The Change Healthcare attack is usually retold as a technical story. A BlackCat / ALPHV ransomware group accessed a Change Healthcare Citrix portal where multi-factor authentication had not been enabled. From that single point of entry, the incident ultimately exposed protected health information for approximately 192.7 million individuals: the largest healthcare data breach in U.S. history. Notifications to affected individuals did not begin until roughly five months after the attack.

For a small practice, the technical lesson, enforce MFA everywhere, is real but not the most useful one, because the practice did not control Change Healthcare's Citrix portal. The most useful lesson is contractual. The vast majority of practices affected by Change Healthcare were not breached themselves. Their business associate was. And the instrument that governed what happened next, who notified whom, on what timeline, who bore the cost, was the Business Associate Agreement.

Two years on, the durable question for a small practice is not "is our MFA enforced." It is "what does our BAA actually say when the vendor on the other side of it gets breached." Here is how to read your BAAs in light of what Change Healthcare exposed.

The incident was a business-associate incident.

The OCR Change Healthcare FAQ, updated in March 2025, makes the structural point explicit. Change Healthcare is a business associate. The covered entities whose patients' PHI was exposed were, in the overwhelming majority of cases, not themselves attacked. They had a business associate relationship with Change Healthcare (directly or through a chain), and the business associate's breach became their breach-notification problem.

The FAQ addresses a question that surprised many practices: who is responsible for notifying affected individuals when the breach happened at the business associate? Under HIPAA, the breach-notification obligation ultimately runs to the covered entity, but it can be delegated to the business associate by agreement. Whether that delegation existed, and on what terms, was a function of what each practice's BAA said. Practices with silent or vague BAAs discovered, under deadline pressure, that the question of who sends the notices and who pays for them had never actually been settled in writing.

That is the core lesson. The breach was somebody else's. The obligations landed on the practice anyway. The BAA was the only document that determined how.

What a BAA is actually supposed to contain.

The HHS Sample Business Associate Agreement Provisions is the authoritative reference for what a compliant BAA must address. Read in the light of Change Healthcare, four categories of provisions deserve specific attention from any practice reviewing its agreements.

Breach notification timing. HIPAA's default is that a business associate must report a breach to the covered entity "without unreasonable delay" and no later than 60 days from discovery. Sixty days is a long time when the breach is unfolding and notification clocks for affected individuals are running. The HHS sample provisions explicitly contemplate that a covered entity may negotiate a stricter timeframe: a bracketed option in the sample language. A practice that wants to know about a vendor breach in days rather than two months has to put that in the BAA. The default will not give it to them.

Subcontractor flow-down. Change Healthcare was itself a node in a chain. A business associate's subcontractors that handle PHI must themselves be bound by equivalent terms: the flow-down requirement at 45 CFR 164.502(e) and 164.308(b)(2). A practice reviewing its BAAs should confirm the agreement actually requires the business associate to bind its subcontractors, because the breach can originate several links down a chain the practice never sees.

Audit and records access. The HHS sample provisions contemplate the covered entity's ability to obtain information about the business associate's safeguards. A BAA that gives the practice no right to ask the vendor about its security posture, no right to see evidence of controls, and no right to records in the event of an incident leaves the practice blind until the vendor chooses to disclose. Change Healthcare's affected entities largely learned the scope of their exposure from public reporting, not from contractual information rights.

Indemnification and cost allocation. This one is not in the HIPAA-mandated minimum, which is precisely why it matters. HIPAA tells you what a BAA must contain to be compliant. It does not tell you who pays for the notification mailing, the credit monitoring, the call center, and the regulatory response when the breach is the business associate's fault. That allocation is a negotiated commercial term. A BAA that is silent on cost allocation is a BAA where, in a Change-Healthcare-scale event, the practice may bear costs for a breach it did not cause and could not have prevented.

What to actually do with your BAAs now.

The current HIPAA Journal explainer on Business Associate Agreements (updated January 2026) reinforces the same elements practitioners should be checking: breach notification clauses, mandatory subcontractor downstream contracts, and audit and records-access rights. Translated into an action the practice can actually take:

  1. Inventory every BAA. Not "do we have BAAs" but "which vendors that touch PHI do we have signed BAAs with, and where are the documents." Change Healthcare exposed how many practices could not quickly answer which of their vendors' breaches affected which patients.
  2. Read the breach-notification clause in each one. If it says "within 60 days" or "without unreasonable delay" with no negotiated stricter timeframe, that is the timeline you will actually get. Decide whether that is acceptable for your most critical vendors.
  3. Confirm subcontractor flow-down language exists. The breach can come from a subcontractor you have never heard of. The flow-down clause is the only contractual reach you have into that layer.
  4. Check for audit and information rights. Can you ask the vendor about its security posture and get a meaningful answer in writing? If the BAA gives you no right to ask, you have no way to press until the vendor volunteers information.
  5. Look for cost allocation, and notice if it is absent. Silence on cost allocation is itself the answer: in a vendor-caused breach, absent a negotiated term, the economic exposure tends to flow toward the covered entity.

The Change Healthcare attack will be remembered as a technical failure: a missing MFA configuration on a remote-access portal. For the practices that lived through the notification scramble, the more practical memory is the moment they pulled the BAA to find out what it actually said, and discovered the answer to "what happens now" had never really been written down. The lesson is not only to enforce MFA. It is to read the agreement that governs the day a vendor's failure becomes your obligation, before that day, not during it.