The Change Healthcare breach exposed the data of 190 million people after hackers exploited a remote access portal that lacked multifactor authentication. The attack didn't hit a hospital, it hit a third-party service provider most patients had never heard of, yet it threatened the stability of the entire healthcare system.
This situation raises a critical question: Should you audit every Business Associate in your ecosystem, or is that an impractical standard that diverts resources from more impactful controls?
The Case for Comprehensive Business Associate Auditing
The argument for auditing all Business Associates is straightforward: you can't delegate accountability. Under the HIPAA Security Rule's administrative safeguards, you're required to obtain assurances that each Business Associate will safeguard ePHI. A signed Business Associate Agreement (BAA) meets the legal minimum, but it doesn't confirm the vendor's actual implementation.
Proponents of comprehensive auditing highlight the asymmetry of risk. When a Business Associate fails, you face breach notification obligations, OCR investigations, and reputational damage. Patients don't distinguish between a breach you caused and one your vendor caused. If Change Healthcare's lack of multifactor authentication can lead to a sector-wide crisis, then every Business Associate is a potential single point of failure.
The Security Rule doesn't explicitly require you to audit Business Associates, but it does require you to "implement policies and procedures to prevent, detect, contain, and correct security violations" (§164.308(a)(1)(i)). Relying solely on Business Associates' self-reporting creates a gap in your risk management program, and OCR has penalized Covered Entities for inadequate oversight.
From this perspective, the question isn't whether you can afford to audit every Business Associate, it's whether you can afford not to.
The Case for Risk-Tiered Oversight
The counterargument is practical: comprehensive auditing is a resource trap with diminishing returns.
Most healthcare organizations work with dozens or hundreds of Business Associates. They range from claims clearinghouses handling millions of records to software vendors who touch a single workstation. If you treat the email archiving vendor the same way you treat your EHR platform, you'll waste resources on low-risk relationships while under-investing in critical vendors.
Risk-tiered oversight acknowledges that not all Business Associates pose equal risk. Relevant factors include:
- Volume and sensitivity of ePHI accessed
- Whether the vendor stores data or only transmits it
- Whether access is persistent or episodic
- The vendor's role in care delivery or payment operations
- Whether a failure would disrupt clinical operations
Under this model, you classify Business Associates into tiers and apply different oversight mechanisms to each. High-risk vendors (your EHR platform, cloud infrastructure provider, payment processor) get annual audits, detailed security questionnaires, and continuous monitoring. Medium-risk vendors get questionnaires and periodic reviews. Low-risk vendors get annual attestations and contract renewals.
This approach focuses resources where exposure is highest and recognizes that auditing has real costs, not just your staff time, but the vendor's time and the risk of focusing on checkbox compliance instead of substantive controls.
The risk-tiered camp argues that the goal isn't perfect visibility into every vendor; it's proportional oversight that reduces your aggregate risk profile without creating an unsustainable compliance burden.
Where Practitioners Actually Land
In practice, most organizations adopt a hybrid model that leans toward risk-tiering but incorporates baseline requirements for all Business Associates.
You'll typically see:
Universal baseline controls: Every Business Associate, regardless of tier, must complete an initial security assessment (often a standardized questionnaire), provide evidence of cyber liability insurance, and commit to breach notification timelines in the BAA. This creates a floor below which no vendor can operate.
Tiered verification: High-risk vendors undergo annual audits or must maintain third-party certifications (HITRUST CSF, SOC 2 Type II). Medium-risk vendors submit annual self-assessments. Low-risk vendors attest to ongoing compliance at contract renewal.
Trigger-based reviews: Any vendor can move up a tier based on events, a breach at another client, a change in the scope of ePHI access, or a failed assessment. This keeps the model dynamic.
Incident response integration: Business Associate oversight isn't just about preventing breaches; it's about ensuring you can respond effectively when one happens. This means testing notification procedures, validating that vendors can provide forensic logs, and confirming that their incident response plans align with yours.
HHS is now working with industry to identify third-party risks that have "outsized impact" on the sector. This suggests regulatory focus is shifting toward systemic risk, not just entity-level compliance. If your Business Associate could disrupt care delivery across multiple organizations, expect heightened scrutiny, regardless of what your internal risk model says.
Our Take
You shouldn't audit every Business Associate, but you should have a defensible methodology for deciding which ones you audit and how often.
The all-or-nothing framing misses the point. Comprehensive auditing isn't feasible for most organizations, and it's not what the Security Rule requires. But purely contractual oversight, signing a BAA and hoping for the best, is indefensible after an incident that exposed 190 million records because a vendor didn't enable multifactor authentication.
The right model is risk-based, but your risk assessment needs to account for concentration risk and systemic dependencies, not just the volume of ePHI a vendor touches. A vendor who processes a small percentage of your claims might still represent a critical dependency if they're the only vendor who can perform that function. A cloud provider who hosts your disaster recovery environment might see limited ePHI day-to-day but becomes critical during an outage.
Start by identifying Business Associates whose failure would either expose large volumes of ePHI or disrupt clinical operations for more than 24 hours. Those vendors warrant annual verification, either through your own audit, a third-party certification you review, or a detailed technical questionnaire with evidence. For everyone else, implement a tiered model with clear escalation criteria.
Recognize that this isn't a static exercise. The vendor who seemed low-risk when you signed the contract three years ago might now be integrated into clinical workflows you didn't anticipate. Your risk model should trigger reviews when scope changes, not just when contracts renew.
The lesson from Change Healthcare isn't that you need perfect visibility into every vendor. It's that you need enough visibility to spot the gaps that matter before they become sector-wide crises.



