Key takeaways
- Business associates, the vendors that handle patient data for healthcare organizations, were involved in 43% of reported breaches in the first half of 2026, per HHS OCR portal data analyzed by The HIPAA Journal.
- The damage share is worse: 65% of individuals affected by healthcare breaches in 2025 were compromised through a business associate, up from 5% in 2015.
- The mechanism is concentration: one vendor serves many providers, so one vendor breach is every client’s breach at once.
- I run a business associate. This post is what those numbers oblige a vendor to do, and the questions I would ask any vendor before signing, including us.
Business associates, the vendors healthcare organizations hire to handle patient data, are where the breach damage has moved. In the first half of 2026, 43% of reported healthcare breaches involved a business associate, and in 2025, 65% of all individuals affected by healthcare breaches were compromised through one, up from 5% a decade earlier. Those figures come from the federal breach portal run by HHS’s Office for Civil Rights, as analyzed by The HIPAA Journal, and the two largest vendor incidents alone, Change Healthcare and Conduent, affected roughly a quarter of a billion people.
I run a business associate. Catalytics builds systems that hold and move patient data for home care agencies and healthcare providers, which makes us exactly the category those numbers describe. So this is not a post pointing at someone else’s problem. It is what I think the numbers obligate a vendor like us to do, and what I would ask any vendor before letting them near patient data.
What do the numbers actually show?
| Measure | Then | Now |
|---|---|---|
| Share of breaches involving a business associate | ~20% average, 2009–2017 | 34% average 2018–2026, and 43% in the first half of 2026 |
| Share of affected individuals compromised via a business associate | 5% in 2015 | 65% in 2025 |
| Largest vendor incidents | — | Change Healthcare (2024) and Conduent (2025), roughly a quarter of a billion people combined |
Source: HHS OCR breach portal data, as analyzed by The HIPAA Journal (June 2026). The events line rose by two; the damage line rose by thirteen. That gap is the story.
Why do business associates account for so much of the damage?
Concentration. A clinic that gets breached exposes its own patients. A vendor that gets breached exposes the patients of every client it serves, in one incident. A billing processor serving three hundred practices is, from an attacker’s perspective, three hundred breaches behind one door, and attackers have noticed: hacking now accounts for the overwhelming majority of reported incidents.
Nothing about that is exotic. It is the same reason the BAA chain matters so much: every vendor in the path of patient data is a door, and the doors with the most behind them are the vendors that serve many clients at once.
What do those numbers oblige a vendor to do?
Speaking as one, four things at minimum, none of which are paperwork.
Sign the BAA and mean it. The agreement makes the business associate legally accountable for safeguards and breach notification. A vendor that hesitates to sign is telling you where you stand. We have asked platform vendors to sign on clients’ behalf and been declined; the decline is useful information, and it is the vendor’s right, but then patient data cannot flow there.
Keep the client’s data isolatable. The concentration risk shrinks when a business associate’s clients are not one pool. Separate bases, separate access scopes, separate credentials per client mean an incident has a blast radius of one, not all.
Hold the chain downstream. A business associate’s own vendors, hosting, automation, email, become subcontractors under the regulation, and each needs its own agreement. When we build, the chain is mapped vendor by vendor, in writing, because the client inherits every link we choose.
Design so the vendor holds less. The best answer to “how do you protect the data you hold” is to hold less of it. Systems we build live in the client’s own accounts wherever possible, with the client owning the infrastructure outright at handoff. A vendor that cannot access your data cannot leak it.
What should you ask a business associate before signing?
The questions I would want asked of us, in the order I would ask them of anyone:
- Will you sign a BAA before any data flows? Not “are you HIPAA compliant”, which is a marketing phrase. Will you sign.
- Where exactly will our data live, and in whose account? The answer tells you who really controls it.
- Which subcontractors touch it, and do you hold agreements with each? Ask for the list. A vendor who cannot produce it has not mapped their own chain.
- Is our data isolated from your other clients’? One pool or separate rooms.
- What happens at termination? Who owns the system, and how does the data come back.
- When were you last asked these questions? Not disqualifying either way, but a vendor who has never been vetted has never had to be ready.
Put side by side, the questions and the answers that should worry you:
| Question | A good answer sounds like | A worrying answer sounds like |
|---|---|---|
| Will you sign a BAA? | ”Yes, before any data flows." | "We’re HIPAA compliant” with no contract offered |
| Where does our data live? | A named account, ideally yours | ”In our platform” with no specifics |
| Which subcontractors touch it? | A written list, each under agreement | ”We use standard cloud providers” |
| Is our data isolated? | Separate bases, scopes, credentials | ”Everything is encrypted” (different question) |
| What happens at termination? | You own the system; export path named | ”We’ll work something out” |
None of these require technical depth to ask, and the pattern of answers, direct or evasive, tells you most of what the audit would.
Frequently asked questions
What is a business associate under HIPAA?
Any person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity: billing services, software vendors, IT providers, consultancies that touch patient records. The full explainer is here.
Is a breach at a business associate the provider’s responsibility?
Both parties carry obligations. The provider must have a signed BAA in place and can face enforcement for using an uncovered vendor; the business associate is directly liable under HIPAA for its own safeguards and breach notification duties.
Do small vendors get breached, or is this a big-vendor problem?
The record-setting incidents are large vendors, because that is where the concentration is. The obligation structure is identical at any size, and small vendors are more often the unvetted ones, which is its own risk.
The builder's side of this
Want the six questions answered before you ask them?
Every system we build ships with the chain mapped in writing: where the data lives, which vendors touch it, and what the client owns at handoff. Asking us the vetting questions is encouraged, and the answers are part of the deliverable.
Ask us the six questionsThe numbers in this post come from the HHS OCR breach portal as analyzed by The HIPAA Journal, and they update monthly. If you are choosing a vendor to build systems that touch patient data, ask the six questions, of us included, and read our portal architecture guide for what the compliant version of the build looks like.