Skip to content
Compliance Framework

HIPAA

HIPAA governs protected health information under United States law. It applies by operation of law rather than by customer request, there is no such thing as HIPAA certification, and what you are left with is a posture you have to be able to evidence.

Compliance Guide
7 min read

What HIPAA is

HIPAA is United States law governing protected health information. It is enforced by the Department of Health and Human Services Office for Civil Rights, and unlike SOC 2 or ISO 27001 it is not something a buyer asks you for. It applies whether or not anyone requests it.

There is no such thing as HIPAA certification. No government body issues one, and any vendor claiming to have been certified by an authority is describing something that does not exist. What exists is a compliance posture you have to be able to evidence, and third-party assessments that give you a defensible read on it.

Who it applies to

HIPAA divides the world into covered entities and business associates, and the second category is where most technology companies land.

  • Covered entities: health plans, healthcare clearinghouses, and providers who transmit health information electronically
  • Business associates: anyone creating, receiving, maintaining, or transmitting protected health information on a covered entity’s behalf
  • Subcontractors of business associates, who inherit substantially the same obligations
  • In practice this reaches hosting providers, analytics vendors, billing platforms, and most health-adjacent SaaS

The rules that matter

Several rules sit under HIPAA and the HITECH Act. Three drive most of the operational work.

  • The Privacy Rule governs permitted uses and disclosures of protected health information, and individuals’ rights over it
  • The Security Rule governs electronic protected health information through administrative, physical, and technical safeguards
  • The Breach Notification Rule sets what has to be assessed, reported, and disclosed when protected health information is compromised, and on what timeline
  • Business Associate Agreements are the contractual mechanism that carries these obligations down the chain

Required and addressable safeguards

The Security Rule marks some implementation specifications as required and others as addressable. Addressable is routinely misread as optional. It is not.

Where a specification is addressable, you must implement it if it is reasonable and appropriate for your environment. If it is not, you have to document why, and implement an equivalent alternative measure where one is reasonable. The written justification is the deliverable, and its absence is a finding.

What the record has to show

HIPAA obligations are evidenced in documentation, and the retention requirement means that documentation has to survive for years.

  • A current, genuine security risk analysis, and a risk management plan acting on what it found
  • Policies and procedures covering each applicable safeguard, with the addressable determinations written down
  • Workforce training records, sanction policy, and access authorization and termination records
  • Executed Business Associate Agreements across every relationship that handles protected health information
  • Incident and breach assessment records, including incidents assessed and determined not to be reportable
  • Documentation retained for six years from creation or last effective date, whichever is later

How Verdict helps

Verdict runs the security risk analysis, builds the policy and safeguard record against your actual environment, and documents the addressable determinations so they hold up rather than sitting unexplained.

We maintain the Business Associate Agreement inventory, carry the remediation record, and keep the whole thing current as your systems and workforce change. Your team reviews it in a client portal instead of reassembling it when a regulator or a customer’s counsel asks.

HIPAA is part of commercial assurance, the work that covers what a customer, partner, or procurement team asks you to produce before they will do business with you. The same lane also covers SOC 2 Type I and Type II, and ISO/IEC 27001. For the mechanics of an engagement, see how we work.

If you handle protected health information as a covered entity or a business associate, we can run the risk analysis and hold the documentation record behind it.

Talk to a Consultant