HIPAA Compliance / Healthcare IT
A Signed BAA Won't Save You: What Healthcare Vendors Must Be Able to Prove
If your organization creates, receives, maintains, or transmits electronic protected health information (ePHI) on behalf of a healthcare organization, a Business Associate Agreement (BAA) is an important part of your HIPAA responsibilities. But the signed agreement is only the beginning. When a client, auditor, regulator, or prospective partner starts asking harder questions, they may want more than a contract. They may want evidence that the safeguards described in your policies and agreements actually exist, are being reviewed, and work as intended.
That is the difference between having a BAA and being able to defend what happens behind it. Healthcare vendors should be prepared to demonstrate how they control access to ePHI, protect data, test security, respond to incidents, manage subcontractors, and document ongoing oversight.
In This Article
A BAA Is a Contract, Not Proof of Compliance
A Business Associate Agreement defines how a business associate may use and disclose protected health information and establishes important responsibilities for safeguarding that information. What it does not do is prove that those safeguards are actually implemented or operating effectively.
A vendor can have a signed BAA on file and still have unanswered questions behind it:
- Is multi-factor authentication actually enforced for systems that provide access to ePHI?
- Are shared or generic accounts still being used?
- Are devices containing or accessing ePHI appropriately protected?
- When was the last vulnerability scan or security test performed?
- Has the incident response plan ever been tested?
- Can the organization demonstrate that backups can actually be restored?
- Who reviews security logs, and is that review documented?
- Which subcontractors can access ePHI, and how are they being overseen?
A contract can describe responsibilities. Evidence shows whether the organization is actually carrying them out.
Why Healthcare Clients Are Asking Harder Questions
Healthcare organizations increasingly need visibility into the third parties that create, access, maintain, or transmit patient information on their behalf. That means vendors may face deeper scrutiny during contract reviews, renewals, security assessments, incidents, or when a new compliance or IT leader evaluates the relationship.
The question is becoming less about whether you can produce a BAA and more about whether you can confidently explain and document what happens after the BAA is signed.
What Healthcare Vendors Should Be Able to Prove
Healthcare vendors should be prepared to provide current, written evidence across five areas: access and identity controls, data protection, testing and validation, incident response and recovery, and security documentation. The goal is not simply to claim that controls exist, but to show how they are implemented and maintained.
1. Access & Identity Controls
Access to systems containing ePHI should be controlled at the individual-user level. Vendors should understand who has access, why they need it, how access is approved, and how quickly it is removed when an employee leaves or changes roles.
Evidence may include:
- Multi-factor authentication: Proof that MFA is enabled where required by the organization's security program for access to systems handling ePHI
- Individual user accounts: Evidence that shared or generic credentials are not being used in place of accountable user identities
- Access provisioning procedures: A documented process for granting, modifying, reviewing, and removing access
- Access reviews: Records showing that permissions are periodically reviewed and inappropriate access is corrected
Saying "only authorized employees have access" is a statement. An access roster, MFA report, and documented review provide evidence behind that statement.
2. Data Protection
Vendors need to understand where ePHI is stored, transmitted, and accessed throughout their environment. That includes laptops, cloud platforms, backup systems, remote-work processes, and other technologies involved in delivering the service.
Healthcare organizations may want evidence that:
- ePHI is appropriately protected at rest and in transit
- Laptops and other devices accessing sensitive data are secured
- Remote and offline workflows have defined data-protection procedures
- Data handling practices match the organization's written security policies
This is particularly important for vendors whose employees work remotely or whose service depends on multiple cloud applications and third-party platforms. Each additional place where ePHI can move creates another area that should be understood and documented.
3. Testing & Validation
A security control that has never been tested creates uncertainty. Healthcare vendors should be able to show that they regularly evaluate whether their security program is working as expected.
Continuous's vendor readiness framework includes evidence such as:
- Vulnerability scanning: Documented results from recurring scans used to identify potential weaknesses
- Penetration testing: Results from more in-depth security testing conducted on a defined schedule
- Security log review: Evidence that relevant logs are being collected, reviewed, and investigated when concerns arise
- Corrective actions: Documentation showing how identified issues were addressed rather than simply recorded
The important question is not only, "Do we test?" It is also, "What did we find, what did we do about it, and can we show the record?"
4. Incident Response & Recovery
A written incident response plan matters, but an untested plan leaves major questions unanswered. Vendors should know who takes the lead during an incident, who contacts affected clients, how technical response activities are coordinated, and how operations are restored.
Evidence should be able to demonstrate:
- A written incident response and contingency plan exists
- The plan has been tested through an exercise, tabletop scenario, or another appropriate method
- Roles and escalation responsibilities are clearly defined
- Client notification procedures are documented
- Critical systems and data can be restored from backups
- Lessons learned from testing or actual incidents are incorporated into updated procedures
"We have backups" and "we can restore our critical systems" are not the same statement. Testing helps turn assumptions into evidence.
