What this Preview includes
- Preview requirement catalog
- Preliminary shared-control mappings
- Likely evidence examples
- Open questions for product feedback
HIPAA
PreviewReview preliminary Security Rule mappings, shared controls, likely evidence, and open questions. Active HIPAA readiness programs are not yet available.
Shared work
Preview mappings show possible relationships to controls already supporting SOC 2 or ISO 27001. A mapping is a planning aid, not proof that a requirement is satisfied.
Review the context, assets, threats, vulnerabilities, and documentation an eventual risk analysis may need. Qualified review must determine the applicable requirement and adequacy.
Explore preliminary relationships for sanction, contingency, access-management, and incident-response policies without treating a mapping as satisfaction.
Review examples such as encryption settings, access reviews, training records, and backup tests. The Preview does not accept or credit evidence.
Identify which vendors may handle protected health information and which agreement or review questions require qualified follow-up.
HIPAA is the US federal law protecting health information. It applies to covered entities such as providers and health plans and can also apply to vendors that handle protected health information under business associate arrangements. Qualified legal guidance should determine whether a specific organization and data flow are in scope.
The Security Rule is the part a software company operationalizes. It defines administrative, physical, and technical safeguards, plus organizational and documentation requirements, and it is assessed at the level of 46 implementation specifications. Each one is either Required or Addressable. Addressable does not mean optional. It means implement it, or document why an alternative measure is reasonable in your environment.
There is no official HIPAA certification. Organizations generally demonstrate their program through risk analysis, written policies, workforce training, business associate agreements, and operating evidence. Exact obligations and review expectations depend on the organization and require qualified interpretation.
The Preview represents 46 implementation specifications for planning and mapping review alongside possible SOC 2 and ISO 27001 relationships.
Risk analysis, workforce security, training, incidents, contingency
Facilities, workstations, devices, and media
Access control, audit, integrity, authentication, encryption
Business associate agreement content
Written policies, retention, and updates
Quick answers about the product, frameworks, and getting started.
No. HIPAA does not have an official accredited certification comparable to ISO 27001. Organizations document their applicable program through risk analysis, policies, training, agreements, and operating records, subject to qualified legal and compliance review.
The Security Rule identifies encryption-related implementation specifications as Addressable. That requires a documented, fact-specific decision rather than treating encryption as optional. Qualified guidance should assess the organization's systems, risks, alternatives, and breach obligations.
A BAA is the contract that makes a vendor legally responsible for protecting PHI it handles for a covered entity or another business associate. If customers send you PHI, they will require one from you, and you need one from every subprocessor that touches that data. Our vendor module tracks that chain.
Some Security Rule work may overlap with controls already used for SOC 2. The Preview can help identify likely relationships and open questions, but it does not determine that a safeguard is satisfied or replace qualified HIPAA review.
Did not find what you were looking for? Talk to us.
Preview access
Tell us what your team needs. Active readiness remains limited to SOC 2 and ISO 27001 today.