HHS OCR enforcement actions continue — settlements in the millions · 60-day breach clock applies to every business associate, not only covered entities
HIPAA Compliance Consulting

HIPAA doesn't end at covered entities.
If you handle PHI, you're in scope.

The HIPAA Privacy, Security, and Breach Notification Rules apply to covered entities — and to every business associate, subcontractor, and SaaS that creates, receives, maintains, or transmits Protected Health Information on their behalf. We deliver the Security Rule risk analysis, BAA support, and NIST CSF-aligned controls that survive an OCR audit.

Compliance scope
§164.308 Administrative §164.312 Technical §164.404 Breach Notice BAA Support NIST CSF Mapping HHS OCR Ready
The framework

Three HIPAA rules. Most work concentrates in the Security Rule.

HIPAA's Privacy, Security, and Breach Notification Rules layer together. The Security Rule is where most of the operational engineering happens — administrative, physical, and technical safeguards for electronic PHI. The Privacy Rule governs how PHI is used and disclosed. The Breach Notification Rule sets the 60-day clock on unsecured PHI incidents.

§164.308–.312
Security Rule
Administrative · Physical · Technical safeguards
Sets the safeguard floor for electronic PHI. Risk analysis, workforce training, access control, audit controls, integrity, transmission security. The operational backbone of a HIPAA compliance program.
§164.500–.534
Privacy Rule
Permitted uses & disclosures · Individual rights
Governs who can use or disclose PHI, minimum-necessary standard, patient access and amendment rights, Notice of Privacy Practices. Pre-dates the Security Rule and applies to PHI in any form.
§164.400–.414
Breach Notification Rule
60-day clock · HHS + media notification
Unsecured PHI breaches trigger individual notice within 60 days, HHS notice (annual log for ≤500 affected, 60-day for >500), and prominent media notice in the affected state for breaches exceeding 500 residents.
Applicability

Three roles. Every one of them has HIPAA obligations.

HIPAA's reach is wider than most early-stage healthcare companies assume. Covered entities are bound directly. Business associates — every SaaS, cloud, AI, or analytics vendor that touches PHI on a covered entity's behalf — are bound through contract (a signed BAA) and now directly through HIPAA itself. Subcontractors of business associates are bound downstream.

Covered Entity

Healthcare Providers, Health Plans & Clearinghouses

Direct HIPAA obligation. Hospitals, physician practices, mental health providers, dental groups, health plans (insurers, HMOs, Medicare), and healthcare clearinghouses that electronically transmit health information are covered entities. They own the Notice of Privacy Practices, the BAA program, and the Security Rule risk analysis.

Trigger: any electronic PHI transaction.
Business Associate

SaaS, Cloud, AI & Service Vendors Handling PHI

If you create, receive, maintain, or transmit PHI on a covered entity's behalf, you are a business associate — regardless of stage or funding. A signed Business Associate Agreement is required. Pre-2013 this was contract-only; the HITECH Act and Omnibus Rule made HIPAA obligations attach directly. HHS has settled with digital-health and AI-triage startups over missing BAAs and inadequate safeguards.

Trigger: any PHI handling on behalf of a covered entity.
Subcontractor

Subcontractors of Business Associates

A vendor that touches PHI on behalf of a business associate is itself a subcontractor — and bound by the same HIPAA requirements through a downstream BAA. Common examples: hosted databases serving the business associate's PHI workload, transcription services, analytics platforms, and AI model providers. The BAA chain must extend end-to-end.

Trigger: PHI handling in a BA-of-BA relationship.
NIST CSF & HIPAA Security Rule

Your NIST CSF work is your HIPAA Security Rule foundation.

NIST CSF Govern/Identify/Protect/Detect/Respond/Recover functions map directly to HIPAA Security Rule safeguards. A mature NIST CSF posture — risk register, access reviews, audit trails, contingency planning, documented incident response — substantially closes the HIPAA audit gap and gives HHS/OCR a recognizable evidence trail. Here's the realistic mapping.

