What HIPAA actually is
The HIPAA Security Rule sets administrative, physical and technical safeguards for electronic protected health information. Unlike SOC 2 or ISO 27001, there is no certifying body and no certificate — compliance is a legal obligation, demonstrated through your own documented safeguards, a required risk analysis, and evidence that you follow them. Business associate agreements govern PHI shared with vendors.
Who needs it
Covered entities and, far more commonly for software companies, business associates — anyone processing PHI on behalf of a provider, payer or clearinghouse. If a hospital or insurer is your customer, this applies to you.
How long it takes
There is no audit to schedule, so the timeline is driven by closing the gaps a risk analysis finds. That said, beware of anyone selling you a HIPAA certificate: none exists, and claiming certification is itself a credibility problem when a real assessor arrives.
What we do for your HIPAA program
- Conduct and document the required risk analysis, which is the control most often found missing
- Draft the safeguard policies and the workforce procedures that go with them
- Track business associate agreements and your subprocessor chain
- Monitor access controls, audit logging and encryption continuously
- Keep the documentation an OCR investigation or a customer security review would ask for
HIPAA questions we get asked
- Can we get HIPAA certified?
- No. There is no official HIPAA certification and no government body issues one. Any vendor offering you a HIPAA certificate is selling something that does not exist. What you can have is a documented, operating program and the evidence to demonstrate it.
- We are a business associate, not a covered entity. Does HIPAA apply?
- Yes. Business associates are directly liable under the Security Rule, and your customers will hold you to it contractually through a business associate agreement.
- Is a risk analysis really mandatory?
- Yes, and it is among the most frequently cited deficiencies in enforcement actions. It has to be documented, periodically reviewed, and actually connected to what you then did about the risks.
- Can HIPAA and SOC 2 share evidence?
- Substantially, yes. Access control, encryption, logging and workforce training evidence supports both. Running them together is considerably less work than running them separately.
