The HIPAA Omnibus Rule, explained
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
The Omnibus Rule is why your SaaS is directly on the hook for HIPAA — it extended liability from covered entities to their business associates and subcontractors.
What it changed
The 2013 Omnibus Rule was a significant update that, among other things, made business associates directly liable for compliance with the HIPAA Security Rule and parts of the Privacy Rule — previously, liability flowed mainly through contracts. It also extended obligations down to subcontractors of business associates.
Why it matters to vendors
For a tech company handling PHI, the Omnibus Rule is the reason you are directly accountable, not merely contractually so. A regulator can pursue a business associate directly. That is why "we just process data for a hospital" does not get a SaaS off the hook.
Breach and BAA updates
Omnibus also revised the breach-notification standard (moving to the "compromise" risk assessment) and updated what BAAs must contain, including flow-down to subcontractors. If your BAAs predate it or do not bind your subcontractors, they need refreshing.
The practical takeaway
Treat your HIPAA obligations as real and direct, ensure BAAs are current and flow down to any subcontractor touching PHI, and align your breach process with the current standard. SentinelPanda tracks the BAA inventory and the safeguards that make the direct liability manageable.