Get Your HIPAA Quote
Show a US health system you can be trusted with PHI
A US hospital, payer or health system will not sign until you can evidence HIPAA compliance. If your product or service touches protected health information on their behalf, you are a business associate with direct statutory duties - safeguards, breach notification and a signed business associate agreement - enforceable against you, not only against them.
You need HIPAA ifβ¦
- !A US health systemβs procurement team has sent a security questionnaire and a business associate agreement to sign.
- !Your device or application now transmits patient data into a US hospital network.
- !Evidence of your Security Rule risk analysis has been requested, and there is nothing in the file to send.
- !You are hosting US patient records and subcontractors handle part of the processing.
- !Nobody can say when the notification clock started on the lost laptop, only that it held patient information.
- !An acquisition brought US healthcare customers and the obligations that come attached to them.
United States federal law governing protected health information. The Privacy Rule limits how it may be used and disclosed, the Security Rule requires administrative, physical and technical safeguards for electronic records, and the Breach Notification Rule sets who must be told and how quickly.
There is no government HIPAA certificate. Compliance is demonstrated through independent assessment against the Rules; SIS reviews your safeguards and issues an assessment report and attestation of compliance.
Compliance is continuous, not dated. Assessment reports are normally refreshed annually, and the Security Rule risk analysis must be updated whenever systems or services change.
US providers, health plans and clearing houses, and the far larger group of business associates: software firms, device makers, hosting providers, billing and transcription services.
Where this certification is demanded
HIPAA is applicable across 2 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What HIPAA Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
A record of what protected health information you hold, where it lives, who can reach it and which subcontractors receive it. Everything else depends on this.
A documented, organisation-wide analysis of risks to electronic protected health information with a risk management plan. This is the single most commonly cited failure in enforcement actions.
Assigned security responsibility, workforce clearance and termination procedures, a sanction policy, and training records showing who was trained and when.
Unique user identification, access aligned to the minimum necessary standard, audit logging of PHI access, integrity controls, and encryption addressed with a documented decision.
Executed agreements with every customer and every subcontractor that touches PHI, with flow-down terms in place before data moves rather than afterwards.
A written procedure covering risk assessment of an incident, notification to individuals and the Secretary within the statutory windows, and media notice above the threshold.
How HIPAA Compliance Assessment Works
No black box. A defined, time-bound route from first call to assessment report.
Applicability & Scoping
We establish whether you are a covered entity or a business associate, which services and systems touch protected health information, and which subcontractors sit in the chain.
2β4 daysRisk Analysis & Gap Review
Most business associates have written policies and no risk analysis, or one done at launch and never touched since. That single document decides how the rest of the review goes.
2β4 weeksRemediation & Documentation
Policies, agreements, training and technical controls are put right. Business associate agreements and the risk management plan usually set the pace, because they need other parties.
1β3 months by gapAssessment Report & Attestation
The report is written rule by rule because that is how a US customerβs counsel reads it, going straight to the risk analysis and the breach procedure before anything else.
Report 1β2 weeks; refresh annuallyIndustries That Need HIPAA
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Nobody can certify you against a federal statute
We will not sell you a HIPAA certificate, because no such thing exists and your customer’s counsel knows it. An independent assessment against the Rules is what they will accept.
Get My Free Quote βWhat HIPAA Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
US contracts move forward
Health systems and payers will not execute an agreement without evidence of safeguards. An assessment report ends the questionnaire loop with procurement.
Evidence when enforcement calls
Enforcement tiers turn on whether a failure was wilful neglect and whether it was corrected. A documented risk analysis is what separates the two.
Breach clocks understood
Notification windows run from discovery, not from the day legal finishes arguing. A written and rehearsed procedure keeps you inside the statutory limits.
Subcontractor chain covered
Business associate duties flow down. Getting agreements and evidence from hosting, support and analytics vendors closes the gap customers probe first.
A base for HITRUST
Most of the safeguards, policies and evidence assembled here map directly into a HITRUST CSF assessment if a customer later specifies one.
One pack, many customers
A rule-by-rule report answers most of what US healthcare procurement asks, so each new customer does not restart the whole exercise.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
Readiness checklist for business associates
The documents US healthcare procurement asks for, from the risk analysis through to training records and subcontractor agreements.
Security Rule risk analysis template
A structured worksheet covering systems, threats, likelihood, impact and the risk management decisions taken, in the form enforcement reviewers expect.
Covered entity or business associate
How to work out which one you are, and what changes in your obligations once the answer is settled.
Breach notification timelines and decisions
The four-factor risk assessment, the sixty-day limit, and the decisions that have to be made in the first week.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to HIPAA.
Can we be HIPAA certified?
We are outside the United States. Does HIPAA apply to us?
What is the difference between HIPAA and HITRUST?
How often do we need to redo the risk analysis?
What counts as a reportable breach?
Do we need agreements with our cloud provider?
Get an independent HIPAA compliance assessment
The risk analysis is the document enforcement reviewers ask for first, and the one most business associates cannot produce. Start there and the questionnaire answers itself.
Get My Free Quote β WhatsApp Us