Safeguard Health Data
HIPAA Compliance and Health Information Security
HIPAA governs how health information is protected in the United States, and it reaches Indian health-tech, revenue cycle and IT companies through business associate agreements. We help you meet the Security, Privacy and Breach Notification Rules your US clients hold you to.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
HIPAA sets the rules for protecting health information handled by US health care providers, health plans and clearinghouses, and by the business associates that work for them. Its Security Rule requires administrative, physical and technical safeguards and a documented risk analysis for electronic protected health information, its Privacy Rule limits how that information is used and disclosed, and its Breach Notification Rule sets deadlines when it is compromised. Indian companies in medical coding, billing, transcription, health-tech SaaS and IT services usually meet HIPAA as business associates or subcontractors, bound by agreements their US clients audit. There is no official HIPAA certification, so what clients want is evidence. We build that evidence and the safeguards behind it, working remotely across India from our Greater Noida and Kanpur offices.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the HIPAA engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Role Confirmation. We confirm whether you are a covered entity or a business associate and map where health information lives. Activities: Determine covered entity or business associate status; Inventory systems holding protected health information; Map PHI flows across applications and vendors; Confirm which HIPAA rules apply to each flow. Hands over PHI Inventory and Applicability Memo. Phase 2, Security Risk Analysis. We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards. Activities: Assess threats and vulnerabilities to each PHI system; Evaluate administrative, physical, and technical safeguards; Score risks by likelihood and impact; Document the analysis per NIST SP 800-66 guidance. Hands over Security Risk Analysis Report. Phase 3, Safeguard Design. We design the policies and controls to close gaps, from access controls to encryption and workforce training. Activities: Draft HIPAA policies and procedures; Design access control and audit logging safeguards; Specify encryption for PHI at rest and in transit; Build the workforce training programme. Hands over HIPAA Policy Set and Remediation Plan. Phase 4, Privacy and Breach Processes. We set up processes for permitted uses, patient rights, and breach notification within the required timelines. Activities: Define permitted use and disclosure rules; Build the patient rights request workflow; Write the breach assessment and notification procedure; Test the breach process with a tabletop exercise. Hands over Privacy Procedures and Breach Notification Playbook. Phase 5, Business Associate Management. We help you put business associate agreements in place and manage vendor risk. Activities: Identify vendors that touch PHI; Execute business associate agreements with each; Assess vendor safeguards and certifications; Set a reassessment cadence for critical vendors. Hands over Executed Business Associate Agreements and Vendor Register. Phase 6, Readiness Review. We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator. Activities: Verify remediation of risk analysis findings; Test safeguards against the Security Rule; Compile the compliance evidence pack; Brief leadership on residual risk and next steps. Hands over HIPAA Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Role Confirmation
We confirm whether you are a covered entity or a business associate and map where health information lives.
What Happens In This Phase
- Determine covered entity or business associate status
- Inventory systems holding protected health information
- Map PHI flows across applications and vendors
- Confirm which HIPAA rules apply to each flow
The Handover
PHI Inventory and Applicability Memo
The next phase starts from this.
Phase 01 Scoping and Role Confirmation
We confirm whether you are a covered entity or a business associate and map where health information lives.
What Happens In This Phase
- Determine covered entity or business associate status
- Inventory systems holding protected health information
- Map PHI flows across applications and vendors
- Confirm which HIPAA rules apply to each flow
The Handover
PHI Inventory and Applicability Memo
The next phase starts from this.
- 01
Scoping and Role Confirmation
We confirm whether you are a covered entity or a business associate and map where health information lives.
OutputPHI Inventory and Applicability MemoActivities
- Determine covered entity or business associate status
- Inventory systems holding protected health information
- Map PHI flows across applications and vendors
- Confirm which HIPAA rules apply to each flow
- 02
Security Risk Analysis
We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards.
OutputSecurity Risk Analysis ReportActivities
- Assess threats and vulnerabilities to each PHI system
- Evaluate administrative, physical, and technical safeguards
- Score risks by likelihood and impact
- Document the analysis per NIST SP 800-66 guidance
- 03
Safeguard Design
We design the policies and controls to close gaps, from access controls to encryption and workforce training.
OutputHIPAA Policy Set and Remediation PlanActivities
- Draft HIPAA policies and procedures
- Design access control and audit logging safeguards
- Specify encryption for PHI at rest and in transit
- Build the workforce training programme
- 04
Privacy and Breach Processes
We set up processes for permitted uses, patient rights, and breach notification within the required timelines.
OutputPrivacy Procedures and Breach Notification PlaybookActivities
- Define permitted use and disclosure rules
- Build the patient rights request workflow
- Write the breach assessment and notification procedure
- Test the breach process with a tabletop exercise
- 05
Business Associate Management
We help you put business associate agreements in place and manage vendor risk.
OutputExecuted Business Associate Agreements and Vendor RegisterActivities
- Identify vendors that touch PHI
- Execute business associate agreements with each
- Assess vendor safeguards and certifications
- Set a reassessment cadence for critical vendors
- 06
Readiness Review
We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator.
OutputHIPAA Readiness ReportActivities
- Verify remediation of risk analysis findings
- Test safeguards against the Security Rule
- Compile the compliance evidence pack
- Brief leadership on residual risk and next steps
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
Built by SecureRoot
DPDP Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the HIPAA scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Compliancy Group, AWS Config, Microsoft Purview, Jira, Confluence, Tenable Nessus. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: HIPAA Security Rule, HIPAA Privacy Rule, HIPAA Breach Notification Rule, HITECH Act, NIST SP 800-66 Rev. 2.
