Safeguard Health Data
HIPAA Compliance and Health Information Security
HIPAA governs how you protect health information in the United States. We help you meet the Security and Privacy Rules and prove you handle patient data responsibly.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
HIPAA sets the rules for protecting health information handled by providers, insurers, and their vendors. Its Security Rule covers safeguards for electronic health data, the Privacy Rule covers how it may be used and shared, and the Breach Notification Rule covers what happens when things go wrong. It matters because health data is sensitive, heavily regulated, and a frequent target. We help covered entities and business associates meet their obligations with controls that fit clinical and operational reality.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the HIPAA engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Role Confirmation. We confirm whether you are a covered entity or a business associate and map where health information lives. Activities: Determine covered entity or business associate status; Inventory systems holding protected health information; Map PHI flows across applications and vendors; Confirm which HIPAA rules apply to each flow. Hands over PHI Inventory and Applicability Memo. Phase 2, Security Risk Analysis. We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards. Activities: Assess threats and vulnerabilities to each PHI system; Evaluate administrative, physical, and technical safeguards; Score risks by likelihood and impact; Document the analysis per NIST SP 800-66 guidance. Hands over Security Risk Analysis Report. Phase 3, Safeguard Design. We design the policies and controls to close gaps, from access controls to encryption and workforce training. Activities: Draft HIPAA policies and procedures; Design access control and audit logging safeguards; Specify encryption for PHI at rest and in transit; Build the workforce training programme. Hands over HIPAA Policy Set and Remediation Plan. Phase 4, Privacy and Breach Processes. We set up processes for permitted uses, patient rights, and breach notification within the required timelines. Activities: Define permitted use and disclosure rules; Build the patient rights request workflow; Write the breach assessment and notification procedure; Test the breach process with a tabletop exercise. Hands over Privacy Procedures and Breach Notification Playbook. Phase 5, Business Associate Management. We help you put business associate agreements in place and manage vendor risk. Activities: Identify vendors that touch PHI; Execute business associate agreements with each; Assess vendor safeguards and certifications; Set a reassessment cadence for critical vendors. Hands over Executed Business Associate Agreements and Vendor Register. Phase 6, Readiness Review. We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator. Activities: Verify remediation of risk analysis findings; Test safeguards against the Security Rule; Compile the compliance evidence pack; Brief leadership on residual risk and next steps. Hands over HIPAA Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Role Confirmation
We confirm whether you are a covered entity or a business associate and map where health information lives.
What Happens In This Phase
- Determine covered entity or business associate status
- Inventory systems holding protected health information
- Map PHI flows across applications and vendors
- Confirm which HIPAA rules apply to each flow
The Handover
PHI Inventory and Applicability Memo
The next phase starts from this.
Phase 01 Scoping and Role Confirmation
We confirm whether you are a covered entity or a business associate and map where health information lives.
What Happens In This Phase
- Determine covered entity or business associate status
- Inventory systems holding protected health information
- Map PHI flows across applications and vendors
- Confirm which HIPAA rules apply to each flow
The Handover
PHI Inventory and Applicability Memo
The next phase starts from this.
- 01
Scoping and Role Confirmation
We confirm whether you are a covered entity or a business associate and map where health information lives.
OutputPHI Inventory and Applicability MemoActivities
- Determine covered entity or business associate status
- Inventory systems holding protected health information
- Map PHI flows across applications and vendors
- Confirm which HIPAA rules apply to each flow
- 02
Security Risk Analysis
We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards.
OutputSecurity Risk Analysis ReportActivities
- Assess threats and vulnerabilities to each PHI system
- Evaluate administrative, physical, and technical safeguards
- Score risks by likelihood and impact
- Document the analysis per NIST SP 800-66 guidance
- 03
Safeguard Design
We design the policies and controls to close gaps, from access controls to encryption and workforce training.
OutputHIPAA Policy Set and Remediation PlanActivities
- Draft HIPAA policies and procedures
- Design access control and audit logging safeguards
- Specify encryption for PHI at rest and in transit
- Build the workforce training programme
- 04
Privacy and Breach Processes
We set up processes for permitted uses, patient rights, and breach notification within the required timelines.
OutputPrivacy Procedures and Breach Notification PlaybookActivities
- Define permitted use and disclosure rules
- Build the patient rights request workflow
- Write the breach assessment and notification procedure
- Test the breach process with a tabletop exercise
- 05
Business Associate Management
We help you put business associate agreements in place and manage vendor risk.
OutputExecuted Business Associate Agreements and Vendor RegisterActivities
- Identify vendors that touch PHI
- Execute business associate agreements with each
- Assess vendor safeguards and certifications
- Set a reassessment cadence for critical vendors
- 06
Readiness Review
We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator.
OutputHIPAA Readiness ReportActivities
- Verify remediation of risk analysis findings
- Test safeguards against the Security Rule
- Compile the compliance evidence pack
- Brief leadership on residual risk and next steps
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
Built by SecureRoot
DPDPA Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the HIPAA scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Compliancy Group, AWS Config, Microsoft Purview, Jira, Confluence, Tenable Nessus. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: HIPAA Security Rule, HIPAA Privacy Rule, HIPAA Breach Notification Rule, HITECH Act, NIST SP 800-66.
What We Run
8 tools
- Drata
- Compliancy Group
- AWS Config
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
Deliverables
What You Receive
- Security risk analysis report
- HIPAA policy and procedure set
- Safeguard remediation plan
- Business associate agreement templates
- Breach notification procedure
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What is the difference between a covered entity and a business associate?
A covered entity is a provider, health plan, or clearinghouse. A business associate is a vendor that handles health data on their behalf. Both have HIPAA duties, and we cover both.
Is a HIPAA risk analysis mandatory?
Yes. The Security Rule requires a documented risk analysis, and it is one of the first things a regulator asks for. We run it properly and keep it current.
Does HIPAA require encryption?
Encryption is addressable, not strictly mandatory, but you must justify any decision not to use it. In practice we recommend it for data at rest and in transit.
Keep Moving Through Compliance
Service 7 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.