HIPAA compliance program
Build a HIPAA compliance program you can actually operate.
Not a template folder. A working program: risk analysis, customized policies, trained staff, covered vendors, and incident readiness — with evidence for all of it.
A note on terminology: HIPAA has no official private certification, and a private assessment does not replace your legal obligations. We implement and assess your program; responsibility for compliance remains with your organization.
Who HIPAA applies to.
A simple decision path — with a clear recommendation to involve counsel when your status is genuinely uncertain.
Covered entities
Health care providers who transmit standard electronic transactions, health plans, and clearinghouses. If you bill insurance or deliver care, this is likely you.
Business associates
Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity — most healthcare SaaS, hosting, analytics, billing, and AI companies serving providers fall here.
Genuinely unclear?
Some models — wellness apps sold directly to consumers, de-identified data businesses — sit near the boundary. We assess applicability first and recommend qualified counsel for close calls rather than guessing.
What the program covers.
Operational readiness across the Privacy, Security, and Breach Notification Rules, within a scope we agree on up front.
Administrative safeguards
- Security management process and risk analysis
- Assigned security responsibility
- Workforce security and authorization
- Training and security awareness
- Incident procedures and contingency planning
- Business associate contracts
Physical safeguards
- Facility access controls
- Workstation use and security
- Device and media controls
- Disposal and media re-use procedures
Technical safeguards
- Access control and unique user identification
- Audit controls and activity logging
- Integrity controls
- Person or entity authentication
- Transmission security and encryption
How we run the risk analysis.
The Security Rule risk analysis anchors the entire program. Ours is methodical, documented, and reusable at every annual refresh.
- 1Inventory assets, systems, and everywhere ePHI is created, received, maintained, or transmitted
- 2Identify threats and vulnerabilities relevant to each asset
- 3Assess likelihood and impact for each threat/vulnerability pair
- 4Document existing controls and their effectiveness
- 5Determine residual risk and rank it
- 6Select treatment: remediate, mitigate, transfer, or accept with justification
- 7Document everything and set the review cycle
Then the program around it
Policies and procedures customized to how your organization actually works, with owners, approval records, version history, and staff acknowledgment — because an unacknowledged policy protects no one.
Workforce training assigned by role, tracked to completion, and repeated annually, with sanctions procedures documented.
Vendors and BAAs: every vendor that touches PHI inventoried, its agreement status tracked, and renewal reminders set before anything lapses.
Incidents and breaches: playbooks for assessment, documentation, and notification decisions, plus an incident log — built before you need them.
Evidence binder and annual calendar: everything above, organized and dated, with a standing schedule so the program keeps operating after go-live.
The package.
Full inclusions, exclusions, and pricing — no quote-wall.
HIPAA Foundations
Small practices, business associates, and early-stage healthcare vendors that need a documented HIPAA program but are not pursuing SOC 2 yet.
$4,500 implementation
+ $399/month ongoing
Or $7,500/year prepaid.
Target: 4–8 weeks
Timelines are targets, assuming timely client responses.
Included
- Applicability and entity-status assessment
- HIPAA Security Rule risk analysis
- Privacy and security gap assessment
- Remediation plan prioritized by risk
- Administrative, physical, and technical safeguard review
- Policy and procedure library customized to your organization
- Security/privacy officer role documentation
- Workforce HIPAA training and completion tracking
- Sanctions and policy-acknowledgment workflow
- Business associate inventory and BAA tracking
- Asset and system inventory
- PHI/ePHI data-flow inventory
- Incident response and breach-notification playbooks
- Incident log and investigation template
- Contingency plan, backup, disaster recovery, and emergency-mode review
- Annual review calendar and evidence binder
- Final readiness summary with legally accurate wording
- Quarterly check-in during the ongoing term
Not included unless purchased
- Penetration testing
- Legal opinions
- Hands-on cloud remediation
- SOC 2 CPA examination
- HITRUST validation
- State-law analysis
- 24/7 incident response
Also pursuing SOC 2? The combined program maps both frameworks into one control library.
HIPAA terminology and program FAQ
Can we become 'HIPAA certified'?
No one can be officially HIPAA certified. HHS does not recognize or endorse any private certification. What your organization can do — and what buyers and regulators actually look for — is implement a documented HIPAA compliance program and complete an independent readiness assessment with evidence behind it. That is what we deliver.
Does HIPAA apply to us?
If you are a health care provider, health plan, or clearinghouse, you are likely a covered entity. If you create, receive, maintain, or transmit protected health information on behalf of one — as most healthcare SaaS and AI vendors do — you are likely a business associate. Edge cases exist; when your status is genuinely unclear, we recommend confirming with qualified counsel, and we will say so rather than guess.
What exactly do we get at the end?
A documented, operating program: your completed risk analysis, a customized policy set with recorded acknowledgments, training completions, a vendor/BAA inventory, incident playbooks and log, a contingency plan review, an annual calendar, and a final readiness summary — organized in an evidence binder you can hand to a customer or assessor.
Is a risk analysis really required?
Yes. The Security Rule requires an accurate and thorough assessment of risks to ePHI, and a missing or superficial risk analysis is one of the most common findings in enforcement actions. It is also genuinely useful: it decides what you fix first.
How long does implementation take?
Our target is 4–8 weeks for HIPAA Foundations, assuming timely client responses. Complex environments and slower feedback cycles extend that. We publish targets, not guarantees.
What is not included?
Penetration testing, legal opinions, hands-on cloud remediation, the SOC 2 CPA examination, HITRUST validation, state-law analysis, and 24/7 incident response are separate. Several are available as add-ons or partner services.
Start with a real risk analysis, not a template.
In 30 minutes we'll map your entity status, likely gaps, and a realistic timeline.