Skip to main content

Your Biggest HIPAA Risk in 2026 Might Not Be Your Practice — It Might Be Your Vendor

Network diagram showing a medical practice connected to vendors with one compromised link flagged — HIPAA business associate risk, Atlantic Computer Systems 2026 guide.

You can lock down every workstation in your office, encrypt every laptop, and pass your own HIPAA risk analysis with flying colors — and still get pulled into a breach investigation because your billing company, answering service, or scribe app got hit instead. In 2026, the biggest hole in a practice’s HIPAA compliance usually isn’t inside the building anymore.

The numbers are moving fast in the wrong direction

From 2018 through early 2026, business associates were involved in an average of 34% of healthcare data breaches. In just the first six months of 2026, that number jumped to 43%. Third-party breaches in healthcare rose 60% year over year, and seven of the ten largest healthcare breaches reported in the first half of 2026 traced back to a vendor or business associate system, not the covered entity itself.

Your practice can do everything right and still end up named in a breach notification because a vendor several steps removed from your front desk mishandled the data you gave them.

A signed BAA doesn’t mean the risk is gone

A Business Associate Agreement is a contract, not a security control. It establishes who’s responsible for what on paper, but it doesn’t stop a vendor’s employee from reusing a password, skipping encryption, or leaving an S3 bucket open. OCR has made this distinction explicit in its 2026 enforcement posture: having a technically-compliant BAA on file does not shield a covered entity when the business associate causes the breach. Regulators are increasingly asking practices to show they actively manage vendor risk, not just that they collected a signature once and filed it away.

What changed with the 2026 Security Rule update

The updated rule raises the bar on vendor accountability in a few concrete ways:

  • Business associates must verify at least once every twelve months that they’ve actually deployed the technical safeguards the Security Rule requires — not just attest to it once at signing.
  • BAAs now need to require business associates to execute their own BAAs with any subcontractor who touches PHI, and to notify the covered entity when a new subcontractor comes on board.
  • Covered entities are expected to run a tabletop breach exercise at least annually, with documented results and corrective actions for anything the exercise exposes.

In practice, that means a static folder of signed PDFs from years ago no longer holds up. Vendor oversight has to be an ongoing process, not a one-time checkbox.

The vendors practices forget to vet

When people hear “business associate,” they usually think of the EHR vendor or the cloud host — the obvious ones that already have a BAA on file. The ones that slip through are smaller and easier to overlook:

  • Medical billing and revenue cycle companies
  • After-hours answering and patient messaging services
  • AI scribe and transcription tools a provider signed up for directly
  • Text and email appointment-reminder platforms
  • Remote support or tele-service vendors for imaging and diagnostic equipment

Many of these get adopted by a single staff member solving a day-to-day problem, with no one checking whether a BAA exists or whether the vendor takes security seriously. That’s shadow IT with a HIPAA price tag attached.

What to actually do about it

  • Inventory every vendor that touches, stores, or transmits PHI — including tools individual staff members signed up for on their own.
  • Confirm a signed BAA exists for each one, and that it requires the vendor to flow that agreement down to its own subcontractors.
  • Request an annual security attestation from every business associate, not just a signature at onboarding.
  • Fold vendor risk into your HIPAA risk analysis as its own documented section, updated on a schedule.
  • Run a tabletop exercise at least once a year that specifically includes a vendor-caused breach scenario.

Where ACS fits in

Most practices have never actually mapped every vendor touching patient data, let alone verified BAA coverage down to the subcontractor level. That’s exactly the kind of gap we look for during a free IT and HIPAA assessment — we’ll show you where your vendor risk actually stands and what it would take to close it.

Book a free 30-minute IT & HIPAA assessment

Is your practice’s IT actually secure?

Book a free 30-minute IT & HIPAA security assessment with our team, no obligation, no jargon.

Book a Free Assessment

Related articles

Request a Quote

Fill out the form below and our team will get back to you within one business day.

Free IT & HIPAA security assessment