Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
HIPAA

HIPAA: the Security Rule safeguards, checked continuously

Map the HIPAA Security Rule's administrative, physical and technical safeguards to controls with automated checks, keep the required risk analysis current, manage business associate agreements, and hand an assessor evidence that proves each safeguard operates.

What is HIPAA?

HIPAA is the US federal law that protects health information. Its Security Rule (45 CFR Part 164, Subpart C) requires covered entities and their business associates to protect electronic protected health information with administrative, physical and technical safeguards: a documented risk analysis and risk management process, workforce training and sanctions, access controls, audit controls, integrity controls, transmission security, contingency planning and more. The Privacy Rule governs how PHI may be used and disclosed, and the Breach Notification Rule sets the duty to notify affected people, the Department of Health and Human Services and sometimes the media after a breach of unsecured PHI. There is no government-issued HIPAA certification. An organization demonstrates compliance with a current risk analysis, implemented and documented safeguards, signed business associate agreements with the parties that handle PHI for it, and evidence that the safeguards operate, which is what an independent assessor or an enterprise customer's security review will ask to see.

In one paragraph

HIPAA is the US Health Insurance Portability and Accountability Act of 1996. Its Privacy, Security and Breach Notification Rules govern how protected health information (PHI) is used, secured and disclosed by covered entities and their business associates. There is no official HIPAA certificate; compliance is demonstrated through a documented risk analysis, implemented safeguards, policies, training and agreements, and it is enforced by the HHS Office for Civil Rights.

Who it's for

Health-tech and SaaS companies that create, receive, store or transmit PHI for US healthcare customers, and any vendor those customers ask to sign a business associate agreement.

With Viglyn

How Viglyn runs HIPAA

  • Every Security Rule safeguard mapped to a control, with automated checks on your cloud, identity and device systems for the technical ones (access, audit logging, encryption, session controls) and structured evidence requests for the administrative and physical ones
  • The required risk analysis and risk management plan run in the risk module, with risks linked to the safeguards that treat them and a dated record of every review
  • Business associate agreements tracked per vendor in the vendor module, so the parties that touch PHI are known, assessed and under contract
  • Policies, training records, contingency plans and breach procedures held as dated evidence with a full audit trail
  • A readiness view per safeguard, and an export an independent assessor or an enterprise security team can verify outside Viglyn
Straight answers

The HIPAA questions that decide it

Is there a HIPAA certification?

No. HIPAA has no official certificate; the Department of Health and Human Services does not certify anyone. What exists is evidence: a current risk analysis, implemented safeguards, signed agreements and proof the safeguards operate. Some companies add an independent HIPAA assessment or a SOC 2 report with HIPAA criteria to show customers, and Viglyn supports both from the same evidence.

How long does HIPAA readiness take?

Weeks for a company that already runs basic security controls, longer when the risk analysis has to be done from scratch. The risk analysis, the policies and the business associate agreements are the slow parts; Viglyn's practitioners do them with you rather than hand you templates.

How much does HIPAA cost?

HIPAA counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. If you choose an independent assessment, the assessor's fee is separate and paid by you directly; we take no commission.

FAQ

More HIPAA questions

Does HIPAA apply to us if we are not a healthcare company?
If you handle protected health information on behalf of a covered entity, for example a SaaS product used by hospitals, clinics or health plans, you are a business associate and the Security Rule applies to you directly. Your customers will ask you to sign a business associate agreement before they send PHI.
Can HIPAA share evidence with SOC 2?
Yes. Access control, logging, encryption, change management, vendor management and incident response evidence serves both. In Viglyn one evidence base maps across both, and SOC 2 reports can include HIPAA-related criteria for customers who ask.
What happens after a breach?
The Breach Notification Rule sets deadlines: affected individuals without unreasonable delay and no later than 60 days after discovery, the Department of Health and Human Services within 60 days for breaches affecting 500 or more people and annually for smaller ones, and the media for large breaches in a state or jurisdiction. Viglyn holds your breach procedure and incident records as evidence so the process is defined before it is needed.

See HIPAA run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.