Data Protection

HIPAA Compliance Readiness

HIPAA compliance readiness for covered entities and business associates. We deliver the Security Rule risk analysis, the administrative and policy documentation the rules require, safeguards mapping, and Business Associate Agreement support. Your team implements the technical safeguards. We build the documented program that demonstrates your HIPAA compliance posture.

Overview

The Health Insurance Portability and Accountability Act, known as HIPAA, requires covered entities and their business associates to protect electronic protected health information (ePHI) through administrative, physical, and technical safeguards, all backed by a documented risk analysis and the right policies and agreements. Both sides of the relationship carry direct obligations under HIPAA rules. HHS defines covered entities as health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with HIPAA-standard covered transactions. Technology and service provider organisations that handle ePHI on behalf of covered entities are business associates, directly subject to HIPAA Security Rule safeguards and other applicable obligations under the rules.

We deliver the HIPAA compliance readiness work: a Security Rule risk analysis, the administrative and policy documentation the rules require, a safeguards mapping against all three categories, and Business Associate Agreement support. The HIPAA rules require you to protect the privacy and security of patient data and other sensitive health information throughout its lifecycle. Technical safeguards inside your environment are implemented by your teams. We define them, verify they are in place, and build the documented program that demonstrates your compliance posture.

HIPAA compliance services from Onyx Security Labs are scoped to your organisation's actual risk landscape. Healthcare data, including identifiable health records and clinical information, carries a high risk of harm if it is disclosed without authorisation. The Security Rule requires every covered entity and business associate to conduct a risk analysis that identifies vulnerabilities across every location where ePHI is created, received, maintained, and transmitted. We build that risk analysis and the risk management plan around it.

There is no official government HIPAA certification. Compliance is demonstrated through a documented risk analysis, implemented safeguards, current policies, and trained staff. HITRUST certification is a recognised framework that maps to HIPAA requirements and some organisations pursue it as a way to demonstrate a mature security framework to healthcare partners. We can advise on HITRUST alignment as part of a broader HIPAA compliance program.

What’s included

  • HIPAA Security Rule risk analysis
  • Risk management plan covering identified vulnerabilities
  • Privacy Rule and Security Rule policies and procedures
  • Administrative, physical, and technical safeguards mapping
  • Workforce training materials and sanction policy
  • Business Associate Agreement (BAA) review and support
  • Breach notification readiness under the Breach Notification Rule
  • Handling sensitive health information: policies for ePHI access controls and audit logging
  • Healthcare data confidentiality and data security gap analysis

How we work

  1. 01
    Risk analysis

    We perform the Security Rule risk analysis across every location where ePHI is created, received, maintained, and transmitted. This is the foundation the regulation builds everything else on, and it is the document an HHS (Department of Health and Human Services) audit will ask for first.

  2. 02
    Document the program

    We author the Privacy Rule and Security Rule policies and the safeguards documentation. Every document is specific to how your organisation handles ePHI and patient data. We also address how to protect PHI across your data flows and mitigate vulnerabilities in your current controls.

  3. 03
    Agreements and training

    We review Business Associate Agreements for coverage and accuracy and prepare workforce training materials your staff can use. A service provider that handles healthcare data on your behalf must have a signed BAA in place before you share any ePHI with them.

  4. 04
    Verify and advise

    We confirm the required technical safeguards are in place with your teams, build the risk management plan, and document the remediation steps for any gaps. The goal is to achieve HIPAA compliance that holds up to an audit or a covered entity's due diligence review.

What you get

  • HIPAA risk analysis
  • Risk management plan addressing identified vulnerabilities
  • Privacy and Security Rule policy and procedure set
  • Safeguards mapping and gap remediation plan
  • Workforce training materials and BAA support documentation
  • Healthcare data confidentiality and data security advisory report

Non-technical scope

We deliver the administrative, governance, and documentation side of HIPAA readiness, including the required risk analysis. Technical safeguards such as encryption, access controls, and audit logging are implemented by your own teams. We define what is required, verify it, and document the program. We do not deploy or operate technical controls inside your environment.

Frequently asked questions

Does HIPAA apply to us if we are not a healthcare provider?

It may. Business associates that handle ePHI on behalf of covered entities are directly subject to HIPAA Security Rule safeguards, but their breach-notification role differs from covered entities. If a breach occurs at or by a business associate, the business associate must notify the covered entity; it is the covered entity that handles notification to individuals, HHS, and in some cases the media, though those duties may be delegated by agreement. If you process health information for a covered entity as a service provider or technology vendor, the rules apply and you need a signed BAA. HIPAA regulations apply to the full chain of organisations that touch ePHI.

Is there an official HIPAA certification?

There is no official government HIPAA certification. HIPAA compliance is demonstrated through a documented risk analysis, implemented safeguards, current policies, and trained staff. We build that defensible body of evidence so you can show your work to an auditor, a regulator, or a covered entity asking for assurance. HITRUST certification is a separate, recognised framework that maps closely to HIPAA requirements.

What is the Security Rule risk analysis and why does it matter?

The HIPAA Security Rule requires every covered entity and business associate to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI. This security risk analysis is not optional. It is the document an HHS audit will ask for first, and it underpins every safeguard decision the program makes. Without it, you cannot demonstrate that your technical or administrative safeguards were chosen for defensible reasons.

Our software vendor says they are HIPAA compliant. Does that cover us?

No. A vendor's compliance covers their side of the relationship. You still need a signed Business Associate Agreement with them, and your own policies, risk analysis, and safeguards remain your responsibility. We review your vendor BAAs and build the documentation that covers your side. A SaaS platform claiming to be HIPAA-compliant does not transfer any of your obligations to them.

What is the difference between HIPAA compliance services and HIPAA compliance solutions?

HIPAA compliance solutions often refer to software platforms or automated tools that help manage policies and training. Our HIPAA compliance services are a professional engagement: we perform the risk analysis, author the documentation, map the safeguards, and verify controls with your teams. We do not sell software. We deliver the documented readiness work that regulators and covered entities expect.

Does disaster recovery planning fall under HIPAA?

Yes. The HIPAA Security Rule includes contingency plan requirements, which cover disaster recovery. The rule requires covered entities and business associates to have policies for data backup, disaster recovery, and emergency mode operation. We address contingency planning as part of the administrative safeguards documentation.

Credentials held by our team

ISO/IEC 27001 Lead Auditor
CISM
CISA
COBIT 2019
CEH
CRTP
eCPPT
CSA
CCNA
ITIL
Free tool · about 3 minutes · instant score

How ready is your security and compliance?

Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.

Start the free assessment

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.