HIPAA Compliance for Health Data
Protected health information carries some of the strictest handling rules in the world. We help healthcare organisations and their vendors meet them.
What is HIPAA?
The US Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting patient health information (PHI). Its Security Rule requires administrative, physical and technical safeguards for electronic PHI (ePHI).
Its Breach Notification Rule sets out what must happen if that data is exposed - including who must be told, and how quickly. Business associates that handle PHI on behalf of a covered entity carry many of the same obligations.
What's included
Security Rule Gap Assessment
HIPAA Security Rule gap assessment.
Safeguard Implementation
Administrative, physical and technical safeguard implementation.
BAA Review
Business Associate Agreement (BAA) review.
Risk Analysis & Management
Risk analysis and risk management plan.
Breach Notification Design
Breach notification procedure design.
PHI Staff Training
Staff training on PHI handling.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
Questions we get asked first
Who needs to be HIPAA compliant?
Covered entities (healthcare providers, health plans, clearinghouses) and their business associates - any vendor that creates, receives, maintains or transmits PHI on their behalf.
Is HIPAA a certification?
No - there's no official HIPAA certificate. Compliance is demonstrated through documented risk analysis, safeguards and audit-ready evidence, which is what our assessment and implementation work delivers.
How does HIPAA relate to SOC 2?
They're not the same, but a SOC 2 report scoped to include HIPAA's requirements is common for healthcare SaaS vendors who need to satisfy both auditors and healthcare customers.
Ready to get audit-ready for HIPAA?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
