HIPAA: the Security Rule safeguards, checked continuously
Map the HIPAA Security Rule's administrative, physical and technical safeguards to controls with automated checks, keep the required risk analysis current, manage business associate agreements, and hand an assessor evidence that proves each safeguard operates.
What is HIPAA?
HIPAA is the US federal law that protects health information. Its Security Rule (45 CFR Part 164, Subpart C) requires covered entities and their business associates to protect electronic protected health information with administrative, physical and technical safeguards: a documented risk analysis and risk management process, workforce training and sanctions, access controls, audit controls, integrity controls, transmission security, contingency planning and more. The Privacy Rule governs how PHI may be used and disclosed, and the Breach Notification Rule sets the duty to notify affected people, the Department of Health and Human Services and sometimes the media after a breach of unsecured PHI. There is no government-issued HIPAA certification. An organization demonstrates compliance with a current risk analysis, implemented and documented safeguards, signed business associate agreements with the parties that handle PHI for it, and evidence that the safeguards operate, which is what an independent assessor or an enterprise customer's security review will ask to see.
HIPAA is the US Health Insurance Portability and Accountability Act of 1996. Its Privacy, Security and Breach Notification Rules govern how protected health information (PHI) is used, secured and disclosed by covered entities and their business associates. There is no official HIPAA certificate; compliance is demonstrated through a documented risk analysis, implemented safeguards, policies, training and agreements, and it is enforced by the HHS Office for Civil Rights.
Health-tech and SaaS companies that create, receive, store or transmit PHI for US healthcare customers, and any vendor those customers ask to sign a business associate agreement.
How Viglyn runs HIPAA
- Every Security Rule safeguard mapped to a control, with automated checks on your cloud, identity and device systems for the technical ones (access, audit logging, encryption, session controls) and structured evidence requests for the administrative and physical ones
- The required risk analysis and risk management plan run in the risk module, with risks linked to the safeguards that treat them and a dated record of every review
- Business associate agreements tracked per vendor in the vendor module, so the parties that touch PHI are known, assessed and under contract
- Policies, training records, contingency plans and breach procedures held as dated evidence with a full audit trail
- A readiness view per safeguard, and an export an independent assessor or an enterprise security team can verify outside Viglyn
The HIPAA questions that decide it
Is there a HIPAA certification?
No. HIPAA has no official certificate; the Department of Health and Human Services does not certify anyone. What exists is evidence: a current risk analysis, implemented safeguards, signed agreements and proof the safeguards operate. Some companies add an independent HIPAA assessment or a SOC 2 report with HIPAA criteria to show customers, and Viglyn supports both from the same evidence.
How long does HIPAA readiness take?
Weeks for a company that already runs basic security controls, longer when the risk analysis has to be done from scratch. The risk analysis, the policies and the business associate agreements are the slow parts; Viglyn's practitioners do them with you rather than hand you templates.
How much does HIPAA cost?
HIPAA counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. If you choose an independent assessment, the assessor's fee is separate and paid by you directly; we take no commission.
More HIPAA questions
Does HIPAA apply to us if we are not a healthcare company?
Can HIPAA share evidence with SOC 2?
What happens after a breach?
See HIPAA run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
