HIPAA role guide
Technology Vendor HIPAA Guide
Navigate business associate responsibilities, secure data pipelines, and the assurance questions covered entities ask.
Reviewed August 2026
Learn → Assess → Remediate
Sources and limitations
Source types include regulation, official guidance, NIST and CISA materials, and clearly labeled HIPAAmart implementation notes. This educational starting point is not legal advice, a risk determination, an audit opinion, or a certification of compliance.
Available guidance
- Business Associates
Learn when a vendor is a business associate, what a BAA should cover, and how subcontractors extend your compliance responsibilities.
- Administrative Safeguards
The governance, risk, workforce, incident, and contingency practices that organize Security Rule protection.
- Physical Safeguards
Facility, workstation, device, and media controls that help protect ePHI from physical threats.
- Technical Safeguards
Access, audit, integrity, authentication, and transmission controls for systems handling ePHI.
- HIPAA Access Controls
Designing unique identification, emergency access, automatic logoff, and least-privilege practices around ePHI.
- Encryption and HIPAA
How to evaluate encryption for ePHI without reducing a broader risk decision to a yes-or-no checkbox.
- HIPAA Audit Controls
Create useful, reviewable records of activity in systems that contain or use ePHI.
- Ransomware and HIPAA
A grounded response framework for ransomware risk, availability, evidence, and breach analysis.
- Business Associate Agreements
A practical center for deciding when a BAA is needed and connecting contract terms to the vendor's actual service.
- HIPAA Vendor Management
Connect business associate inventory, security review, contract scope, monitoring, and offboarding into one repeatable practice.