Is Cardinal Health HIPAA Compliant? BAAs, PHI Protection, and What to Know

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is Cardinal Health HIPAA Compliant? BAAs, PHI Protection, and What to Know

Kevin Henry

HIPAA

April 15, 2026

6 minutes read
Share this article
Is Cardinal Health HIPAA Compliant? BAAs, PHI Protection, and What to Know

Determining whether Cardinal Health is HIPAA compliant starts with understanding how it engages with your organization and whether Protected Health Information (PHI) is involved. HIPAA does not grant formal “certifications”; instead, compliance depends on documented safeguards, executed Business Associate Agreements (BAAs), and ongoing operational controls aligned to the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule.

HIPAA Compliance Framework

Cardinal Health may act as a Business Associate when its services involve PHI or electronic PHI. In that role, it must implement administrative, technical, and physical safeguards consistent with the HIPAA Security Rule and support permissible uses and disclosures under the Privacy Rule. Breach identification, assessment, and notification processes must also align to the Breach Notification Rule.

How to evaluate fit for your use case

  • Map data flows: what PHI is shared, by whom, how, and where it is stored or transmitted.
  • Confirm role: determine whether the relationship is Covered Entity–Business Associate or another arrangement that still touches PHI.
  • Verify controls: request evidence of security safeguards, risk analysis, and incident response procedures.
  • Set scope and limits: apply the minimum necessary standard and define purpose-bound processing in the contract.

Business Associate Agreements Overview

A BAA is the cornerstone of HIPAA compliance for services that handle PHI. It establishes permitted and required uses, mandates safeguards, governs subcontractors, defines breach notification timelines, and details return or destruction of PHI at termination. Many organizations complement BAAs with confidentiality agreements to reinforce workforce and subcontractor obligations.

BAA essentials to request from Cardinal Health

  • Clear description of services and PHI types processed, including ePHI.
  • Security commitments mapped to the HIPAA Security Rule and any applicable Access Controls.
  • Breach and security incident definitions, reporting timeframes, and investigation cooperation.
  • Right-to-audit language and acceptance of reasonable customer compliance audits.
  • Subcontractor flow-down requirements, termination rights, and PHI disposition procedures.

PHI Protection Measures

Strong PHI protection blends policy, technology, and facility safeguards. Administrative safeguards include risk analysis and management, workforce training, vendor oversight, and sanctions for noncompliance. Technical safeguards cover authentication, encryption, audit logging, and integrity controls. Physical safeguards address facility access, workstation security, media handling, and secure disposal.

Controls to look for

  • Encryption in transit and at rest, key management, and tokenization where appropriate.
  • Network segmentation, endpoint hardening, vulnerability management, and timely patching.
  • Data loss prevention, immutable backups, and tested disaster recovery and business continuity.
  • Comprehensive audit logs with retention, monitoring, and alerting for anomalous activity.
  • Documented secure media destruction and chain-of-custody for devices containing PHI.

Compliance Documentation and Recordkeeping

Your due diligence should include reviewing Cardinal Health’s security program documentation and evidence that its controls operate effectively. Robust recordkeeping demonstrates ongoing compliance rather than a one-time posture.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Documents and evidence to request

  • Completed risk analysis and risk management plan aligned to the HIPAA Security Rule.
  • Policies and procedures, workforce training materials, and training completion records.
  • Incident response and breach notification playbooks, plus breach log summaries.
  • Change management, access review, and segregation-of-duties records.
  • Third-party assurance reports (for example, SOC 2 Type II, HITRUST) and remediation tracking, if available.
  • Confidentiality agreements for employees and subcontractors handling PHI.
  • Data retention schedules, records of disclosures, and evidence of periodic compliance audits.

Regulatory Oversight and Audits

HIPAA compliance is enforced primarily by the U.S. Department of Health and Human Services Office for Civil Rights (OCR). OCR conducts investigations and can perform audits; state attorneys general may also bring actions related to HIPAA provisions. Beyond government regulatory oversight, customers may conduct their own compliance audits, and organizations often engage independent assessors to validate security controls.

Staying audit-ready

  • Maintain up-to-date risk assessments, vulnerability scans, and penetration test summaries.
  • Track corrective actions through closure and keep evidence easily retrievable.
  • Rehearse incident response, breach notification, and executive communications.
  • Periodically test BAA obligations end to end, including subcontractor oversight.

Secure Transmission Methods

When exchanging PHI with Cardinal Health, require secure, standards-based transport with integrity checks. Your objective is to ensure confidentiality, integrity, and availability throughout the transaction lifecycle.

  • TLS 1.2+ for web portals and APIs, with modern cipher suites and HSTS where applicable.
  • SFTP or FTPS with strong encryption and separate control/data channels, plus file integrity verification.
  • Mutual TLS, IPsec VPNs, or private connectivity for system-to-system flows.
  • Encrypted email using S/MIME or PGP, or secure messaging portals as an alternative.
  • Healthcare data standards (for example, HL7 FHIR with OAuth 2.0/OpenID Connect) implemented securely.

Access Control Protocols

Access Controls must enforce least privilege and ensure only authorized users can view or act on PHI. Expect multi-factor authentication, robust identity lifecycle management, and frequent access certifications for elevated roles.

  • Single sign-on (SAML or OIDC), MFA for all remote and privileged access, and strong password policies.
  • Role-based or attribute-based access control with fine-grained entitlements and separation of duties.
  • Just-in-time privileged access, session recording for administrative actions, and rapid deprovisioning via SCIM.
  • Periodic user access reviews, break-glass procedures with post-event review, and continuous audit logging.

Conclusion

Cardinal Health can operate in a HIPAA-compliant manner when its services fall under a well-scoped BAA and the organization demonstrates effective safeguards across the HIPAA Security Rule. Your responsibility is to validate the fit: map PHI flows, review documentation, test secure transmission paths, and confirm Access Controls. Combine contractual protections with evidence-based assessments to maintain ongoing compliance and readiness for audits.

FAQs.

What is Cardinal Health's role in HIPAA compliance?

Cardinal Health typically functions as a Business Associate when its services involve PHI, meaning it must implement HIPAA-required safeguards and support your Privacy Rule obligations. Your organization, as a Covered Entity or upstream Business Associate, remains accountable for ensuring the relationship is governed by a BAA and that data sharing follows the minimum necessary standard.

How does Cardinal Health protect PHI?

Protection should include administrative, technical, and physical controls: encryption in transit and at rest, Access Controls with MFA, audit logging, workforce training, vendor oversight, and documented incident response. Ask for evidence such as risk assessments, policy sets, security architecture summaries, and results of compliance audits.

Does Cardinal Health sign Business Associate Agreements?

Yes—when services require handling PHI and Cardinal Health acts as your Business Associate, it will sign a BAA outlining permitted uses, safeguards, breach notification, subcontractor requirements, and the right to conduct reasonable compliance audits. Always request and review the finalized BAA to confirm scope and responsibilities.

What regulatory bodies oversee Cardinal Health's compliance?

For HIPAA, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) is the primary enforcer, and state attorneys general may also take action. Depending on the specific services, additional oversight can involve agencies such as the FDA, DEA, and state boards of pharmacy, but HIPAA privacy and security enforcement rests with OCR.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles