Governance, Risk & Compliance

If you touch a US client’s patient data, you are already a Business Associate.

HIPAA does not require you to be American. An Indian IT firm, BPO or health-tech vendor that creates, receives, maintains or transmits ePHI on behalf of a US covered entity is a Business Associate under the law — and that status attaches to what you do, not to whether anyone remembered to send you a contract.

ePHI, and the agreements that should follow it Covered entity US hospital / payer You Business Associate Subcontractor also a BA BAA BAA? Status attaches to what you do with ePHI not to whether anyone sent you a contract Downstream subcontractors need their own BAAs HHS and OCR certify nobody — there is no HIPAA certificate
3Rules that apply to you
4Penalty tiers
1Mandatory risk analysis
0Certifications HHS issues

Business Associate status is a fact, not a choice

If you process, host, transcribe, code, support or build against US patient data — medical billing, claims processing, EHR support, telehealth infrastructure, health-app backends — you are almost certainly a Business Associate rather than a bystander. Your US client, the covered entity, is legally required to have a signed Business Associate Agreement in place before sharing ePHI with you. If they have not asked for one, that is a problem for both of you, and the Office for Civil Rights has repeatedly held Business Associates directly liable rather than treating the covered entity as the only responsible party.

There is no HIPAA certification. HHS and OCR do not certify, accredit or approve organisations, and no third party can issue a certificate that carries statutory weight. Firms selling "HIPAA certified" status in India are selling a training completion record or a self-assessment with a logo on it. What is real is a documented risk analysis, implemented safeguards and a defensible compliance posture — which is what an OCR investigation or a covered entity’s vendor audit actually examines.

One item is worth watching rather than acting on as settled law: a Notice of Proposed Rulemaking published in the Federal Register in January 2025 proposes significant Security Rule changes, including mandatory encryption and multi-factor authentication and the removal of the "addressable" distinction. As of August 2026 that remains proposed rather than final. We flag it because the direction of travel is a sensible target regardless of the final compliance date — not because it binds you today.

Coverage

What the rules actually require of a Business Associate

The Security Rule is where most technical work lands, but the Privacy Rule and Breach Notification Rule both apply to Business Associates directly, not only through contract.

Administrative safeguards

The mandated risk analysis and risk management process, assigned security responsibility, workforce training and access management, contingency planning and periodic evaluation.

Physical safeguards

Facility access controls, workstation use and security, and device and media controls including disposal and re-use. Applies to cloud-first teams too — a home-working laptop with ePHI on it is in scope.

Technical safeguards

Access control and unique user identification, audit controls, integrity controls, authentication and transmission security. This is where testing evidence replaces assertion.

Business Associate Agreements

A signed, current BAA with every covered entity you serve, and downstream BAAs with your own subcontractors who touch ePHI. Reviewed for the clauses OCR actually enforces on.

Breach Notification Rule

Discovery, assessment against the four-factor risk analysis, and notification to the covered entity without unreasonable delay and per the terms of your BAA.

Privacy Rule obligations

Permitted uses and disclosures, the minimum necessary standard, and the restrictions your BAA imposes on what you may do with ePHI.

Approach

How a HIPAA engagement runs

Status determination comes first, because the obligations follow from it and because a surprising number of Indian vendors have never had it established in writing.

  1. 01 · Business Associate determination

    A written assessment of whether, where and how your systems touch ePHI on behalf of a covered entity — and whether any of your subcontractors do too.

  2. 02 · Gap assessment

    Current state against the Privacy, Security and Breach Notification Rules, prioritised by real exposure rather than by rule order.

  3. 03 · Security Rule risk analysis

    The mandated risk analysis, done properly and specific to your environment. This is the single most cited failure in OCR enforcement, and templates do not survive scrutiny.

  4. 04 · BAA review and remediation

    Your existing agreements and your subcontractor agreements, checked for the clauses that matter and the ones that are quietly missing.

  5. 05 · Technical safeguards

    Access control hardening, encryption and audit-logging review, and penetration testing of every system in the ePHI path.

  6. 06 · Operate and monitor

    Breach process rehearsed, training delivered, and continuous monitoring so posture does not decay between client audits.

