Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Safeguard Health Data

HIPAA Compliance and Health Information Security

HIPAA governs how health information is protected in the United States, and it reaches Indian health-tech, revenue cycle and IT companies through business associate agreements. We help you meet the Security, Privacy and Breach Notification Rules your US clients hold you to.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

HIPAA sets the rules for protecting health information handled by US health care providers, health plans and clearinghouses, and by the business associates that work for them. Its Security Rule requires administrative, physical and technical safeguards and a documented risk analysis for electronic protected health information, its Privacy Rule limits how that information is used and disclosed, and its Breach Notification Rule sets deadlines when it is compromised. Indian companies in medical coding, billing, transcription, health-tech SaaS and IT services usually meet HIPAA as business associates or subcontractors, bound by agreements their US clients audit. There is no official HIPAA certification, so what clients want is evidence. We build that evidence and the safeguards behind it, working remotely across India from our Greater Noida and Kanpur offices.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the HIPAA engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Role Confirmation. We confirm whether you are a covered entity or a business associate and map where health information lives. Activities: Determine covered entity or business associate status; Inventory systems holding protected health information; Map PHI flows across applications and vendors; Confirm which HIPAA rules apply to each flow. Hands over PHI Inventory and Applicability Memo. Phase 2, Security Risk Analysis. We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards. Activities: Assess threats and vulnerabilities to each PHI system; Evaluate administrative, physical, and technical safeguards; Score risks by likelihood and impact; Document the analysis per NIST SP 800-66 guidance. Hands over Security Risk Analysis Report. Phase 3, Safeguard Design. We design the policies and controls to close gaps, from access controls to encryption and workforce training. Activities: Draft HIPAA policies and procedures; Design access control and audit logging safeguards; Specify encryption for PHI at rest and in transit; Build the workforce training programme. Hands over HIPAA Policy Set and Remediation Plan. Phase 4, Privacy and Breach Processes. We set up processes for permitted uses, patient rights, and breach notification within the required timelines. Activities: Define permitted use and disclosure rules; Build the patient rights request workflow; Write the breach assessment and notification procedure; Test the breach process with a tabletop exercise. Hands over Privacy Procedures and Breach Notification Playbook. Phase 5, Business Associate Management. We help you put business associate agreements in place and manage vendor risk. Activities: Identify vendors that touch PHI; Execute business associate agreements with each; Assess vendor safeguards and certifications; Set a reassessment cadence for critical vendors. Hands over Executed Business Associate Agreements and Vendor Register. Phase 6, Readiness Review. We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator. Activities: Verify remediation of risk analysis findings; Test safeguards against the Security Rule; Compile the compliance evidence pack; Brief leadership on residual risk and next steps. Hands over HIPAA Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Role Confirmation

We confirm whether you are a covered entity or a business associate and map where health information lives.

What Happens In This Phase

  • Determine covered entity or business associate status
  • Inventory systems holding protected health information
  • Map PHI flows across applications and vendors
  • Confirm which HIPAA rules apply to each flow

The Handover

PHI Inventory and Applicability Memo

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Role Confirmation

    We confirm whether you are a covered entity or a business associate and map where health information lives.

    OutputPHI Inventory and Applicability Memo

    Activities

    • Determine covered entity or business associate status
    • Inventory systems holding protected health information
    • Map PHI flows across applications and vendors
    • Confirm which HIPAA rules apply to each flow
  2. 02

    Security Risk Analysis

    We run the risk analysis the Security Rule requires, covering administrative, physical, and technical safeguards.

    OutputSecurity Risk Analysis Report

    Activities

    • Assess threats and vulnerabilities to each PHI system
    • Evaluate administrative, physical, and technical safeguards
    • Score risks by likelihood and impact
    • Document the analysis per NIST SP 800-66 guidance
  3. 03

    Safeguard Design

    We design the policies and controls to close gaps, from access controls to encryption and workforce training.

    OutputHIPAA Policy Set and Remediation Plan

    Activities

    • Draft HIPAA policies and procedures
    • Design access control and audit logging safeguards
    • Specify encryption for PHI at rest and in transit
    • Build the workforce training programme
  4. 04

    Privacy and Breach Processes

    We set up processes for permitted uses, patient rights, and breach notification within the required timelines.

    OutputPrivacy Procedures and Breach Notification Playbook

    Activities

    • Define permitted use and disclosure rules
    • Build the patient rights request workflow
    • Write the breach assessment and notification procedure
    • Test the breach process with a tabletop exercise
  5. 05

    Business Associate Management

    We help you put business associate agreements in place and manage vendor risk.

    OutputExecuted Business Associate Agreements and Vendor Register

    Activities

    • Identify vendors that touch PHI
    • Execute business associate agreements with each
    • Assess vendor safeguards and certifications
    • Set a reassessment cadence for critical vendors
  6. 06

    Readiness Review

    We run a final review so you can demonstrate compliance to a customer, an auditor, or the regulator.

    OutputHIPAA Readiness Report

    Activities

    • Verify remediation of risk analysis findings
    • Test safeguards against the Security Rule
    • Compile the compliance evidence pack
    • Brief leadership on residual risk and next steps

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Built by SecureRoot

DPDP Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the HIPAA scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Compliancy Group, AWS Config, Microsoft Purview, Jira, Confluence, Tenable Nessus. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: HIPAA Security Rule, HIPAA Privacy Rule, HIPAA Breach Notification Rule, HITECH Act, NIST SP 800-66 Rev. 2.

