HIPAA
HIPAA is US law, not a certification — there is no certificate to earn and no body that issues one. What regulators, customers and covered entities look for is a documented program: a security risk analysis, implemented safeguards, adopted policies and executed business associate agreements. Complyanz runs that program.
The safeguards, the records and the risk analysis
How a HIPAA program runs
Scope and PHI inventory
Identify every system that creates, receives, maintains or transmits protected health information.
Security risk analysis
Conduct the risk analysis required by the Security Rule — the single most commonly cited failure in enforcement actions.
Safeguards
Implement and record the Administrative, Physical and Technical safeguards against the systems in scope.
Policies, BAAs and breach readiness
Adopt the required policies, execute business associate agreements, train the workforce and keep breach notification ready to run.
HIPAA alongside your other programs
HIPAA is standalone in Complyanz — it does not require ISO 27001 and is not part of the integrated management system. It does share the same underlying platform: the same asset inventory, the same incident handling, the same training records. Healthcare organizations commonly run HIPAA and SOC 2 together for exactly that reason.
HIPAA FAQ
Can we become HIPAA certified?
No such thing exists. HIPAA is a regulation, and there is no accredited certification for it. What you can have is a documented, defensible compliance program — which is what Complyanz builds and what auditors and customers actually assess.
What is the security risk analysis?
A risk analysis required by the Security Rule. It is the requirement most frequently cited in enforcement actions, usually because it was never done or never updated. Complyanz runs it as a first-class step with the risk register behind it.
Do you handle business associate agreements?
Business associates are tracked alongside your other suppliers, with the agreements and the data they touch recorded against each one.
What happens when there is a breach?
Incidents are logged and classified, breach records are kept, and the notification requirements are tracked so the clock is not being managed from an inbox.
Build your HIPAA program
Create an organization and the safeguards, PHI inventory and risk analysis are ready to work with.