HIPAA compliance

Get HIPAA compliant without building a security team first.

There is no official HIPAA certificate, so buyers judge your program on its evidence. A dedicated SecureSlate compliance lead runs your risk analysis, implements the Security Rule safeguards, and manages business associate agreements, while our compliance automation platform keeps the evidence current. One fixed price covers the work.

HIPAA Security Rule, 45 CFR 16448 requirements

HIPAA Security Rule, 45 CFR 164: 48 requirements, 23 Administrative safeguards, 10 Physical safeguards, 9 Technical safeguards, 2 Organizational requirements, 4 Policies and documentation. 7 highlighted: Evidenced by included security scanning.

Evidenced by included security scanningScoped with your compliance lead
Enforced by
HHS Office for Civil Rights
Certificate
None issued by HHS
Breach notification
Within 60 days of discovery
The standard

HIPAA compliance is judged on evidence, because there is no certificate to show.

HIPAA is a federal law enforced by HHS. For vendors that handle protected health information, the Security Rule sets the safeguards and the Breach Notification Rule sets what happens when they fail.

Administrative, physical, and technical safeguards

The Security Rule groups its requirements into administrative, physical, and technical safeguards, plus organizational and documentation requirements. Specifications are required or addressable, and addressable does not mean optional: you implement them or document why an equivalent measure is reasonable.

Risk analysis comes first

An accurate and thorough analysis of where electronic PHI lives and what threatens it is the foundation of the rule, and missing or outdated risk analyses are a recurring theme in HHS enforcement actions.

No certificate, so evidence does the talking

HHS does not certify organizations. Buyers ask for your risk analysis, policies, training records, signed business associate agreements, and often a SOC 2 or HITRUST report that maps to the safeguards.
How it works

We build your HIPAA program so a buyer's security review has answers.

Four stages from the scoping call to a program you can evidence, with a named compliance lead accountable at every one.

Map where PHI lives

We trace how protected health information enters, moves through, and leaves your product, including cloud accounts, databases, logs, backups, analytics, and vendors. That map sets the scope for every safeguard that follows.

Run the risk analysis

Your compliance lead identifies threats and vulnerabilities to electronic PHI, rates their likelihood and impact, and records a risk management plan with owners. Scanning results feed the technical side, so the analysis reflects what actually runs.

Implement the safeguards and agreements

Policies written for how your team operates, access and audit controls configured, training and device checks scheduled, and business associate agreements put in place with customers and with the vendors that touch PHI.

Evidence it, then keep it current

Evidence collects continuously, and we revisit the risk analysis and safeguards when your systems change and on a regular schedule. When a buyer needs an independent report, we extend the same program into SOC 2 or HITRUST.
What is included

Everything a HIPAA security review asks for, prepared before they ask.

HIPAA compliance software and the expert who runs it arrive together under one fixed price, so the program does not land on your engineers.

A dedicated compliance lead

One experienced practitioner owns your HIPAA program end to end. They map PHI, run the risk analysis, draft policies, join the security review calls that turn technical, and keep the documentation current, so your team approves instead of interpreting the regulation.

Risk analysis and risk management

Threats and vulnerabilities to electronic PHI assessed and scored, with a risk management plan, owners, and review dates recorded, so the document an investigator or buyer asks for first is ready.

Business associate agreements

Signed agreements with the covered entities you serve and with every subcontractor that touches PHI, tracked with renewal dates so a new vendor never slips in without one.

Evidence from the stack you already run

Connect your cloud provider, identity provider, code host, and devices once. Access, audit logging, and encryption settings are tested continuously, and when one fails, SecureSlate AI finds the gap and prepares a fix for your team to approve.

Workforce training and device checks

Security awareness training, policy acknowledgements, and device checks for encryption, screen lock, and antivirus run on a schedule and are tracked for you, covering the workforce safeguards with evidence.

A Trust Center for healthcare buyers

Publish your HIPAA program summary, policies, and subprocessor list on a live page, and answer security questionnaires from your own evidence, so procurement keeps moving instead of stalling the deal.
Technical safeguards evidence

Several HIPAA requirements need evidence from your code and cloud, not a policy.

Risk analysis, evaluation, authentication, and encryption are judged against what actually runs. Security scanning is part of the engagement, so the evidence comes from your real repositories, domains, and cloud accounts.
§164.308(a)(1)(ii)(A), §164.308(a)(8)

Code security scanning

Repositories scanned for vulnerable code, with findings classified by CWE and ranked by severity. They feed the technical side of your risk analysis and the periodic evaluation the rule requires.
§164.308(a)(5)(ii)(D), §164.312(d)

Secrets detection

API keys, tokens, and credentials committed to source code, found and pinpointed to the file and line, so authentication to systems holding ePHI is not undermined by a leaked secret.
§164.308(a)(1)(ii)(A)

Dependency and license risk

An SBOM for every repository, with vulnerable open source components flagged, so third-party code risk shows up in your risk analysis instead of after an incident.
§164.308(a)(8)

Public surface monitoring

Your domains and forgotten subdomains scanned on a schedule and when you ship, with each finding explained and a fix recommended, which evidences ongoing technical evaluation.
§164.308(a)(5)(ii)(D), §164.308(a)(6)(ii)

Dark web monitoring

Company email addresses checked against known breach data, so exposed workforce credentials are rotated and handled through your incident procedures when needed.
§164.312(a)(2)(iv), §164.312(b)

Cloud misconfiguration checks

AWS, Azure, and GCP configurations checked through read-only access for risky settings in encryption, access, logging, and networking where ePHI is stored and processed.
Beyond HIPAA

One program, several frameworks.

HIPAA safeguards overlap with the frameworks healthcare buyers ask for next, so each new report extends the program instead of starting a new one.

SOC 2

The independent report many health systems accept from vendors. Access, logging, risk, and vendor controls serve both, so one program produces both sets of evidence.

HITRUST

Some large health systems and payers require it. It builds on HIPAA and other frameworks, with assessment levels that let the effort match the requirement.

ISO 27001

The certificate international and enterprise buyers expect, with a management system around the same risk and access work HIPAA already requires.

GDPR

If you process health data about people in the EU, GDPR treats it as a special category with its own lawful basis and impact assessment requirements.

ISO 42001

AI features that touch PHI raise questions about training data and model providers. ISO 42001 answers them and reuses your HIPAA risk and vendor work.

HITECH

The HITECH Act extended HIPAA obligations directly to business associates and strengthened breach notification and penalties.
Customer results

HIPAA results from SecureSlate customers

Healthcare teams that needed to prove their HIPAA program to partners without a weekly evidence scramble.

50+
Hours a week back for HealthHaven, with HIPAA evidence no longer gathered by hand
70%
Lower platform cost for Elfie, a health app running HIPAA, SOC 2, ISO 27001, and GDPR on SecureSlate

HIPAA isn’t something you do once. SecureSlate connected our tools, owners, and evidence so we can prove our program without the constant scramble, and we get 50+ hours a week back.

Edward
Edward CEO at HealthHaven
Resources

Read up before your scoping call.

Practical guides to HIPAA, from what counts as PHI to what an audit looks for.

FAQs

What teams ask before starting HIPAA compliance.

Find out what your HIPAA program will take

Bring the systems that touch PHI and the buyer asking about them. You will leave the call with a gap summary, a timeline, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?