Auditen
framework watch

The BAA Is Signed. The Privacy Rule Still Failed.

The upcoming changes to HIPAA rules from HHS OCR are being framed as routine updates for dental practices and small providers. They aren't. This is a targeted tightening of how sensitive health data moves when it leaves the clinic’s immediate control.

For years, healthcare providers have treated Business Associate Agreements (BAAs) like magic spells. You sign the document, your vendor promises they are "HIPAA compliant," and you assume the risk has vanished into their cloud. It hasn't. A BAA is a legal contract; it isn’t a technical control.

The FTC’s recent move to sue Hims & Hers over deceptive health data sharing proves this gap. The suit doesn't just target billing practices—it targets how sensitive information was handled behind the scenes. When firms claim "privacy by design" while building systems that default-share user data with third parties, they aren't designing privacy. They are designing a loophole and calling it a feature.

The core