Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Safeguard Health Data

HIPAA Compliance and Health Information Security

HIPAA governs how you protect health information in the United States. We help you meet the Security and Privacy Rules and prove you handle patient data responsibly.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

HIPAA sets the rules for protecting health information handled by providers, insurers, and their vendors. Its Security Rule covers safeguards for electronic health data, the Privacy Rule covers how it may be used and shared, and the Breach Notification Rule covers what happens when things go wrong. It matters because health data is sensitive, heavily regulated, and a frequent target. We help covered entities and business associates meet their obligations with controls that fit clinical and operational reality.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the HIPAA engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Role Confirmation. We confirm whether you are a covered entity or a business associate and map where health information lives. Activities: Determine covered entity or business associate status; Inventory systems holding protected health information; Map PHI flows across applications and vendors; Confirm which HIPAA rules apply to each flow. Hands over PHI Inventory and Applicability Memo. Phase 2, Security Risk Analysis. We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards. Activities: Assess threats and vulnerabilities to each PHI system; Evaluate administrative, physical, and technical safeguards; Score risks by likelihood and impact; Document the analysis per NIST SP 800-66 guidance. Hands over Security Risk Analysis Report. Phase 3, Safeguard Design. We design the policies and controls to close gaps, from access controls to encryption and workforce training. Activities: Draft HIPAA policies and procedures; Design access control and audit logging safeguards; Specify encryption for PHI at rest and in transit; Build the workforce training programme. Hands over HIPAA Policy Set and Remediation Plan. Phase 4, Privacy and Breach Processes. We set up processes for permitted uses, patient rights, and breach notification within the required timelines. Activities: Define permitted use and disclosure rules; Build the patient rights request workflow; Write the breach assessment and notification procedure; Test the breach process with a tabletop exercise. Hands over Privacy Procedures and Breach Notification Playbook. Phase 5, Business Associate Management. We help you put business associate agreements in place and manage vendor risk. Activities: Identify vendors that touch PHI; Execute business associate agreements with each; Assess vendor safeguards and certifications; Set a reassessment cadence for critical vendors. Hands over Executed Business Associate Agreements and Vendor Register. Phase 6, Readiness Review. We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator. Activities: Verify remediation of risk analysis findings; Test safeguards against the Security Rule; Compile the compliance evidence pack; Brief leadership on residual risk and next steps. Hands over HIPAA Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Role Confirmation

We confirm whether you are a covered entity or a business associate and map where health information lives.

What Happens In This Phase

  • Determine covered entity or business associate status
  • Inventory systems holding protected health information
  • Map PHI flows across applications and vendors
  • Confirm which HIPAA rules apply to each flow

The Handover

PHI Inventory and Applicability Memo

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Role Confirmation

    We confirm whether you are a covered entity or a business associate and map where health information lives.

    OutputPHI Inventory and Applicability Memo

    Activities

    • Determine covered entity or business associate status
    • Inventory systems holding protected health information
    • Map PHI flows across applications and vendors
    • Confirm which HIPAA rules apply to each flow
  2. 02

    Security Risk Analysis

    We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards.

    OutputSecurity Risk Analysis Report

    Activities

    • Assess threats and vulnerabilities to each PHI system
    • Evaluate administrative, physical, and technical safeguards
    • Score risks by likelihood and impact
    • Document the analysis per NIST SP 800-66 guidance
  3. 03

    Safeguard Design

    We design the policies and controls to close gaps, from access controls to encryption and workforce training.

    OutputHIPAA Policy Set and Remediation Plan

    Activities

    • Draft HIPAA policies and procedures
    • Design access control and audit logging safeguards
    • Specify encryption for PHI at rest and in transit
    • Build the workforce training programme
  4. 04

    Privacy and Breach Processes

    We set up processes for permitted uses, patient rights, and breach notification within the required timelines.

    OutputPrivacy Procedures and Breach Notification Playbook

    Activities

    • Define permitted use and disclosure rules
    • Build the patient rights request workflow
    • Write the breach assessment and notification procedure
    • Test the breach process with a tabletop exercise
  5. 05

    Business Associate Management

    We help you put business associate agreements in place and manage vendor risk.

    OutputExecuted Business Associate Agreements and Vendor Register

    Activities

    • Identify vendors that touch PHI
    • Execute business associate agreements with each
    • Assess vendor safeguards and certifications
    • Set a reassessment cadence for critical vendors
  6. 06

    Readiness Review

    We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator.

    OutputHIPAA Readiness Report

    Activities

    • Verify remediation of risk analysis findings
    • Test safeguards against the Security Rule
    • Compile the compliance evidence pack
    • Brief leadership on residual risk and next steps

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the HIPAA scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Compliancy Group, AWS Config, Microsoft Purview, Jira, Confluence, Tenable Nessus. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: HIPAA Security Rule, HIPAA Privacy Rule, HIPAA Breach Notification Rule, HITECH Act, NIST SP 800-66.

What We Run

8 tools

  • Vanta
  • Drata
  • Compliancy Group
  • AWS Config
  • Microsoft Purview
  • Jira
  • Confluence
  • Tenable Nessus

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • HIPAA Security Rule
  • HIPAA Privacy Rule
  • HIPAA Breach Notification Rule
  • HITECH Act
  • NIST SP 800-66
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Security risk analysis report
  • HIPAA policy and procedure set
  • Safeguard remediation plan
  • Business associate agreement templates
  • Breach notification procedure

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What is the difference between a covered entity and a business associate?

A covered entity is a provider, health plan, or clearinghouse. A business associate is a vendor that handles health data on their behalf. Both have HIPAA duties, and we cover both.

Is a HIPAA risk analysis mandatory?

Yes. The Security Rule requires a documented risk analysis, and it is one of the first things a regulator asks for. We run it properly and keep it current.

Does HIPAA require encryption?

Encryption is addressable, not strictly mandatory, but you must justify any decision not to use it. In practice we recommend it for data at rest and in transit.

Keep Moving Through Compliance

Service 7 of 13 in this practice area