HIPAA
The regulatory floor for anyone handling protected health information, and the entry point to healthcare deals.
What it is
HIPAA is regulation, not certification. The Security Rule requires administrative, physical, and technical safeguards; the Privacy Rule governs use and disclosure; the Breach Notification Rule sets disclosure obligations. Compliance is demonstrated through a documented risk analysis, implemented safeguards, workforce training, and executed business associate agreements — there is no certificate, so buyers assess your program directly or ask for HITRUST instead.
Who typically needs it
- Digital health and healthcare AI vendors signing business associate agreements
- Companies whose customers are covered entities and who are therefore business associates
- Sub-processors handling PHI on behalf of another business associate
- Organizations that signed BAAs before building the underlying program
- Vendors being asked for HITRUST who need the HIPAA foundation first
What the engagement looks like
Baseline. We perform the Security Rule risk analysis the regulation requires and score every implementation specification, required and addressable. Most organizations have safeguards but no risk analysis, which is the first thing an investigation asks for.
Build. We author the policy suite, the workforce training program, the sanctions policy, and the incident and breach determination procedures. We review the BAA population and flag agreements whose terms exceed what your program can actually deliver.
Build, continued. Technical safeguards get the attention — encryption, audit controls, access management — but administrative safeguards carry most of the enforcement risk. We build the documentation trail for both.
Audit Sprint. There is no HIPAA audit to prepare for in the ordinary case, so this tier is used for customer security reviews, payer diligence, or preparation for a HITRUST assessment. We mock the diligence and close what it surfaces.
Steady State. The risk analysis is required to be current, not annual by accident. We refresh it, keep training and BAA records in order, and maintain the evidence a payer or enterprise customer will ask for on short notice.
Common failure modes
- A security questionnaire answered as though it were the risk analysis
- Addressable specifications treated as optional, with no record of the alternative applied
- BAAs signed with terms the program cannot meet, particularly on breach notification timelines
- Training completed but not evidenced, which fails almost every payer diligence review
Price range
Programs typically run between $20,000 and $50,000 for the Build phase, depending on PHI footprint and BAA population.
Talk to us about your HIPAA.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.
Book a consultation