top of page

Is Your Old BAA Enough? No. HIPAA's Proposed Security Rule Will Make That Very Clear.

May 20
5 min read

# Understanding HIPAA Compliance: The Importance of a Robust Approach


By Michele Alexander | MDA Solutions LLC | HIPAA AI Compliance & C-Suite Advisory



Let's talk about something many healthcare organizations refer to as compliance. They send a vendor a Business Associate Agreement (BAA). The vendor signs it, and it gets filed away—either physically or digitally. Everyone moves on, feeling secure.


However, here's the problem: the signed BAA isn't doing what you think it is. It does not encrypt files. It does not stop phishing attacks. It does not verify whether your vendor's system has been patched. It does not confirm whether patient data is moving through secure workflows or if it's moving at all in the direction you believe. A BAA is merely a legal document. It is not a safeguard.


If the proposed changes to the HIPAA Security Rule are finalized, which could happen as early as May 2026, that BAA will matter much more than it does now.


What's Changing in HIPAA Compliance


The proposed HIPAA Security Rule update is not a minor tweak. It represents a significant shift in what healthcare organizations and their business associates will be expected to prove. The current rule includes "addressable" implementation specifications. These are requirements that organizations may handle differently based on what is reasonable and appropriate for their situation. Unfortunately, this flexibility has often been misinterpreted as optional. It was never optional, but it allowed organizations to document their reasoning and move on.


The proposed changes eliminate that distinction. Everything becomes mandatory. And mandatory means documented, tested, and verifiable—not assumed.


Under the proposal, organizations would need to:


  • Maintain a complete technology asset inventory.

  • Map where electronic protected health information (ePHI) moves across systems and vendors.

  • Implement encryption of ePHI at rest and in transit.

  • Deploy multifactor authentication.

  • Conduct continuous monitoring and vulnerability scanning.

  • Perform penetration testing.

  • Manage patches and system configurations.

  • Maintain audit logs.

  • Run annual testing of technical controls.


This is not a small list. It applies to business associates, not just covered entities.


The Vendor Problem Nobody Wants to Name


Here’s a truth healthcare leaders know but often don’t vocalize: most breaches do not start inside the hospital. They begin through a vendor, a subcontractor, a platform, or a cloud environment. Sometimes, they stem from a workflow nobody mapped, set up three systems ago, and hasn’t been reviewed since.


In March 2026 alone, 44 large healthcare data breaches were reported to the Office for Civil Rights (OCR), affecting over 1.5 million individuals. Of those, 40 were hacking or IT incidents—90.9 percent. Several high-profile cases, including breaches affecting Atrium Health Navicent and Interim HealthCare, originated at third-party vendors.


The covered entity still had to answer for it.


This is the part that tends to catch people’s attention. When your vendor fails, your patients are affected. Your organization is named. Your leadership team faces questions. Your board wants to know what happened. Investigators and auditors are not particularly interested in hearing that you had a signed BAA because the responsibility ultimately lies with you and your organization.


Under the proposed rule, organizations would need written verification from business associates that cybersecurity safeguards are in place. This verification must be validated by subject-matter experts and certified by an authorized person. Vendors would also be required to notify covered entities within 24 hours of activating a contingency plan.


This shifts the conversation from “Did you sign our BAA?” to “Can you prove your safeguards are working?”


The AI Challenge in Healthcare


If your organization is using AI tools for documentation, coding assistance, patient intake, quality review, analytics, care coordination, or anything else that touches clinical or operational data, this conversation is relevant to you.


Every AI tool that interacts with patient data raises questions that most organizations have not formally answered yet:


  • What data enters the tool?

  • Is ePHI involved?

  • Where is it stored after the session?

  • Is it retained and used for model training?

  • Who has access on the vendor side?

  • Does the vendor use subcontractors?

  • Is there a current BAA in place—one that accurately reflects how the tool operates today?


AI readiness and HIPAA readiness are not separate workstreams. They are part of the same conversation. If you cannot map the workflow, you cannot govern the risk. The technology is advancing rapidly, but accountability has not changed.


What Governance Actually Looks Like Here


This is not about panicking. Panic is not a strategy; it is just cortisol with a laptop. But preparation is a strategy. Organizations that prepare now are not waiting for a final rule to tell them what to do. They are doing the foundational work that makes compliance sustainable instead of reactive.


Know What You Have


Build a current inventory of all systems, platforms, tools, and applications that handle ePHI. This includes those in place before the current IT team arrived.


Map Where Data Moves


Not just what systems you use, but how data flows between them. Where does it begin? Who touches it? Where does it go next? Where does it rest? What happens if a system fails?


Review Your Vendor Relationships


Are your BAAs current? Do they reflect how your vendors operate today—including subcontractors, cloud environments, and AI tools? A BAA from three platform updates ago may not cover what the vendor is doing now.


Ask Harder Questions


Stop accepting “Yes, we’re HIPAA compliant” as an answer. Inquire about multifactor authentication, encryption, audit logs, penetration testing, breach notification timelines, disaster recovery, and subcontractor oversight.


Connect Compliance to Workflow


If a safeguard disrupts how people actually work, they will find a workaround. That workaround is where risk hides. Compliance must be designed into operations, not bolted on after the fact. You cannot blame the vendor or subcontractor if you choose to ignore the safeguard to get something done faster.


Include AI Tools in Every Review


No exceptions.


The Real Issue Is Trust


Patients entrust healthcare organizations with their most sensitive information: diagnoses, medications, mental health history, family details, and personal information. When that information is exposed, it is not just a technical failure or a regulatory event. It is a breach of trust. For communities that already experience medical mistrust, fragmented access, and disparities in care, rebuilding that trust is challenging.


Security must be a topic in leadership meetings, not just IT discussions. It should be part of vendor selection, workflow design, staff training, AI governance, and budgeting. It belongs in the conversation before something goes wrong, not after.


Organizations that treat it this way will be better positioned when the final rule arrives. More importantly, they will be better equipped to protect the people who depend on them.


Ready to Know Where You Stand?


MDA Solutions works with hospital leaders, clinic executives, and healthcare C-suites to evaluate workflow, AI readiness, vendor risk, and compliance gaps—before they become the kind of problem that ends up in a breach report.



Sources: HIPAA Journal, May 2026 | HHS/OCR Proposed HIPAA Security Rule NPRM | OCR Report to Congress on HIPAA Compliance and Data Breaches, 2023 | March 2026 Healthcare Data Breach Report, HIPAA Journal | Reuters analysis of proposed HIPAA Security Rule changes


 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page