.ai

HIPAA

Preview

Explore how HIPAA safeguards could fit into your existing security program.

Review preliminary Security Rule mappings, shared controls, likely evidence, and open questions. Active HIPAA readiness programs are not yet available.

What this Preview includes

  • Preview requirement catalog
  • Preliminary shared-control mappings
  • Likely evidence examples
  • Open questions for product feedback

What this Preview does not provide

  • No active readiness score
  • No complete regulatory-coverage claim
  • No legal, audit, or certification conclusion
  • No production framework activation

Shared work

Explore where existing work may be reusable.

Preview mappings show possible relationships to controls already supporting SOC 2 or ISO 27001. A mapping is a planning aid, not proof that a requirement is satisfied.

Risk analysis, the real one

Review the context, assets, threats, vulnerabilities, and documentation an eventual risk analysis may need. Qualified review must determine the applicable requirement and adequacy.

Policies mapped to safeguards

Explore preliminary relationships for sanction, contingency, access-management, and incident-response policies without treating a mapping as satisfaction.

Evidence examples per safeguard

Review examples such as encryption settings, access reviews, training records, and backup tests. The Preview does not accept or credit evidence.

Vendor and BAA questions

Identify which vendors may handle protected health information and which agreement or review questions require qualified follow-up.

What is HIPAA?

HIPAA is the US federal law protecting health information. It applies to covered entities such as providers and health plans and can also apply to vendors that handle protected health information under business associate arrangements. Qualified legal guidance should determine whether a specific organization and data flow are in scope.

The Security Rule is the part a software company operationalizes. It defines administrative, physical, and technical safeguards, plus organizational and documentation requirements, and it is assessed at the level of 46 implementation specifications. Each one is either Required or Addressable. Addressable does not mean optional. It means implement it, or document why an alternative measure is reasonable in your environment.

There is no official HIPAA certification. Organizations generally demonstrate their program through risk analysis, written policies, workforce training, business associate agreements, and operating evidence. Exact obligations and review expectations depend on the organization and require qualified interpretation.

46 Security Rule implementation specifications represented in Preview mappings

The Preview represents 46 implementation specifications for planning and mapping review alongside possible SOC 2 and ISO 27001 relationships.

164.308

Administrative safeguards

Risk analysis, workforce security, training, incidents, contingency

164.310

Physical safeguards

Facilities, workstations, devices, and media

164.312

Technical safeguards

Access control, audit, integrity, authentication, encryption

164.314

Organizational requirements

Business associate agreement content

164.316

Policies and documentation

Written policies, retention, and updates

Questions the production workspace must answer

  • Which obligations apply to this organization?
  • Which mappings need qualified review?
  • What program records are still missing?
  • What evidence is current and approved?

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

HIPAA basics

Is there a HIPAA certification?

No. HIPAA does not have an official accredited certification comparable to ISO 27001. Organizations document their applicable program through risk analysis, policies, training, agreements, and operating records, subject to qualified legal and compliance review.

Does HIPAA require encryption?

The Security Rule identifies encryption-related implementation specifications as Addressable. That requires a documented, fact-specific decision rather than treating encryption as optional. Qualified guidance should assess the organization's systems, risks, alternatives, and breach obligations.

What is a business associate agreement?

A BAA is the contract that makes a vendor legally responsible for protecting PHI it handles for a covered entity or another business associate. If customers send you PHI, they will require one from you, and you need one from every subprocessor that touches that data. Our vendor module tracks that chain.

We already have SOC 2. How much extra work is HIPAA?

Some Security Rule work may overlap with controls already used for SOC 2. The Preview can help identify likely relationships and open questions, but it does not determine that a safeguard is satisfied or replace qualified HIPAA review.

Did not find what you were looking for? Talk to us.

Preview access

Help shape the HIPAA workspace.

Tell us what your team needs. Active readiness remains limited to SOC 2 and ISO 27001 today.

Do not include credentials, security findings, regulated data, or other sensitive information.