HIPAA Security Rule Update Get ahead of the rule.

    Loading...

    Your Accountant Might Be a HIPAA Business Associate — and Not Know It

    > TL;DR: In August 2025, HHS' Office for Civil Rights (OCR) settled with BST & Co. CPAs, LLP — an accounting and advisory firm — for $175,000 after ransomware infected part of its network in 2019. BST wasn't a hospital. It was a business associate: it received financial information containing patient data from a healthcare client. OCR didn't cite the breach itself. It cited what was missing before the attack — an accurate and thorough risk analysis (45 CFR 164.308(a)(1)(ii)(A)). If your firm handles data for a healthcare client, HIPAA may already apply to you. (Source: HHS OCR, August 2025.)

    Most people picture HIPAA as a rule for doctors and hospitals. It reaches further than that. It also reaches the firms those doctors hand data to — and most of those firms never got the memo.

    In December 2019, an accounting firm in New York discovered that part of its network had been infected with ransomware. The firm was BST & Co. CPAs — accountants and advisors, not a medical practice. But one of their clients was a healthcare organization, and the financial records that client had shared held protected health information (PHI). BST reported the breach in February 2020. (Source: HHS OCR press release, August 2025.)

    In August 2025, OCR settled the case for $175,000 and a two-year corrective action plan. The finding underneath it is the one that shows up in most of these settlements: BST "had failed to conduct an accurate and thorough risk analysis." OCR Director Paula M. Stannard put it plainly:

    > "A HIPAA risk analysis is essential for identifying where ePHI is stored and what security measures are needed to protect it. Completing an accurate and thorough risk analysis that informs a risk management plan is a foundational step to mitigate or prevent cyberattacks and breaches."

    The part that catches firms off guard

    Here's the trap, and it's worth being precise about, because getting it wrong is what leads firms to assume they're in the clear.

    You don't become a business associate simply by having patient data land in your inbox. Under HIPAA, a business associate is a person or firm that performs a service or function on behalf of a covered entity that involves that entity's PHI (45 CFR 160.103). The accountant doing the books for a medical practice, the IT provider managing its servers, the billing company, the outside consultant, the law firm holding case files — when the work involves the practice's patient data, that firm is a business associate. BST had signed business associate agreements with its healthcare clients. It was squarely covered.

    And a business associate carries the same core Security Rule obligation as the clinic itself: safeguard the ePHI, and — first of all — conduct a risk analysis to know where it lives and what could go wrong.

    The problem is that most firms that quietly qualify have never done one, because nobody ever told them they had to. The healthcare client is thinking about its own compliance. The vendor assumes HIPAA is the client's problem. The obligation sits in the gap between them until a breach forces the question.

    OCR didn't fine them for getting hacked

    This is the lesson, and it's easy to miss. Getting hit by ransomware is not, by itself, a HIPAA violation. What OCR cited was a failure that existed long before the attacker showed up: no accurate, thorough assessment of where BST's electronic PHI lived or what threatened it.

    The ransomware was the event that exposed the gap. The gap was there the whole time.

    And this isn't a one-off. OCR called the BST settlement its 15th ransomware enforcement action and its 10th under the Risk Analysis Initiative — a focused push to penalize organizations, covered entities and business associates alike, that can't produce an accurate risk analysis (Source: HHS OCR, August 2025). The risk analysis is the first thing OCR asks for. It is the most common thing it finds missing. We wrote about the covered-entity version of this same story — a $450,000 settlement with a retailer's health plan — and the finding was identical.

    What would have changed the outcome

    Not better luck. A real risk analysis.

    A business associate agreement alone wouldn't have saved BST — it had those. A questionnaire wouldn't have caught it either; a self-attestation form doesn't find the unprotected server holding a client's patient records. What OCR looks for is a real assessment: a technical look at where PHI actually enters, sits, and leaves the business, and a written plan to close each gap it turns up. That work was knowable — and doable — before the breach, not after.

    That's the uncomfortable part and the hopeful part at once. Every gap OCR named was fixable in advance.

    First, find out if HIPAA already applies to you

    If your firm receives health information from a client — as an accountant, an IT provider, a billing service, a consultant, or a law firm — the question isn't hypothetical. The honest first step is to check whether you're a business associate at all, and if you are, whether you could produce a risk analysis today if OCR asked.

    Live Compliance runs and documents that Security Risk Analysis — the first thing OCR asks to see — and keeps your policies, training, and monitoring current around it, so the gaps that turn a breach into a settlement are closed before anything happens. If you want to see where you stand, the free 12-minute gap scan gives you a score and the specifics, no sales pressure. In sixteen years of doing this, every client we've taken through an audit or OCR review has passed — because the work got done before it was tested, not after.

    > Accuracy & legal note. This article summarizes a public HHS Office for Civil Rights enforcement action as announced by HHS in August 2025, alongside general HIPAA requirements (45 CFR Parts 160 and 164) current as of the date below. Details are drawn from OCR's public announcement — see the HHS press release for the primary source. This is general educational information, not legal advice — verify current requirements at hhs.gov/hipaa or with your compliance counsel. Last updated: July 2026.