5. Documentation & Evidence
Policies should reflect what is actually happening inside the environment. Vendors should be able to connect written security requirements to the controls, people, systems, and recurring activities that support them.
A defensible documentation set may include:
- Written security policies tied to actual safeguards
- Named owners for security and compliance responsibilities
- Records of periodic reviews
- Documented remediation and corrective actions
- Risk assessment documentation
- Training records
- Security testing results
- Incident response testing evidence
- Materials that can be produced during audits, contract renewals, or vendor due diligence
The goal is not documentation for documentation's sake. The documentation should make it possible for an outside party to understand what the organization is doing, who owns it, when it was last reviewed, and whether identified problems are being addressed.
Your Subcontractors Are Part of Your Compliance Story
A healthcare vendor's responsibilities do not stop at its own employees and systems. If subcontractors or third-party platforms create, receive, maintain, or transmit ePHI on the vendor's behalf, those relationships become part of the vendor's HIPAA compliance program too.
This is where the original BAA conversation remains especially important. Vendors frequently depend on outside technology for services such as cloud hosting, backups, remote monitoring, security operations, support, and other functions. Those relationships should not disappear into the background simply because the healthcare client never interacts with the subcontractor directly.
Questions Vendors Should Be Able to Answer
- Which subcontractors and third-party platforms may create, receive, maintain, or transmit ePHI?
- Are the appropriate Business Associate Agreements in place?
- What security due diligence was performed before the vendor was approved?
- How are critical subcontractors reviewed over time?
- What happens when a vendor changes platforms or introduces a new subcontractor?
- Can the organization produce documentation showing how those third parties are being overseen?
A signed BAA with your healthcare client does not eliminate the need to understand the companies operating further down your service chain.
Common Vendor Gaps That Create Risk
Some of the most concerning gaps are not organizations doing nothing. They are organizations assuming that something is being handled without having enough visibility to prove it.
Common examples include:
- "Our MSP handles security." The vendor depends on an IT provider but cannot produce reports, testing results, or documentation showing what the provider actually manages.
- "We have policies." Written policies exist, but the organization has never verified whether employees and technology actually follow them.
- "We have an incident response plan." The document exists, but it has never been tested and staff members are unclear about their responsibilities.
- "We have backups." Backups are running, but restore testing has not been performed or documented.
- "We haven't been asked for this before." The organization assumes a lack of previous scrutiny means its existing compliance program is sufficient.
Those gaps can remain hidden until a client asks for documentation, a contract comes up for renewal, an incident occurs, or an audit requires evidence with little notice.
For practices that want this operationalized rather than just documented, managed IT compliance support for healthcare practices covers vendor agreement review, subcontractor vetting, and the technical controls that make BAA language enforceable in practice.
Frequently Asked Questions
Is a signed BAA enough to prove HIPAA compliance?
No. A BAA establishes contractual responsibilities between a covered entity and a business associate, but it does not prove that the business associate's security safeguards are implemented, tested, or functioning effectively. Vendors should also maintain evidence supporting the controls and processes behind the agreement.
What should a healthcare vendor be able to prove to its clients?
Healthcare vendors should be prepared to demonstrate how they manage access and identity, protect ePHI, perform security testing, monitor systems, prepare for incidents, test recovery capabilities, document corrective actions, and oversee subcontractors or third parties that interact with ePHI.
Do subcontractors that handle ePHI need Business Associate Agreements?
When a subcontractor creates, receives, maintains, or transmits protected health information on behalf of a business associate and meets HIPAA's definition of a business associate, the appropriate written agreement is required. Healthcare vendors should understand and document the subcontractors in their ePHI service chain.
Why does security testing matter for healthcare vendors?
Security testing helps demonstrate whether safeguards are working as intended and identifies weaknesses that may otherwise go unnoticed. Vulnerability scans, penetration testing, log review, incident response exercises, and recovery testing can provide evidence that security controls are being actively evaluated rather than simply documented.
What documentation should a healthcare vendor maintain for HIPAA readiness?
Documentation may include security policies, risk assessments, access reviews, employee training records, vulnerability and penetration testing results, logging and monitoring evidence, incident response plans and test results, backup restore testing, remediation records, Business Associate Agreements, and subcontractor oversight documentation.
When might a healthcare vendor be asked to produce this evidence?
Healthcare vendors may face requests for security and compliance documentation during client due diligence, contract renewals, security reviews, audits, investigations, incidents, or when a healthcare organization changes compliance or IT leadership and begins reviewing third-party risk more closely.
Could You Produce the Proof Today?
A signed BAA may get you through the first question. The harder questions come next. Continuous can help you understand what documentation and security evidence you already have, identify what is missing or outdated, and prioritize improvements before a client, auditor, contract review, or incident forces the issue.
Get Your Compliance Assessment