What "HIPAA-grade" actually means, and what it does not
A Business Associate Agreement is a contract. It establishes who is responsible for protecting PHI and what happens if a breach occurs. It does not, on its own, create a single technical control. An offshore vendor with a BAA on file and no PHI segregation, no audit logging, and no access control review cadence is not HIPAA-compliant. The contract creates the legal framework. The controls are what make that framework hold.
ISO 27001 is a certification that an organization's information security management system meets a defined standard. It is a meaningful security credential and a genuine signal that an organization takes security seriously. It is not equivalent to HIPAA compliance. The ISO 27001 standard does not map to HIPAA's specific technical safeguard requirements for PHI. A vendor can be ISO 27001 certified and still be processing health data in ways that would constitute a HIPAA violation.
SOC 2 Type II is an audit report covering a specific set of controls over a specific period. It is evidence that those controls operated during the audit window. It is not a HIPAA assessment, and it does not certify that PHI handling meets the HIPAA Security Rule. What these credentials share is that they are easy to point to in a sales conversation and difficult to evaluate without asking the follow-up questions most procurement teams do not know to ask.
"A BAA establishes who is responsible if something goes wrong. The controls are what prevent something from going wrong. Most vendor conversations cover the first and skip the second entirely."
Badge compliance vs. real compliance: what the controls look like in practice
The gap between a vendor that claims HIPAA compliance and one that demonstrates it comes down to six specific areas. Most healthcare procurement teams check the first row and stop. The violations and breaches tend to happen in the rows they did not check.
| Control Area | Badge Compliance (What Vendors Claim) | Real Compliance (What to Verify) | Risk if Absent |
|---|---|---|---|
| Business Associate Agreement | "We have a BAA." BAA is a standard template, covers the vendor entity but not subcontractors or offshore sub-processors handling PHI on their behalf | BAA explicitly covers PHI scope, offshore sub-processors, permitted uses, and breach notification timelines. Subcontractor BAAs in place for every entity with PHI access | Critical |
| PHI segregation | "Our systems are secure." PHI sits in shared environments, accessed by engineers who do not need it for their specific workload. No technical boundary between PHI and non-PHI data | PHI stored in dedicated, access-controlled environments. Engineers access only the minimum PHI required for their assigned workload. Segregation verified, not assumed | Critical |
| Access control and MFA | "We use strong passwords and two-factor." MFA is enforced for some systems. No formal access provisioning or deprovisioning process. Terminated engineers retain access longer than acceptable | Role-based access control with documented provisioning and deprovisioning SLAs. MFA required for all PHI-adjacent systems. Access recertification on a defined schedule. Off-boarding procedure revokes PHI access within hours | High |
| Audit logging | "We log system activity." Logs exist but are not reviewed. Log retention is shorter than HIPAA's six-year requirement. Logs are not accessible to the covered entity's security team | Immutable audit logs covering PHI access, modification, and transmission. Retention of at least six years. Logs reviewable by the covered entity on request. Anomaly alerts configured and monitored | High |
| Incident response | "We have a security team." No documented offshore incident response procedure. Covered entity not in the notification chain. Detection-to-notification timeline undefined | Written incident response plan covering the offshore environment. Covered entity named in the notification chain with defined response timelines. Annual drill completed. 72-hour HHS OCR notification window tracked explicitly | High |
| Annual security risk assessment | "We do regular security reviews." Last formal risk assessment was two or three years ago. Assessment did not cover offshore team environments specifically. Findings were not remediated with tracked timelines | Formal HIPAA Security Rule risk analysis completed annually. Assessment covers the offshore environment explicitly. Findings documented with remediation owners and deadlines. Results available to the covered entity's compliance team on request | Moderate |
Not sure whether your offshore team's HIPAA posture holds up?
10decoders runs healthcare compliance assessments for organizations evaluating or already operating with offshore teams. Our assessment covers BAA scope, PHI segregation, access control architecture, audit logging, and incident response readiness, and produces a remediation plan before a breach makes the gaps visible.
Book a Free AI Assessment →The BAA timing problem most healthcare firms discover too late
The most common HIPAA failure in offshore engagements is not a technical one. It is a timing one. A healthcare organization starts an outsourcing relationship, development begins, engineers gain access to systems that touch patient data, and somewhere between week three and month six someone asks whether a Business Associate Agreement is in place. It often is not. When that conversation happens retroactively, the covered entity has already incurred liability for any PHI the offshore team accessed without a signed BAA. No contract signed after the fact remedies that exposure for the period before it was signed.