NIST CSF Function Scope HIPAA Security Rule Safeguards Est. NIST CSF Overlap
GV — Govern Organizational context, risk management strategy, supply chain §164.308(a)(1)(ii)(B) Risk Management; §164.308(a)(1)(ii)(C) Sanction Policy; §164.308(a)(1)(ii)(D) Information System Activity Review
~55%
ID — Identify Asset management, risk assessment, governance §164.308(a)(1)(ii)(A) Entity-Level Risk Analysis; §164.316(b)(2)(iii) Documentation; Asset inventory supporting §164.308(a)(1)(ii)(D)
~60%
PR — Protect Access control, awareness, data security, platform security §164.308(a)(3) Workforce Security; §164.308(a)(4) Information Access Management; §164.308(a)(5) Security Awareness; §164.312(a) Access Control; §164.312(c) Integrity; §164.312(d) Person or Entity Authentication; §164.312(e) Transmission Security
~75%
DE — Detect Continuous monitoring, anomaly detection, security testing §164.308(a)(1)(ii)(D) Information System Activity Review; §164.312(b) Audit Controls
~70%
RS — Respond Incident management, analysis, mitigation, communication §164.308(a)(6) Security Incident Procedures; §164.404 Individual Breach Notification
~60%
RC — Recover Recovery planning, improvements, communications §164.308(a)(7) Contingency Plan (Data Backup, Disaster Recovery, Emergency Mode Operations, Testing & Revision, Applications & Data Criticality Analysis)
~50%

What this means for you: If you've already invested in a NIST CSF program — or purchased a Rhodigital NIST Policy Package — your HIPAA Security Rule foundation is largely in place. A HIPAA gap assessment identifies which §164.308–.312 safeguards your existing documentation satisfies and which still require dedicated HIPAA evidence (BAA register, Breach Notification playbook, minimum-necessary access reviews, documented risk analysis under §164.308(a)(1)(ii)(A)). See the NIST Policy Package →

Framework comparison

How HIPAA compares to GDPR, SOC 2, and HITRUST.

Most healthcare and life-sciences companies face overlapping privacy and assurance obligations. HIPAA is mandatory federal regulation with tiered penalties — SOC 2 is a voluntary attestation you commission for enterprise buyers, HITRUST is a certifiable framework often required by large healthcare customers, and GDPR covers EU personal data with a 72-hour breach clock. Knowing how they relate prevents redundant work and missed obligations.

vs GDPR

Narrower data, slower breach clock, no turnover-based fines

HIPAA protects Protected Health Information held by covered entities and business associates; GDPR covers any personal data of EU subjects. Both require breach notification but on very different clocks — HIPAA 60 days, GDPR 72 hours to the supervisory authority. HIPAA penalties are tiered by culpability (up to ~$2M/violation/year per OCR tier structure); GDPR penalties are capped at 4% of global turnover.

vs SOC 2

Mandatory regulation vs voluntary attestation

HIPAA is a binding federal regulation with mandatory safeguards and breach notification. SOC 2 is a voluntary attestation report that service organizations commission to win enterprise SaaS deals. SOC 2 covers a broader set of trust services criteria but HIPAA-specific controls (BAA register, §164.308 risk analysis, minimum-necessary access enforcement, breach notification playbook) are not directly addressed by SOC 2 criteria.

vs HITRUST

Regulation vs certifiable framework

HIPAA is the floor: minimum safeguards and breach notification obligations. HITRUST CSF is a certifiable framework that layers additional controls from NIST, ISO, PCI, and HIPAA into a single assurance model. HITRUST certification is often required by enterprise healthcare customers, large payers, and prime vendors. Many healthcare SaaS organizations pursue HITRUST not in place of HIPAA but alongside it — certification against a recognized framework with HIPAA evidence as baseline.

vs HITECH / State Laws

Federal HIPAA plus state breach notification patchwork

HITECH tightened HIPAA breach notification, raised penalties, and extended direct obligations to business associates. Most states have separate breach notification laws (California, New York, Texas, Massachusetts) that trigger on additional data categories with their own clocks and AG notification channels. A defensible program runs HIPAA plus the relevant state-law matrix — especially for organizations handling PHI alongside other state-regulated personal data.

How we work

From BAA in/out scoping to ongoing BAA management.

HIPAA readiness is not a single project — it's a living program. We follow a phased engagement that ends with sustained operational coverage (quarterly posture reviews, annual incident-response testing, ongoing BAA management) rather than an open-ended consulting relationship.

01
Phase 1 · Week 1–2
BAA In/Out Scoping & HIPAA Role Mapping

Clarify your role: covered entity, business associate, or subcontractor. Map every PHI flow in your environment, every BAA you've signed and need to sign, every downstream subcontractor BAA required. This is the most consequential decision in the engagement — mis-identifying your role propagates errors through every later artifact.

02
Phase 2 · Week 2–4
§164.308 Risk Analysis & NIST Baseline Gap Assessment

Conduct the §164.308(a)(1)(ii)(A) entity-level risk analysis if you haven't already. Layer in a NIST CSF baseline assessment for the technical controls (Access Control per §164.312(a), Audit Controls per §164.312(b), Integrity per §164.312(c), Transmission Security per §164.312(e)). Output: a prioritized gap register with remediation effort and OCR-defense rationale for every risk-acceptance decision.

