Frameworks
HIPAA readiness, assessed in days
If you handle protected health information for a US covered entity — as a provider, a processor, or a business associate — the Security Rule reaches you through your contract. We assess you against it and hand back a gap report and a remediation plan.
It usually arrives through a contract, not a regulator
Most European organisations meet HIPAA the same way: a US customer sends a business associate agreement and expects it signed. That agreement makes the Security Rule your problem contractually, whether or not a US regulator would ever write to you directly.
Business associates
Software vendors, data processors, hosting and support providers handling protected health information for a covered entity. The obligations flow down the chain, and a subcontractor is a business associate too.
European firms with US healthcare customers
Where your customer is a US provider, payer or clearinghouse, their compliance obligation becomes your contractual one — and their auditor will ask you for evidence rather than assurance.
Anyone signing a BAA
A business associate agreement commits you to safeguards, breach notification timelines and, usually, to permitting an audit. It is worth knowing what you are agreeing to before you sign rather than afterwards.
The Security Rule, in its three parts
The HIPAA Security Rule is organised into three groups of safeguards. Within them, some implementation specifications are required and others are addressable — which does not mean optional, but means you must implement it or document why an equivalent measure is reasonable.
- 01
Administrative safeguards
Security management, a designated security official, workforce access management, awareness training, incident procedures, contingency planning, and periodic evaluation. This is where most gaps are found, and where most of them are documentation rather than technology.
- 02
Physical safeguards
Facility access controls, workstation use and security, and device and media controls — including how equipment is disposed of and reused, which is a common finding for companies that run their own hardware.
- 03
Technical safeguards
Access control, audit controls, integrity, authentication of persons and entities, and transmission security. Where encryption is addressable rather than required, the decision has to be recorded rather than assumed.
Where HIPAA is not the whole question
Two others come up repeatedly alongside it, and both are assessed the same way.
- 01
FDA 21 CFR Part 11
Electronic records and electronic signatures: the controls that make an electronic record trustworthy enough to stand in for a paper one. It applies to regulated life sciences work rather than to care delivery, and the two are often confused.
- 02
HITRUST
A prescriptive control framework that maps across HIPAA and several other obligations at once. It is heavier than a HIPAA gap assessment and takes longer, and it is usually asked for by name rather than chosen.
Four steps, and a few hours of your time
The assessment is structured so the effort falls on us. What we need from you is access to the people who know how information actually moves.
- 01
Environment call
About an hour. What protected health information you hold, where it lives, who touches it, and which agreements you have already signed.
- 02
Assessment
A structured questionnaire built around the Security Rule rather than a generic control list, completed with your people rather than emailed to them.
- 03
Gap report and plan
A few business days. Findings against each safeguard, a remediation plan with effort and priority against every item, and a posture report written for management.
- 04
Debrief
A working session on what to do first, what can wait, and what to tell the customer who asked.
A readiness assessment, not a certificate
There is no such thing as HIPAA certification. No body issues one, and any supplier offering to make you "HIPAA certified" is selling you a document with no standing. What exists is compliance, demonstrated through evidence, and readiness, demonstrated through an assessment like this one.
We deliver the gap assessment and the remediation plan. Implementing the changes inside your systems stays with your team or your provider, and where you want hands-on help we scope it as separate work.
We are not your legal advisers. Whether a particular arrangement makes you a business associate, and what a specific agreement obliges you to, is a question for counsel — we will tell you plainly when you have reached that line.
A business associate agreement on your desk?
Tell us what you hold and who asked. We will tell you what the Security Rule expects of you and how far you are from it.