NPRM targets. Risks database checks missed entirely

Neotas | Chartis FCC50 Market Disruptor Winner 2026

Run an independent assessment on one critical vendor

A 30-minute call with a risk intelligence expert, not a sales rep. Name the vendor that worries you most, and get adverse media, beneficial ownership, sanctions proximity and financial distress findings within 5 working days.

Schedule a 30-minute call

Healthcare Vendor Risk Management: HIPAA, FDA and ESG

The parent guide: the full regulatory obligation stack, vendor categories and the discipline this assessment sits inside.

Vendor Risk Assessment Template

The documentation structure for recording the 6 checks and the tiering decision on each vendor.

Healthcare TPRM Programme Guide

Governance, lifecycle stages and board reporting for the programme that runs assessments at portfolio scale.

Vendor Due Diligence Checklist and Questionnaire

The questionnaire layer of vendor assessment, its structure and its limits.

Healthcare TPRM Platform

How Neotas delivers continuous, audit-ready vendor compliance across HIPAA, FDA, CQC and GDPR.

Third-Party Risk Management Framework

The sector-agnostic framework the healthcare assessment extends and specialises.

Enhanced Due Diligence Services

The investigation methodology behind step 5: adverse media, ownership and integrity screening on Tier 1 vendors.

Supply Chain Risk Management

Fourth-party dependency mapping and the method behind step 6 of the assessment.

How long does a HIPAA vendor risk assessment take?

A HIPAA vendor risk assessment takes 5 to 15 working days for a Tier 1 vendor when the checks run in parallel, and most of that time sits in two places: waiting on the vendor’s evidence pack, and running the independent screening at steps 5 and 6. Tier 2 and Tier 3 reviews are shorter because fewer checks run. The timeline below assumes the vendor cooperates; a vendor that cannot produce evidence within these windows has already given you a finding.

Tier Typical duration What sets the pace
Tier 1: Critical 5 to 15 working days Vendor evidence turnaround, plus independent screening of ownership, adverse media and subcontractors. Screening itself typically returns within 5 working days.
Tier 2: High 3 to 7 working days BAA review and certification checks, with a lighter screening pass. The BAA provision-mapping is usually the slowest single item.
Tier 3: Standard 1 to 2 working days Questionnaire review and written confirmation that no BAA is required. The trigger to watch is any later scope change that adds PHI access.

Two scheduling rules keep the HIPAA vendor risk assessment off the critical path of procurement. Start it at vendor shortlist stage rather than at contract stage, so screening runs while commercial terms are negotiated. And never let go-live compress it: Raleigh Orthopaedic’s $750,000 settlement began as a vendor arrangement that moved faster than its paperwork.