03
Phase 3 · Week 4–10
Remediation, BAA Library & Breach Notification Playbook

Close the gaps. This phase produces policy documentation (Privacy & Security policies aligned to §164.316(b)), technical control hardening (RBAC, encryption-at-rest for ePHI, audit logging mapped to §164.312(b)), a BAA template library with sub-contractor BAA flow-down language, and the §164.404 Breach Notification playbook with 60-day decisioning and HHS/state-notification routes pre-mapped to >500 vs ≤500 scenarios.

04
Phase 4 · Ongoing
Quarterly Posture Reviews & Annual Incident Response Test

Sustained coverage: quarterly posture reviews, annual incident-response test (including breach-notification dry run), BAA register maintenance with renewal reminders for expiring agreements, and ongoing monitoring of HHS OCR enforcement trends that affect healthcare entities of your size. Yes — we sign BAAs. HIPAA doesn't end at the initial gap assessment.

Don't let a HIPAA gap surface during an OCR audit.

Start with a free security posture check. Find your §164.308 gaps — and your missing BAAs — before your next enterprise deal or board meeting. Yes — we sign BAAs.

Frequently asked

Common HIPAA questions.

What is HIPAA and who is required to comply? +
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a US federal regulation that governs how individually identifiable health information is created, received, maintained, or transmitted. Two categories are bound: covered entities — healthcare providers that electronically transmit health information, health plans, and healthcare clearinghouses — and business associates, any service provider (including cloud, SaaS, AI, and analytics vendors) that creates, receives, maintains, or transmits Protected Health Information (PHI) on a covered entity's behalf. PHI is any individually identifiable health information held or transmitted by a covered entity or business associate — including demographic data, payment information, diagnoses, treatment records, and any information that could be used to identify an individual in a health context.
What are the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule? +
Three HIPAA rules drive most compliance work. The Security Rule (45 CFR §164.308–.312) requires administrative, physical, and technical safeguards for electronic PHI (ePHI). The Privacy Rule (§164.500–.534) governs the permitted uses and disclosures of PHI and the individual right to access. The Breach Notification Rule (§164.400–.414) requires notification to affected individuals within 60 days of an unsecured PHI breach, notification to HHS, and — for breaches affecting more than 500 residents of a state — prominent media notice in the affected state.
Is HIPAA required for healthtech startups and SaaS handling PHI? +
Yes. Any startup, SaaS, or service provider that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate and must comply with HIPAA — regardless of stage, funding, or location. A signed Business Associate Agreement (BAA) is required from every downstream vendor that touches PHI. HHS Office for Civil Rights enforcement has reached settlements with digital-health, cloud-storage, and AI-triage startups — most famously a national online book retailer, a major cloud storage provider, and several AI-driven health platforms. Business-associate obligations are not optional even before product-market fit, and a missing or inadequate BAA is one of the most common OCR enforcement triggers.
How does NIST CSF align to the HIPAA Security Rule? +
NIST CSF Govern/Identify/Protect/Detect/Respond/Recover functions map cleanly to HIPAA Security Rule safeguards. PR.AC (Access Control) maps to §164.312(a); RS.AN and PR.DS (Audit and Data Security) align with §164.308(a)(1)(ii)(D) Information System Activity Review and §164.312(b) Audit Controls. PR.IP and ID.GV (Protective Processes and Governance) cover §164.308(a)(1)(ii)(B) Risk Management. A mature NIST CSF posture — risk register, access reviews, audit trails, incident response, contingency planning — substantially closes HIPAA audit gaps and gives HHS/OCR auditors a recognizable evidence trail.
What is the difference between HIPAA and HITRUST vs SOC 2? +
HIPAA is a federal regulation: mandatory, enforced by HHS Office for Civil Rights with tiered penalties reaching millions of dollars per violation category. HITRUST CSF is a certifiable framework that layers additional controls (NIST, ISO, PCI, HIPAA) into a single assurance model — often required by enterprise healthcare customers and prime vendors. SOC 2 is a voluntary attestation covering a service organization's controls, widely used to win enterprise SaaS deals across industries. Many healthcare SaaS organizations maintain SOC 2 for enterprise sales, HITRUST certification for healthcare-specific buyers, and HIPAA documentation as the regulatory baseline — three different artifacts serving different audiences from overlapping control inventories.