What We Run
8 tools
- Vanta
- Drata
- Compliancy Group
- AWS Config
- Microsoft Purview
- Jira
- Confluence
- Tenable Nessus
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- HIPAA Security Rule
- HIPAA Privacy Rule
- HIPAA Breach Notification Rule
- HITECH Act
- NIST SP 800-66 Rev. 2
Deliverables
What You Receive
- Security risk analysis report
- HIPAA policy and procedure set
- Safeguard remediation plan
- Business associate agreement templates
- Breach notification procedure
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Does HIPAA apply to an Indian company?
It applies through your work rather than your location. HIPAA's rules bind US covered entities, meaning health care providers that transact electronically, health plans and clearinghouses, and their business associates, the vendors that create, receive, maintain or transmit protected health information on their behalf. An Indian company doing medical coding, billing, transcription, claims processing, hosting or health-tech SaaS for a US client is typically a business associate or a subcontractor of one, and signs a business associate agreement that passes HIPAA's safeguards and breach duties down to it. US clients then assess you against those duties before and during the contract, and a failure can end the relationship. A company that never touches US patients' health information is outside HIPAA. We confirm your role for each client and service during scoping, because it decides which obligations apply.
What is a business associate agreement, and what does it commit us to?
A business associate agreement is the contract a covered entity must have before sharing protected health information with a vendor, and a business associate must have one with its own subcontractors. It commits you to use and disclose the information only as the agreement and the law permit, to implement Security Rule safeguards for electronic health information, to report security incidents and breaches of unsecured information to your client, to flow the same terms down to subcontractors, to make information available for access and amendment requests where relevant, and to return or destroy the data when the contract ends. Many US clients add stricter terms, such as reporting within a few days or specific encryption requirements. We review each agreement you have signed, map its clauses to controls and processes, and close the gaps so you can prove compliance when the client's security team asks.
Is a HIPAA security risk analysis mandatory?
Yes. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information they hold, and to manage the risks it identifies. It is the document regulators and clients ask for first, and a missing or outdated risk analysis is among the most common failings in HHS enforcement actions. It has to cover every place the information lives and travels, including laptops, cloud accounts, backups, email and vendor systems, and it has to be reviewed when your environment changes, not written once. We run the analysis using HHS and NIST SP 800-66 guidance, produce a risk register with owners and treatment decisions, and set a review cycle so it stays current as your systems and clients change.
Does HIPAA require encryption?
Under the current Security Rule, encryption of electronic protected health information at rest and in transit is an addressable implementation specification rather than a flat requirement. Addressable does not mean optional: you must implement it where reasonable and appropriate, or document why not and what equivalent measure you use instead. In practice encryption is expected, and it matters for breaches, because information encrypted in line with HHS guidance is not unsecured, so its loss is generally not a reportable breach. In January 2025 HHS proposed amendments to the Security Rule that would remove the distinction between required and addressable specifications and make encryption mandatory with limited exceptions, so check whether that rule has been finalised when you plan. Your business associate agreements may already demand it. We recommend encrypting health information everywhere it is stored or sent and documenting key management properly.
What happens if there is a breach of health information?
The Breach Notification Rule applies to unsecured protected health information. A covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach. If 500 or more residents of a state or jurisdiction are affected, it must also notify prominent media there, and breaches affecting 500 or more people must be reported to HHS at the same time; smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year. A business associate must notify its covered entity without unreasonable delay and no later than 60 days after discovery, although most agreements set far shorter deadlines. Every incident needs a documented risk assessment to decide whether it is a breach at all. We build the incident and breach procedure, the assessment template and the notification drafts, then rehearse them.
Is there an official HIPAA certification?
No. The US Department of Health and Human Services does not certify organisations as HIPAA compliant and does not endorse any private HIPAA certification, so a certificate from a vendor or consultant carries no regulatory weight on its own. What US clients and their auditors look for instead is evidence: a current security risk analysis, written policies and procedures, implemented safeguards, workforce training records, signed business associate agreements, incident and breach procedures, and proof that these operate. Many health-tech companies also pursue SOC 2 or ISO 27001, which provide independent assurance that clients recognise, and map HIPAA safeguards onto those controls. We help you assemble a HIPAA evidence pack that answers client questionnaires directly, and where you also need SOC 2 or ISO 27001, we build one control set that serves all three, so audits and client reviews draw on the same evidence.
How long does HIPAA compliance take for a vendor?
For most Indian business associates, two to four months to reach a position you can evidence to US clients, following our phases. Scoping and role confirmation take one to two weeks, the security risk analysis two to three, safeguard design and implementation four to eight, privacy and breach processes two to three, and business associate management one to two, ending with a readiness review. A SaaS company with a single platform and cloud hosting moves faster than a coding or billing operation with many sites, workstations and remote staff handling records. What stretches the timeline is usually safeguard implementation: access controls, logging, device management and encryption across every place health information is handled. A client audit date often sets the pace. We commit to a timeline after the risk analysis, once the size of the remediation work is known.
What does HIPAA support cost?
We do not publish a figure for HIPAA work, because the effort varies too much between companies for a range to help you. A health-tech SaaS platform hosted in one cloud account needs far less work than a revenue cycle or transcription business with multiple delivery centres, hundreds of workstations and many client agreements. The quote depends on how many systems, sites and people handle protected health information, how many business associate agreements you have signed and what they demand, how much of the risk analysis and policy set already exists, and whether you are also pursuing SOC 2 or ISO 27001, which can share controls and lower the total. Tooling, such as encryption, device management or logging platforms, and your own team's time sit outside our fee. We scope first, then give you a fixed price in writing for the work we will do.
Keep Moving Through Compliance
Service 7 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Build a certifiable privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.