OCR will penalize a business associate directly, regardless of size.
Business associates were involved in 43% of healthcare breaches in the first half of 2026, up from a 2018–2026 average of 34%. On April 23, 2026 OCR announced four simultaneous ransomware settlements totalling $1,165,000 — and one of the four, Consociate Health, was a business associate. Attacks on healthcare businesses like billing, RCM, and third-party administrators rose roughly 35% in the same period while attacks on hospitals held flat. The pressure is moving downmarket, toward you.
Business associates were involved in 43% of healthcare breaches in the first half of 2026, up from a 2018–2026 average of 34%.
The specifics a generalist has never had to learn.
These are the findings that come up repeatedly when a healthcare-specialized team assesses this kind of environment. None of them are theoretical, and none of them are in a generic managed services playbook.
Your clients are about to start sending you questionnaires
Every practice that gets asked for evidence by a payer or a health system passes that question down to its billing company. Being able to answer in a day rather than a month is a retention feature, and increasingly a sales one.
Remote and offshore coders are the soft edge
At-home and offshore coding, billing, and transcription staff commonly reach the PM or EHR over a legacy IPsec or SSL VPN into a flat network. Edge appliance CVEs in Citrix, Ivanti, Fortinet, and SonicWall are exploited in healthcare within days of publication.
BAA flow-down is a two-way obligation nobody tracks
You need an executed BAA with every covered entity you serve and with every subcontractor you use. The register, with renewal dates, is the artifact. Most billing companies cannot produce either half of it on request.
Turnover makes offboarding the control that matters
Access review and termination records under §164.308(a)(3)(ii)(C) are what an investigator asks for after an incident involving a former employee. They are trivial to maintain in advance and impossible to reconstruct afterward.
We already know what these need.
And, more usefully, what each one breaks when you patch it wrong. This is not a partner list. It is the set of systems currently under management across our book in this segment.
- Availity
- Waystar
- Office Ally
- Change Healthcare / Optum
- Kareo / Tebra
- AdvancedMD
- Citrix
- Microsoft AVD
- BAA register covering upstream covered entities and downstream subcontractors, with renewal dates
- Access review and termination records for a workforce with real turnover
- Remote access architecture documentation with MFA coverage evidence
- Client-ready security questionnaire response package
Everything in the standard evidence file applies as well: risk analysis, risk management plan, MFA coverage, training records, restore tests, and the Recognized Security Practices attestation.
How the compliance program worksMost start at Compliant.
A business associate carries direct liability and gets asked for evidence by every client. The evidence file is the product here, not an add-on.
Chartline Core
Managed IT with a security baseline.
$135/ user / month
15-user minimum · 36-month term
Help desk, patching, EDR, Microsoft 365, enforced MFA, immutable backup, and the asset inventory. Everything a practice needs to be running and defensible.
What is in CoreChartline Secure
Everything in Core, plus 24/7 detection and response.
$189/ user / month
15-user minimum · 36-month term
For practices whose carrier, payer, or health-system affiliate has started asking questions. Containment authority, log retention, segmentation, and the exposure monitoring that finds what a scanner does not.
What is in SecureChartline Compliant
Everything in Secure, plus the HIPAA program and the evidence file.
$255/ user / month
25-user minimum · 36-month term
The security program and the paper trail that proves it existed. A named security officer, a real risk analysis, a dated remediation plan, and an evidence file built for an OCR data request.
What is in CompliantWe only do healthcare, but healthcare is not one thing.
Physician groups and specialty practices
Ortho, GI, ophthalmology, women’s health, and primary care. An Epic Community Connect affiliation inherits the host system’s security and audit obligations, and MIPS attestation is a hard annual deadline.
Dental practices and DSOs
On-premise Dentrix, Eaglesoft, and Open Dental, imaging servers, and operatory workstations. The highest ransomware exposure per dollar of revenue in our book.
Behavioral health and SUD providers
42 CFR Part 2 civil enforcement went live February 16, 2026. Consent management, redisclosure controls, and disclosure accounting sit on top of HIPAA.