Regulation

HIPAA

HIPAA is US law, not a certification — there is no certificate to earn and no body that issues one. What regulators, customers and covered entities look for is a documented program: a security risk analysis, implemented safeguards, adopted policies and executed business associate agreements. Complyanz runs that program.

What you get

The safeguards, the records and the risk analysis

68safeguards across the Administrative, Physical and Technical categories
3rules covered: Security, Privacy and Breach Notification
1PHI inventory across the systems that create, receive, maintain or transmit it
0ISO 27001 required — HIPAA runs standalone in Complyanz
In the platform

How a HIPAA program runs

Step 1

Scope and PHI inventory

Identify every system that creates, receives, maintains or transmits protected health information.

Step 2

Security risk analysis

Conduct the risk analysis required by the Security Rule — the single most commonly cited failure in enforcement actions.

Step 3

Safeguards

Implement and record the Administrative, Physical and Technical safeguards against the systems in scope.

Step 4

Policies, BAAs and breach readiness

Adopt the required policies, execute business associate agreements, train the workforce and keep breach notification ready to run.

Going further

HIPAA alongside your other programs

HIPAA is standalone in Complyanz — it does not require ISO 27001 and is not part of the integrated management system. It does share the same underlying platform: the same asset inventory, the same incident handling, the same training records. Healthcare organizations commonly run HIPAA and SOC 2 together for exactly that reason.

Questions

HIPAA FAQ

Can we become HIPAA certified?

No such thing exists. HIPAA is a regulation, and there is no accredited certification for it. What you can have is a documented, defensible compliance program — which is what Complyanz builds and what auditors and customers actually assess.

What is the security risk analysis?

A risk analysis required by the Security Rule. It is the requirement most frequently cited in enforcement actions, usually because it was never done or never updated. Complyanz runs it as a first-class step with the risk register behind it.

Do you handle business associate agreements?

Business associates are tracked alongside your other suppliers, with the agreements and the data they touch recorded against each one.

What happens when there is a breach?

Incidents are logged and classified, breach records are kept, and the notification requirements are tracked so the clock is not being managed from an inbox.

Build your HIPAA program

Create an organization and the safeguards, PHI inventory and risk analysis are ready to work with.