HIPAA vendor risk assessment FAQs

Does HIPAA apply to third-party vendors?
Yes. Any vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate with direct HIPAA compliance obligations, and the HITECH Act extends those obligations to the vendor’s own subcontractors. A signed Business Associate Agreement is required before any PHI is shared, which is why a HIPAA vendor risk assessment runs before onboarding, not after. The governance model around it sits in healthcare third-party risk management.
What is the difference between a HIPAA vendor risk assessment and a HIPAA security risk assessment?
The HIPAA security risk assessment evaluates your own organisation’s systems under 45 CFR 164.308(a)(1)(ii)(A). The HIPAA vendor risk assessment evaluates one external party: its Business Associate Agreement, safeguards, ownership and regulatory record. OCR expects both, and neither substitutes for the other. The vendor-side discipline across the full vendor population is covered in the healthcare vendor risk management guide.
What must a Business Associate Agreement contain?
A compliant Business Associate Agreement contains 8 provisions under 45 CFR 164.504(e): defined permitted uses of PHI, a prohibition on unauthorised disclosure, the minimum necessary standard, specified safeguards, a breach notification timeline, subcontractor obligations under HITECH, HHS audit cooperation, and return or destruction of PHI at termination. The HIPAA vendor risk assessment verifies each clause against practice; the full provision-by-provision breakdown is in the 8 BAA provisions section above.
When is a BAA required?
A BAA is required whenever a vendor will create, receive, maintain or transmit PHI on your behalf, signed before access begins, including cloud providers that hold encrypted data they never view. The BAA trigger and its reassessment conditions belong in your written third-party risk management policy so a scope change that adds PHI access starts the HIPAA vendor risk assessment automatically rather than by memory.
Has OCR fined organisations over business associate failures?
Yes, repeatedly, and the resolution agreements are public on HHS.gov. North Memorial Health Care paid $1.55 million over a missing vendor BAA and risk analysis, Raleigh Orthopaedic paid $750,000 after handing the PHI of 17,300 patients to a vendor with no BAA, and CHSPSC LLC, itself a business associate, paid $2.3 million after a breach affecting over 6 million people. The full settlement table with sources is in the OCR enforcement precedent section.
How often should a HIPAA vendor risk assessment be repeated?
Annually for Tier 1 vendors with continuous monitoring in between, annually with event-driven review for Tier 2, and at renewal for Tier 3. The stronger trigger is change: an acquisition, a sanctions designation, adverse media or new PHI access each restart the vendor risk assessment regardless of the calendar. The 2025 Security Rule NPRM moves annual verification of vendor controls from good practice to regulatory expectation; where triggers sit in the lifecycle is mapped in the third-party risk management framework.
What are the penalties for inadequate vendor oversight under HIPAA?
HIPAA penalties are tiered by culpability, and the annual cap per violation category now exceeds $2.1 million after the January 2026 inflation adjustment in the Federal Register. Inadequate business associate due diligence is a standalone basis for HHS OCR enforcement, breach or no breach, and criminal penalties for intentional PHI misuse reach 10 years. Running vendor oversight through a healthcare TPRM platform keeps the evidence trail OCR asks for in one place.
What is a business associate subcontractor and why does it matter?
A subcontractor is any party a business associate uses to handle PHI, and HITECH requires equivalent HIPAA safeguards to flow down to it. Your exposure follows the PHI, not the contract: health systems affected by the Change Healthcare incident held valid BAAs but had no visibility of the vendor’s own dependencies. Verifying the subcontractor chain is check 6 of the HIPAA vendor risk assessment, using the mapping approach in supply chain risk management.
What can a HIPAA vendor questionnaire not detect?
A vendor risk questionnaire relies on self-disclosure, so it cannot detect adverse media in non-English press, beneficial ownership hidden behind holding companies, financial distress before public filing, regulatory actions in other jurisdictions, subcontractor concentration, or undisclosed executive connections. Those 6 categories need independent enhanced due diligence rather than another questionnaire round, and in healthcare they are the risks that produce the serious incidents.
What changes under the 2025 HIPAA Security Rule NPRM?
The NPRM at 90 FR 800, published 6 January 2025, proposes mandatory MFA on ePHI access points, mandatory encryption at rest and in transit, 24-hour vendor breach notification, annual technology asset inventories covering vendor systems, and documented annual verification of vendor security controls, with the required-versus-addressable distinction removed. Covered entities and business associates get 240 days from the final rule, expected in 2026. The vendor-facing changes are compared line by line in the 2025 Security Rule changes section.
Do vendors with no PHI access need a BAA?
No. The BAA requirement only attaches where a vendor creates, receives, maintains or transmits PHI. No-PHI vendors still carry operational, financial and integrity risk, so they stay in the vendor inventory with a proportionate check using a standard vendor due diligence checklist and questionnaire. The common failure is missing the moment a no-PHI vendor gains system access and crosses into business associate scope without a HIPAA vendor risk assessment.
Is there a HIPAA vendor risk assessment checklist or template?
Yes. This page contains a 16-point HIPAA vendor risk assessment checklist covering onboarding, ongoing monitoring and offboarding, with the evidence to file against each item. For a documented working format, the vendor risk assessment template records the 6 checks, the tiering decision and the evidence trail per vendor, with the items needing independent verification marked for a screening provider.
What evidence should a vendor provide in a HIPAA vendor risk assessment?
At minimum: a SOC 2 Type II report or ISO 27001 certificate, a penetration test dated within 12 months, MFA and encryption evidence, the subcontractor list for PHI handling, and audited financials for critical vendors. Connected device vendors add a current MDS2 and an SBOM under FDA’s 2023 cybersecurity guidance. Evidence a vendor cannot produce within the windows in the assessment timeline is itself a finding.
How do you tier vendors for a HIPAA vendor risk assessment?
Tier by 5 criteria read together: PHI access, BAA requirement, clinical criticality, FDA regulatory category, and integrity exposure such as sanctions or FCPA risk. Tier 1 runs all 6 checks with continuous monitoring, Tier 2 runs the compliance checks with lighter screening, Tier 3 is questionnaire-level, and no PHI-handling vendor belongs in Tier 3. The full model with review cycles is in the vendor tiering section above.
What is vendor management in healthcare?
Vendor management in healthcare is the full lifecycle of selecting, contracting, assessing and monitoring external parties under the overlapping requirements of HIPAA, HITECH, FDA regulation and, for UK organisations, the Modern Slavery Act. The HIPAA vendor risk assessment on this page is one stage of that lifecycle; the wider programme, from governance to board reporting, is covered in the healthcare vendor risk management guide.
Who is responsible if a business associate causes a breach?
Both parties carry exposure. The business associate is directly liable under HITECH, as the $2.3 million CHSPSC settlement shows, and the covered entity remains accountable for its own oversight, as North Memorial’s $1.55 million settlement shows, with patient notification staying the covered entity’s duty. Responsibility for PHI cannot be outsourced along with the function, which is the reason the enforcement precedent above names both sides of the relationship.

References:

[1] 90 FR 800, HIPAA Security Rule NPRM, Federal Register, 6 Jan 2025
https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
[2] HHS OCR, HIPAA Security Rule NPRM fact page (breach statistics: +102% large breaches, +1002% individuals affected 2018-2023, 167M+ in 2023)
https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html
[3] Annual Civil Monetary Penalties Inflation Adjustment, Federal Register, 28 Jan 2026
https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
[4] HHS OCR resolution agreement: North Memorial Health Care ($1.55M)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/north-memorial-health-care/index.html
[5] 45 CFR 164.504, eCFR (current)
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
[6] HHS OCR, Business Associates guidance
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
[7] HHS OCR resolution agreement: Raleigh Orthopaedic Clinic ($750K, 17,300 patients)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/raleigh-orthopaedic-clinic/index.html
[8] HHS OCR resolution agreement: CHSPSC LLC ($2.3M, 6M+ individuals)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/chspsc/index.html
[9] HHS OCR Resolution Agreements index (Catholic Health Care Services, $650K BA settlement, June 2016)
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
[10] Dallas Fed, third-party risk research presentation (Change Healthcare), 2025
https://www.dallasfed.org/-/media/Documents/research/events/2025/25thirdpartyrisks/25thirdpartyrisks-yurcik

The documented process for assessing HIPAA vendors: the 8 BAA provisions of 45 CFR 164.504(e), OCR enforcement precedent, a 6-step assessment, vendor tiering and a 16-point checklist built for the 2025 Security Rule changes.

Share:

Picture of Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.

A detailed guide to TPRM and a downloadable checklist to implement the TPRM Framework in 2026

Book a Demo

Explore Neotas Enhanced Due Diligence