All frameworks
US federal lawUnited States

HIPAA

Health Insurance Portability and Accountability Act

HIPAA’s Privacy, Security and Breach Notification Rules govern protected health information (PHI) held by covered entities (providers, health plans, clearinghouses) and their business associates. There is no official certification; compliance is demonstrated through risk analysis, safeguards and documentation.

Who it reaches

  • Healthcare providers, health plans and clearinghouses in the United States.
  • Business associates: any vendor that creates, receives, maintains or transmits PHI for a covered entity, including software and cloud providers.
  • Subcontractors of business associates, who carry the same duties.

What the audit checks

  1. 01The HHS Office for Civil Rights investigates complaints and breaches and runs periodic audits.
  2. 02Third-party HIPAA assessments check the Security Rule safeguards (administrative, physical, technical), the risk analysis, policies and business associate agreements.
  3. 03Many organisations pair a HIPAA assessment with a SOC 2 that includes the privacy criterion, or with HITRUST.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
PHI data flow mapping1 to 3
Security Rule risk analysis2 to 6
Safeguards, policies and BAAs6 to 16
Assessment and remediation2 to 6

Evidence to have ready

  • Enterprise-wide risk analysis and risk management plan
  • Policies for each Security Rule standard
  • Business associate agreements with every vendor handling PHI
  • Workforce training records
  • Access controls, audit logs and log review
  • Encryption of PHI at rest and in transit
  • Contingency plan and backup testing
  • Breach risk assessments and notifications
  • Sanctions policy and incident records

Questions people ask

Is there a HIPAA certificate?
No. HHS does not certify compliance. An independent assessment report, a SOC 2 with HIPAA mapping, or HITRUST certification are the ways organisations demonstrate it.
Does HIPAA apply to a non-US company?
If you handle PHI for a US covered entity as a business associate, yes, through the business associate agreement and the rules it incorporates.

Go deeper