HIPAA for teams handling health data

HIPAA safeguards work best when they're built into your infrastructure, not bolted on as a policy document nobody reads. We map the Security and Privacy Rules to the cloud-native systems you're actually running.

Book a HIPAA Snapshot Assessment

Who this applies to

Covered entities (health plans, providers, clearinghouses) and their business associates: any vendor that creates, receives, maintains, or transmits protected health information (PHI) on a covered entity's behalf. If you're building health tech, a business associate agreement (BAA) with your customers usually means HIPAA applies to you directly, not just to them.

What HIPAA actually requires

Security Rule

Administrative, physical, and technical safeguards for electronic PHI: access controls, audit logging, encryption, and a documented risk analysis that's actually specific to your systems.

Privacy Rule

Rules on how PHI can be used and disclosed, including patient rights to access and amend their own records.

Breach Notification Rule

Timelines and processes for notifying affected individuals, HHS, and in some cases the media, once a breach involving unsecured PHI is discovered.

Risk analysis

Not optional and not a template you fill in once. It's the foundation OCR looks for first in an audit or breach investigation.

How we help

Snapshot Assessment

A risk analysis against the Security Rule safeguards, with findings prioritized by actual exposure. $9,500, 2 to 3 weeks.

Safeguard implementation

Encryption, access management, and audit logging built into your AWS, Azure, or GCP environment, plus the policies that describe what the systems already do.

BAA & vendor review

Business associate agreements and a vendor risk process for the subprocessors that touch PHI on your behalf.

Frequently asked questions

Is there a HIPAA "certification" we can get?

No official government certification exists. What customers usually mean is a documented risk analysis, a signed BAA, and evidence of your safeguards, sometimes formalized through a HITRUST assessment if a partner specifically requires it.

We use cloud providers that are HIPAA compliant. Are we covered?

Partly. Your cloud provider being able to sign a BAA and offer compliant infrastructure doesn't make your application compliant. You still need to configure and use those services correctly, which is where most real gaps show up.

How does this relate to SOC 2 or ISO 27001?

There's real overlap in access control, encryption, and monitoring, so if you already hold one of those, HIPAA work goes faster. But HIPAA has its own specific requirements, like the formal risk analysis and BAA structure, that neither SOC 2 nor ISO 27001 fully covers on their own.

Get a real risk analysis, not a template

A short conversation covers your data flows, current safeguards, and what OCR would actually want to see.

Schedule a consultation