Eye On Bits
Compliance · HIPAA

HIPAA Compliance for Health Data

Protected health information carries some of the strictest handling rules in the world. We help healthcare organisations and their vendors meet them.

What is HIPAA?

The US Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting patient health information (PHI). Its Security Rule requires administrative, physical and technical safeguards for electronic PHI (ePHI).

Its Breach Notification Rule sets out what must happen if that data is exposed - including who must be told, and how quickly. Business associates that handle PHI on behalf of a covered entity carry many of the same obligations.

What's included

Security Rule Gap Assessment

HIPAA Security Rule gap assessment.

Safeguard Implementation

Administrative, physical and technical safeguard implementation.

BAA Review

Business Associate Agreement (BAA) review.

Risk Analysis & Management

Risk analysis and risk management plan.

Breach Notification Design

Breach notification procedure design.

PHI Staff Training

Staff training on PHI handling.

Our approach - Plan, Do, Check, Act

The same continuous-improvement cycle behind every compliance programme we run.

Plan

Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.

Do

Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.

Check

Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.

Act

Run the audit, then keep improving through continual, corrective and preventive action.

Other compliance frameworks

GDPR

EU regulation governing the processing of personal data.

Learn more →

SOC 2

Independent attestation of security, availability and confidentiality controls.

Learn more →

PCI DSS

Security standard for organisations handling cardholder data.

Learn more →

ISO 27001

International standard for an Information Security Management System (ISMS).

Learn more →

Questions we get asked first

Who needs to be HIPAA compliant?

Covered entities (healthcare providers, health plans, clearinghouses) and their business associates - any vendor that creates, receives, maintains or transmits PHI on their behalf.

Is HIPAA a certification?

No - there's no official HIPAA certificate. Compliance is demonstrated through documented risk analysis, safeguards and audit-ready evidence, which is what our assessment and implementation work delivers.

How does HIPAA relate to SOC 2?

They're not the same, but a SOC 2 report scoped to include HIPAA's requirements is common for healthcare SaaS vendors who need to satisfy both auditors and healthcare customers.

Ready to get audit-ready for HIPAA?

Tell us where you're starting from and we'll come back with a scoped proposal within two working days.