Run against recognised standards

  • HIPAA Security Rule45 CFR Part 164 Subpart C
  • HIPAA Privacy Rule45 CFR Part 164 Subpart E
  • HIPAA Breach Notification Rule45 CFR Part 164 Subpart D
  • NIST SP 800-66Implementing the HIPAA Security Rule
  • NIST SP 800-53Control baseline behind the safeguards
  • SOC 2Frequently requested alongside by US buyers

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Written Business Associate determination

Where your systems sit in the ePHI path, and what that makes you under the law — the document your covered entity will ask for.

Security Rule risk analysis report

The mandated analysis, environment-specific and defensible, with risk management decisions recorded and owned.

BAA review findings

Gaps in your existing agreements and your subcontractor agreements, with the specific clauses that need to change.

Safeguard implementation plan

Administrative, physical and technical safeguards with owners and dates, prioritised by exposure.

Breach notification runbook

The four-factor assessment, notification path to the covered entity and BAA-specific timelines, rehearsed rather than filed.

Technical testing evidence

Penetration test and access-control findings mapped to Security Rule technical safeguards, so the controls are demonstrated rather than described.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A US healthcare client has sent you a Business Associate Agreement and you do not know what signing it commits you to.
  • You handle US patient data and nobody has ever asked you to sign a BAA.
  • You have never completed a Security Rule risk analysis, or the one you have is a filled-in template.
  • You use subcontractors who touch ePHI and have no downstream BAAs with them.
  • You were sold HIPAA certification and want to know what it is actually worth.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

HIPAA — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Are we covered by HIPAA if we are not based in the US?

If you create, receive, maintain or transmit ePHI on behalf of a US covered entity, you are functioning as a Business Associate regardless of where you are located. HIPAA reaches you through the covered-entity relationship and through your Business Associate Agreement, and OCR has held Business Associates directly liable. Geography changes the practicalities of enforcement, not the obligations.

Is there a HIPAA certification we can get?

No. HHS and the Office for Civil Rights do not certify, accredit or endorse organisations, products or training under HIPAA, and no third party can issue a certificate with statutory standing. Anything sold as HIPAA certification is a training record or a self-assessment. What holds up is a documented risk analysis, implemented safeguards and evidence they operate — which is what we build.

What if our US client never sent us a BAA?

That is a compliance gap on both sides, and it is more common than it should be. A covered entity is required to have a signed BAA in place before disclosing ePHI to you. We identify where ePHI is already flowing without an agreement behind it, and help you raise it with the client — which is a considerably better conversation to have proactively than after an incident.

Is the proposed 2025 Security Rule update law?

No. As of August 2026 the Notice of Proposed Rulemaking published in January 2025 remains proposed rather than final. We flag its direction — mandatory encryption, multi-factor authentication and removal of the "addressable" distinction — because those are reasonable targets to build toward now, and because organisations that adopt them early will not face a compressed remediation window if and when a final rule lands. We do not present it as a current obligation.

What are the penalties?

OCR applies civil monetary penalties across four culpability tiers, from genuine lack of knowledge through to uncorrected wilful neglect, with per-violation amounts and annual caps that are adjusted for inflation each year (as of August 2026). Rather than quote figures that move annually, the practical point is this: for an Indian Business Associate, the commercial consequence usually arrives first. A breach traced to your systems ends the covered-entity relationship, and the references that came with it, well before a regulator does anything.

Does HIPAA readiness include penetration testing?

Yes. The Security Rule requires technical safeguards — access control, audit controls, integrity, authentication and transmission security — and a periodic evaluation of whether they meet the rule’s requirements. Documentation alone does not demonstrate that. Our engagements test every system in the ePHI path and map the findings to the specific safeguard they evidence.

How is HIPAA different from SOC 2 for US healthcare clients?

HIPAA is a legal obligation that attaches because you handle ePHI. SOC 2 is a voluntary attestation many US buyers request alongside it as evidence of general security control. They overlap in substance — access control, logging, incident response — but not in status: you cannot satisfy HIPAA by holding a SOC 2 report, and a SOC 2 report is not evidence of HIPAA compliance unless it was scoped to say so.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.