Auditen
framework watch

Does Your BAA Actually Do Anything?

A health tech vendor just leaked the benefits data of 3.8 million patients. If you're a small clinic or a boutique consultancy handling patient data, your first instinct is probably to check if you have a signed Business Associate Agreement (BAA) with your software providers.

You likely do. You probably signed it digitally three years ago and filed it in a folder you never open.

Here is the problem: a BAA is a legal contract, not a security control. It tells the government who to sue and who is responsible for the fine, but it doesn't stop data from walking out the door. For a small firm, relying solely on a BAA is like buying insurance for a house made of matchsticks and thinking that makes the house fireproof.

The regulators, specifically the HHS OCR, don't just look at whether a contract exists. They look at whether you did your due diligence. When a vendor fails this spectacularly, the probe doesn't stop at the vendor. It moves upstream to every firm that fed data into that system.

You'll hear consultants tell you to "simply implement" a comprehensive third-party risk management framework. That advice is useless for someone who spends their Tuesday mornings fighting with a printer and their afternoons doing actual work. You can't afford a dedicated vendor risk team, and you certainly can't fly to a data center in another state to check if the servers are locked.

But you can stop treating BAAs as "set it and forget it" paperwork.

The strongest objection here is that small firms have zero leverage. If you're using a major platform, they aren't going to change their security settings just because you asked. You take the contract as-is or you don't use the tool.

That's true for the terms of service, but it isn't true for evidence of security.

If a vendor is handling patient data, they should already have a SOC 2 Type II report or an ISO 27001 certification. These aren't fancy trophies; they are audits performed by someone else. Instead of paying a consultant to "assess" your vendor, just ask the vendor for their latest bridge letter and their most recent audit summary.

If the vendor refuses to provide a summary of their last independent audit or claims it's "proprietary," they're telling you they have something to hide. That is a cheap, instant signal that your data is at risk.

The second-order effect here isn't just a fine from the OCR. It's your cyber insurance. When the claim hits, the insurer will ask for evidence of your vendor oversight. If all you produce is a signed BAA, they may argue you were negligent in your selection process. They won't pay out for "negligence." You'll be left holding the bill for the forensic cleanup and the notification letters.

It's an ugly realization: the paperwork meant to protect you often just serves as a roadmap for the regulator to find where you failed.

Stop trusting the signature at the bottom of the PDF. A contract is what happens after the breach; it does nothing to prevent one. If you can't see proof that a third party has actually tested the vendor's locks, you don't have a partner, you have a liability.

Check your top three data-processing vendors this week and see if you actually possess their most recent audit summary.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. NDPC Probes UNILAG, Lotus Bank over Students' Data Misuse - Nigerian Bulletin Data Privacy (Google News)
  2. NDPC Launches Forensic Probe Into UNILAG and Lotus Bank Data Breach - streamlinefeed.co.ke Data Privacy (Google News)
  3. Q&A: SEC’s Proposed Quarterly Reporting Rule — Compliance Costs vs. Investor Protection - corporatecomplianceinsights.com Compliance Week (Google News)
  4. Health tech vendor breach hits 3.8 million patients' benefits data - Insurance Business InfoSec Compliance (Google News)
  5. 24H Hot Tokens & Headlines | US SEC Friday Meeting Proposes Allowing Crypto Projects to Raise Funds Without Full Securities Registration; US District Judge Rules CFTC Lacks Exclusive Jurisdiction Over Kalshi (August 12) - odaily.news Compliance Week (Google News)
  6. CFTC Ready to Advance Crypto Rules Independently if CLARITY Bill Stalls - CryptoRank Compliance Week (Google News)
  7. KT Q2 net profit sharply down due to data breach fines - IANS LIVE Data Privacy (Google News)
  8. Germany Invokes Cayla Spy-Device Law Against Meta Smart Glasses; Owners Face Destruction Risk - Tech Times Data Privacy (Google News)

How stories are selected and assessed