The second timing failure is the subcontractor gap. A vendor signs a BAA with the covered entity. That vendor then uses a subcontractor for a specific workload, which is entirely normal. If the subcontractor's BAA with the primary vendor does not cover PHI handling explicitly, or if no subcontractor BAA exists at all, the covered entity's PHI has moved outside the compliance chain without the covered entity's knowledge. HIPAA requires Business Associate Agreements at every level of the chain. Verifying that the chain is complete is the covered entity's responsibility, not the vendor's.
The third timing failure is incident response. Most healthcare organizations have an incident response plan that covers their own internal environment. They rarely check whether their offshore vendor's incident response plan names them in the notification chain and whether the notification timelines are compatible with HIPAA's 72-hour HHS OCR reporting window. An offshore team that detects a breach on a Friday morning in India may not escalate to the US-based covered entity until Monday. That gap is not a HIPAA violation by itself. It becomes one if the covered entity misses the notification deadline because of it.
Badge Compliance
BAA on file. ISO 27001 cert shared. SOC 2 report available on request. These are the documents most procurement teams check. They establish legal accountability, not technical controls. Badge compliance passes procurement review and fails a security audit.
Technical Safeguards
PHI segregation in place. Role-based access control with provisioning and deprovisioning SLAs. MFA across PHI-adjacent systems. Immutable audit logs with six-year retention. Encryption at rest and in transit. These controls are what HIPAA's Security Rule actually specifies.
Operating Habits
Annual risk assessment covering the offshore environment. Quarterly access recertification. Annual incident response drill with the covered entity in the loop. Phishing simulation for all PHI-adjacent staff. Security review cadence that produces findings and tracks remediation. This is the layer that keeps the compliance posture current.
The operating habits that keep an offshore team HIPAA-compliant over time
"The vendors that pass a security audit are the ones whose compliance program produces findings, tracks them, and closes them. The ones that fail are the ones whose program produces a certificate."
What to do this week
01Ask your offshore vendor to send the BAA and check whether subcontractors are covered
Pull the actual Business Associate Agreement your organization has with the offshore vendor and read the subcontractor clause. Specifically: does the BAA require the vendor to obtain subcontractor BAAs for any sub-processor that handles PHI? If the vendor uses third-party cloud infrastructure, a specialized testing firm, or any other party who touches PHI in the course of your engagement, that party needs a BAA. Many vendor BAAs contain a clause committing the vendor to obtain subcontractor agreements. Most vendors have not actually done so for every relevant sub-processor. This check takes 20 minutes and surfaces one of the most common gaps in offshore healthcare compliance programs.
02Request access to audit logs from the offshore environment and time how long it takes to receive them
Send a specific request to your offshore vendor: provide audit logs for PHI access activity during a specific 30-day window in the past 90 days. Do not accept a summary. Request the actual log records. Time how long the vendor takes to respond and assess what format the logs arrive in. If the response takes more than 48 hours, or if the vendor cannot produce the records in a reviewable format, you have identified a gap that would become a significant problem during an HHS OCR investigation or a breach response. This exercise also tends to surface whether the logs exist at all in the form the vendor has been claiming.
03Find out when the vendor last completed a HIPAA security risk assessment and request the findings
Ask your offshore vendor: when was your last HIPAA Security Rule risk analysis completed, did it cover the environment where our PHI is handled, and can you share the findings and current remediation status? A vendor that has completed a recent, thorough assessment will be able to answer all three questions specifically. A vendor that responds with a completion date but cannot share findings is telling you that their compliance program produces documentation rather than controls. The findings document is what tells you what risks were identified and whether they have been addressed.
04Verify that your offshore team is in the 72-hour HHS OCR notification chain
Pull your organization's HIPAA breach notification procedure and find the step that covers incidents originating from a business associate. Verify that the offshore vendor's incident response procedure names your organization as the first notification recipient, not a later step in an internal escalation chain. Then check what the documented timeline is from breach detection on the vendor side to notification to your organization. If that timeline does not leave enough time for your organization to meet the 72-hour HHS OCR reporting window, the notification chain needs to be redesigned before a real incident tests it.
Let 10decoders assess your offshore team's HIPAA posture
We run healthcare compliance assessments for covered entities evaluating or already operating offshore teams. Our assessment covers BAA completeness, PHI segregation, access control architecture, audit log accessibility, incident response readiness, and security risk analysis quality. We produce a findings report and a prioritized remediation plan. ISO 27001 and SOC 2 Type II certified. 200+ engineers across Charlotte, Chennai, Madurai, and Singapore.