What We Run

8 tools

  • Vanta
  • Drata
  • Compliancy Group
  • AWS Config
  • Microsoft Purview
  • Jira
  • Confluence
  • Tenable Nessus

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • HIPAA Security Rule
  • HIPAA Privacy Rule
  • HIPAA Breach Notification Rule
  • HITECH Act
  • NIST SP 800-66 Rev. 2
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Security risk analysis report
  • HIPAA policy and procedure set
  • Safeguard remediation plan
  • Business associate agreement templates
  • Breach notification procedure

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Does HIPAA apply to an Indian company?

It applies through your work rather than your location. HIPAA's rules bind US covered entities, meaning health care providers that transact electronically, health plans and clearinghouses, and their business associates, the vendors that create, receive, maintain or transmit protected health information on their behalf. An Indian company doing medical coding, billing, transcription, claims processing, hosting or health-tech SaaS for a US client is typically a business associate or a subcontractor of one, and signs a business associate agreement that passes HIPAA's safeguards and breach duties down to it. US clients then assess you against those duties before and during the contract, and a failure can end the relationship. A company that never touches US patients' health information is outside HIPAA. We confirm your role for each client and service during scoping, because it decides which obligations apply.

What is a business associate agreement, and what does it commit us to?

A business associate agreement is the contract a covered entity must have before sharing protected health information with a vendor, and a business associate must have one with its own subcontractors. It commits you to use and disclose the information only as the agreement and the law permit, to implement Security Rule safeguards for electronic health information, to report security incidents and breaches of unsecured information to your client, to flow the same terms down to subcontractors, to make information available for access and amendment requests where relevant, and to return or destroy the data when the contract ends. Many US clients add stricter terms, such as reporting within a few days or specific encryption requirements. We review each agreement you have signed, map its clauses to controls and processes, and close the gaps so you can prove compliance when the client's security team asks.

Is a HIPAA security risk analysis mandatory?

Yes. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information they hold, and to manage the risks it identifies. It is the document regulators and clients ask for first, and a missing or outdated risk analysis is among the most common failings in HHS enforcement actions. It has to cover every place the information lives and travels, including laptops, cloud accounts, backups, email and vendor systems, and it has to be reviewed when your environment changes, not written once. We run the analysis using HHS and NIST SP 800-66 guidance, produce a risk register with owners and treatment decisions, and set a review cycle so it stays current as your systems and clients change.

Does HIPAA require encryption?

Under the current Security Rule, encryption of electronic protected health information at rest and in transit is an addressable implementation specification rather than a flat requirement. Addressable does not mean optional: you must implement it where reasonable and appropriate, or document why not and what equivalent measure you use instead. In practice encryption is expected, and it matters for breaches, because information encrypted in line with HHS guidance is not unsecured, so its loss is generally not a reportable breach. In January 2025 HHS proposed amendments to the Security Rule that would remove the distinction between required and addressable specifications and make encryption mandatory with limited exceptions, so check whether that rule has been finalised when you plan. Your business associate agreements may already demand it. We recommend encrypting health information everywhere it is stored or sent and documenting key management properly.

What happens if there is a breach of health information?

The Breach Notification Rule applies to unsecured protected health information. A covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach. If 500 or more residents of a state or jurisdiction are affected, it must also notify prominent media there, and breaches affecting 500 or more people must be reported to HHS at the same time; smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year. A business associate must notify its covered entity without unreasonable delay and no later than 60 days after discovery, although most agreements set far shorter deadlines. Every incident needs a documented risk assessment to decide whether it is a breach at all. We build the incident and breach procedure, the assessment template and the notification drafts, then rehearse them.

Is there an official HIPAA certification?

No. The US Department of Health and Human Services does not certify organisations as HIPAA compliant and does not endorse any private HIPAA certification, so a certificate from a vendor or consultant carries no regulatory weight on its own. What US clients and their auditors look for instead is evidence: a current security risk analysis, written policies and procedures, implemented safeguards, workforce training records, signed business associate agreements, incident and breach procedures, and proof that these operate. Many health-tech companies also pursue SOC 2 or ISO 27001, which provide independent assurance that clients recognise, and map HIPAA safeguards onto those controls. We help you assemble a HIPAA evidence pack that answers client questionnaires directly, and where you also need SOC 2 or ISO 27001, we build one control set that serves all three, so audits and client reviews draw on the same evidence.

How long does HIPAA compliance take for a vendor?

For most Indian business associates, two to four months to reach a position you can evidence to US clients, following our phases. Scoping and role confirmation take one to two weeks, the security risk analysis two to three, safeguard design and implementation four to eight, privacy and breach processes two to three, and business associate management one to two, ending with a readiness review. A SaaS company with a single platform and cloud hosting moves faster than a coding or billing operation with many sites, workstations and remote staff handling records. What stretches the timeline is usually safeguard implementation: access controls, logging, device management and encryption across every place health information is handled. A client audit date often sets the pace. We commit to a timeline after the risk analysis, once the size of the remediation work is known.

What does HIPAA support cost?

We do not publish a figure for HIPAA work, because the effort varies too much between companies for a range to help you. A health-tech SaaS platform hosted in one cloud account needs far less work than a revenue cycle or transcription business with multiple delivery centres, hundreds of workstations and many client agreements. The quote depends on how many systems, sites and people handle protected health information, how many business associate agreements you have signed and what they demand, how much of the risk analysis and policy set already exists, and whether you are also pursuing SOC 2 or ISO 27001, which can share controls and lower the total. Tooling, such as encryption, device management or logging platforms, and your own team's time sit outside our fee. We scope first, then give you a fixed price in writing for the work we will do.

Keep Moving Through Compliance

Service 7 of 13 in this practice area