HIPAA security readiness

We help covered entities and business associates complete a security risk analysis, close gaps in Security Rule safeguards and organize evidence for ePHI.

On this page

What the Security Rule covers

The HIPAA Security Rule is a US federal regulation administered by the Department of Health and Human Services (HHS). It sets national standards for protecting electronic protected health information (ePHI) that an organization creates, receives, maintains or transmits. It applies to covered entities (health plans, health care clearinghouses and health care providers that conduct certain transactions electronically) and to their business associates.

The rule is flexible by design. Each organization chooses safeguards that are reasonable for its size, systems and risks, based on a documented risk analysis. HHS does not certify organizations as HIPAA compliant. Organizations show their position through their risk analysis, policies, safeguards and records, and the HHS Office for Civil Rights (OCR) can review these during an investigation or audit.

Key requirements

Risk analysis

An accurate and thorough assessment of risks and vulnerabilities to the confidentiality, integrity and availability of ePHI. It is a required implementation specification and the basis for other decisions.

Risk management

Security measures that reduce the risks found in the analysis to a reasonable and appropriate level, with the decisions documented.

Three safeguard categories

Administrative, physical and technical safeguards. Each standard has implementation specifications marked required or addressable.

Required and addressable

Addressable does not mean optional. The organization implements the specification, an equivalent alternative, or documents why neither is reasonable and appropriate.

Business associates

Vendors that handle ePHI on behalf of a covered entity must comply with the Security Rule and sign a business associate agreement.

Breach Notification Rule

After a breach of unsecured protected health information, notice goes to affected individuals, to HHS and in some cases to the media. Business associates notify the covered entity.

Documentation

Policies, procedures and required records are kept for six years from creation or the date last in effect, whichever is later.

How the work runs with us

We identify where ePHI is created, received, stored and sent: applications, endpoints, cloud services, backups and vendors. We confirm whether your organization acts as a covered entity, a business associate or both, based on your counsel's view. You receive a scope statement, a data flow map and a plan with dates.

What you receive

Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.

Risk analysis

  • ePHI inventory and data flow map
  • Threats, vulnerabilities and likelihood ratings
  • Risk register with owners

Gap assessment

  • Status for each Security Rule standard
  • Notes on addressable specifications
  • Gaps ranked by risk

Remediation and policy

  • Prioritized risk management plan
  • Safeguards implemented by our engineers
  • Updated policies and procedures for your review

Evidence

  • Evidence organized by standard
  • Safeguard test results
  • Summary for leadership and customers

Safeguards we help implement

These areas map to Security Rule standards. We work inside your existing systems where possible.

Access control and identity

Unique user IDs, multi-factor authentication, role-based access, emergency access and automatic logoff. We can deploy Keycloak privately where it fits.

Audit logging and monitoring

Logs that record activity in systems holding ePHI, with regular review. We can deploy Wazuh privately where it fits.

Encryption

Encryption of ePHI at rest and in transit, with key management recorded. Encryption also affects whether data counts as unsecured under the Breach Notification Rule.

Vulnerability management

Scanning, patching and secure configuration for systems in scope. Penetration testing can confirm results.

Incident response

Security incident procedures linked to breach assessment steps. We also offer incident response training.

Backup and contingency

Data backup, disaster recovery and emergency mode operation plans, with restore tests.

Vendor risk

Inventory of vendors that handle ePHI, security review steps and tracking of business associate agreements.

Device and media controls

Tracking of devices and media that hold ePHI, with secure reuse and disposal.

Security Rule safeguard categories

Selected standards in each category, with examples of how organizations meet them.

CategoryExample standardsTypical controls
AdministrativeSecurity management process, assigned security responsibility, workforce security, security awareness and training, security incident procedures, contingency plan, evaluationRisk analysis, named security official, onboarding and offboarding steps, training records, incident plan, periodic evaluation
PhysicalFacility access controls, workstation use, workstation security, device and media controlsBadge access, screen locks, asset tracking, secure disposal of drives
TechnicalAccess control, audit controls, integrity, person or entity authentication, transmission securitySingle sign-on with MFA, central logging, file integrity checks, TLS for data in transit

Who does what

We scope systems and data flows, perform the risk analysis, implement agreed technical safeguards, draft or update policies, organize evidence and test controls. Your team appoints the security official, approves risk decisions, runs safeguards day to day and keeps records current.

We are not a law firm and do not give legal advice. Questions such as whether your organization is a covered entity or business associate, whether an incident is a reportable breach, or what a business associate agreement must say belong with your legal counsel and privacy officer. HHS does not issue HIPAA certifications, and neither do we. We work alongside your counsel, any external assessor and your compliance platform.

Common questions

How long does it take?

It depends on the number of systems and vendors that handle ePHI and on how much remediation is needed. We agree a plan with dates during scoping.

Can you make us HIPAA certified?

There is no official HIPAA certification from HHS. We help you complete the risk analysis, put safeguards in place and keep evidence that shows how you meet the Security Rule.

We already did a risk analysis. Can you update it?

Yes. We review the existing analysis, check it against current systems and data flows, and update risks and decisions where the environment has changed.

Can you tell us whether an incident is a reportable breach?

No. That is a legal determination for your counsel and privacy officer. We can help with the technical investigation and provide facts they need for the decision.

Can you sign an NDA or a business associate agreement?

We sign an NDA on request. If the work requires access to ePHI, we discuss the need for a business associate agreement with your team and counsel during scoping.

Do you offer ongoing support?

Yes. Engagements have a fixed scope, and we offer retainers for yearly risk analysis updates, control testing and evidence upkeep.

How to prepare

Gather your most recent risk analysis, current security policies, a list of systems and vendors that handle ePHI, signed business associate agreements, and any recent audit or penetration test reports.

Name your security official and privacy officer, and the owners of identity, infrastructure, applications and vendor management. Let us know about any customer questionnaires, OCR correspondence or assessment deadlines.

Business associates and their agreements

A business associate is a person or organization that creates, receives, maintains or transmits protected health information on behalf of a covered entity. Examples include cloud hosting providers, billing companies and software vendors. Business associates are directly liable for compliance with the Security Rule, and their subcontractors that handle ePHI are business associates too.

A business associate agreement sets out how the business associate will protect the information and report security incidents and breaches. Your counsel drafts and negotiates these agreements. We help you keep an inventory of vendors that handle ePHI and check that the security commitments in each agreement match the controls in place.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.