
If your organization creates, receives, maintains, or transmits electronic Protected Health Information (ePHI), the HIPAA Security Rule isn't just a guide—it's a strict federal requirement. Yet one of the most common myths in healthcare compliance is that only hospitals, medical practices, and health plans are on the hook for a formal Security Risk Assessment (SRA).
In reality, the responsibility cascades down the entire healthcare supply chain. When a covered entity handles ePHI, every vendor, cloud host, and subcontractor touching that data inherits a direct duty to safeguard it.
With heightened regulatory scrutiny and sweeping proposed updates to the HIPAA Security Rule setting a higher technical bar, understanding your place in the ePHI risk chain is no longer optional.
1. The SRA Requirement Does Not Stop at the Covered Entity
When the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces HIPAA compliance, they look at the whole ecosystem. A single medical practice might rely on dozens of third-party partners to keep operations running smoothly:
Medical Billing & Revenue Cycle Management Companies
Managed Service Providers (MSPs) & IT Consultants
Cloud Storage & Electronic Health Record (EHR) Vendors
Answering Services & Communication Platforms
Document Destruction & Data Archival Services
Under the HIPAA Omnibus Rule, these third parties are classified as Business Associates (BAs), and their vendors are Subcontractors. If ePHI passes through your servers, rests in your database, or is accessible by your staff, you are directly liable under the Security Rule.
Key Rule: If a security incident occurs at a subcontractor level, HHS OCR evaluates whether every entity in that chain executed a valid Business Associate Agreement (BAA) and conducted its own formal SRA.
2. Vendor Risk Is Still Your Risk
Outsourcing an operational function does not mean outsourcing your legal accountability.
For Covered Entities, relying on a Business Associate without verifying their security posture is a major vulnerability. If your billing vendor suffers a ransomware attack because they lacked basic access controls, the fallout—patient notifications, brand damage, potential penalties—will land on your doorstep first.
For Business Associates, the same rule applies to your subcontractors. If you hire a third-party cloud hosting provider or software developer to support your application, you must verify their compliance.
A thorough SRA process must evaluate vendor risk oversight:
Are signed BAAs active and updated for every vendor with ePHI access?
Do you periodically review third-party security posture and certifications?
Are subcontractor access rights limited strictly to the minimum necessary data?
3. Business Associates Need Their Own SRA
A common misconception among healthcare vendors is assuming that because their client (the medical practice) completed an SRA, the vendor is automatically covered.
An SRA cannot be shared or inherited.
Your client’s SRA evaluates their facility physical security, their staff training, their network firewall, and their operational workflows. It tells regulators nothing about your environment.
As a Business Associate, your unique risk profile depends on:
Your Technology Stack: Cloud servers, API connections, remote workstations, and mobile devices.
Your Workforce: Internal administrative staff, remote developers, and third-party contractors.
Your Workflows: Data backup schedules, encryption key management, and patch management practices.
Attempting to present a covered entity’s SRA during an OCR audit or breach investigation leaves your business entirely undefended.
4. The 2026 Security Environment May Raise the Bar
Regulatory expectations are evolving rapidly to keep pace with cyber threats like targeted ransomware and supply-chain exploits. The proposed modernizations to the HIPAA Security Rule signal a decisive shift toward explicit, verifiable technical controls.
Key focus areas elevating compliance expectations include:
Granular Technology Asset Inventories: Mandating comprehensive lists of all hardware, software, network interfaces, and databases that store or route ePHI.
Network Mapping & Architecture Documentation: Requiring clear, documented diagrams showing how data flows across local and cloud environments.
Mandatory Written Risk Analysis: Moving away from informal checklists to structured, periodic risk assessments that evaluate threat likelihood and business impact.
Enhanced Access & Encryption Controls: Establishing stricter baseline rules for Multi-Factor Authentication (MFA), end-to-end encryption, and automated patch management.
Organizations relying on outdated, static checklists will find themselves ill-prepared for these formalized documentation demands.
5. Why "ASAP" Matters
Proactive compliance costs a fraction of reactive disaster recovery.
When a breach occurs, OCR investigators inspect the organization’s SRA history immediately. An SRA performed after an incident carries little credibility; regulators look for a continuous, ongoing practice of identifying vulnerabilities and remediating gaps before an attack happens.
Starting your SRA process proactively allows you to:
Uncover Hidden Gaps: Fix unpatched servers, weak passwords, or unencrypted backups before bad actors exploit them.
Protect Contracts: Healthcare organizations increasingly demand proof of a recent SRA before signing or renewing vendor contracts.
Demonstrate Good Faith: Demonstrating ongoing compliance efforts significantly mitigates potential OCR fines if a security incident does occur.
Strengthen Your Compliance Posture with Taino Consultants
Navigating the changing landscape of HIPAA compliance doesn't have to interrupt your core operations. Whether you are a Covered Entity seeking oversight of your vendor network or a Business Associate building out your independent compliance documentation, Taino Consultants is here to guide you.
Our team helps you review your current SRA posture, identify hidden vulnerabilities, organize formal documentation, and prepare for evolving security standards.
Is your SRA audit-ready? Contact Taino Consultants today to schedule a consultation and secure your organization’s ePHI chain.
About Dr. Jose I. Delgado
Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.
Need help with healthcare compliance?
Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.
Schedule a consultationRelated articles

The Foundation of Compliance: What Is a HIPAA Security Risk Analysis and Why Is It Failing Your Organization?

The Four Compliance Phrases Shielding Your Practice from Reality—And Leaving You Exposed to Federal Audits
