Security Rule ยท 45 CFR 164
HIPAA
HIPAA has no certificate. What it has is a Security Rule risk analysis that OCR will ask for by name, and that most organizations either never completed or completed once in 2019.
What the engagement covers
Providers, payers, and the vendors who touch their data. Typical timeline: 6 to 10 weeks to a defensible posture.
- Security Rule risk analysis and risk management plan that survives scrutiny
- ePHI data flow mapping across systems, vendors and integrations
- Business Associate Agreement review and vendor risk process
- Workforce training, sanction policy and incident response procedures
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Risk analysis and ePHI inventory
- Risk management plan execution
- Policy, training and vendor controls
- Documented, defensible posture
Related reading
- Placeholder: HIPAA article
Pulled from the legacy archive until this section is migrated.
- Placeholder: HIPAA article
Legacy URL preserved.
Common questions
Is there such a thing as HIPAA certification?
No. No body certifies HIPAA compliance, and any vendor selling a HIPAA certificate is selling a document with no regulatory standing. What matters is the Security Rule risk analysis required at 45 CFR 164.308, plus evidence that the resulting risk management plan was carried out.
What does OCR actually ask for after an incident?
The risk analysis, by name, and the risk management plan that followed from it. Most organizations either never completed one or completed one years ago and never updated it after adding systems and vendors. That gap is the single most common finding.
Does a signed BAA make a vendor safe to use?
A BAA allocates liability. It does not verify that the vendor protects data. Consumer tier tools are a frequent problem here, because a BAA covering a company's enterprise product often does not cover the consumer product staff are actually using.
START HERE
Do not guess how far away you are.
A scored assessment against the HIPAA control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, which within 90 days takes 25% off the first year. Nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.