The HIPAA Privacy, Security, and Breach Notification Rules apply to covered entities — and to every business associate, subcontractor, and SaaS that creates, receives, maintains, or transmits Protected Health Information on their behalf. We deliver the Security Rule risk analysis, BAA support, and NIST CSF-aligned controls that survive an OCR audit.
HIPAA's Privacy, Security, and Breach Notification Rules layer together. The Security Rule is where most of the operational engineering happens — administrative, physical, and technical safeguards for electronic PHI. The Privacy Rule governs how PHI is used and disclosed. The Breach Notification Rule sets the 60-day clock on unsecured PHI incidents.
HIPAA's reach is wider than most early-stage healthcare companies assume. Covered entities are bound directly. Business associates — every SaaS, cloud, AI, or analytics vendor that touches PHI on a covered entity's behalf — are bound through contract (a signed BAA) and now directly through HIPAA itself. Subcontractors of business associates are bound downstream.
Direct HIPAA obligation. Hospitals, physician practices, mental health providers, dental groups, health plans (insurers, HMOs, Medicare), and healthcare clearinghouses that electronically transmit health information are covered entities. They own the Notice of Privacy Practices, the BAA program, and the Security Rule risk analysis.
If you create, receive, maintain, or transmit PHI on a covered entity's behalf, you are a business associate — regardless of stage or funding. A signed Business Associate Agreement is required. Pre-2013 this was contract-only; the HITECH Act and Omnibus Rule made HIPAA obligations attach directly. HHS has settled with digital-health and AI-triage startups over missing BAAs and inadequate safeguards.
A vendor that touches PHI on behalf of a business associate is itself a subcontractor — and bound by the same HIPAA requirements through a downstream BAA. Common examples: hosted databases serving the business associate's PHI workload, transcription services, analytics platforms, and AI model providers. The BAA chain must extend end-to-end.
NIST CSF Govern/Identify/Protect/Detect/Respond/Recover functions map directly to HIPAA Security Rule safeguards. A mature NIST CSF posture — risk register, access reviews, audit trails, contingency planning, documented incident response — substantially closes the HIPAA audit gap and gives HHS/OCR a recognizable evidence trail. Here's the realistic mapping.
| NIST CSF Function | Scope | HIPAA Security Rule Safeguards | Est. NIST CSF Overlap |
|---|---|---|---|
| GV — Govern | Organizational context, risk management strategy, supply chain | §164.308(a)(1)(ii)(B) Risk Management; §164.308(a)(1)(ii)(C) Sanction Policy; §164.308(a)(1)(ii)(D) Information System Activity Review | |
| ID — Identify | Asset management, risk assessment, governance | §164.308(a)(1)(ii)(A) Entity-Level Risk Analysis; §164.316(b)(2)(iii) Documentation; Asset inventory supporting §164.308(a)(1)(ii)(D) | |
| PR — Protect | Access control, awareness, data security, platform security | §164.308(a)(3) Workforce Security; §164.308(a)(4) Information Access Management; §164.308(a)(5) Security Awareness; §164.312(a) Access Control; §164.312(c) Integrity; §164.312(d) Person or Entity Authentication; §164.312(e) Transmission Security | |
| DE — Detect | Continuous monitoring, anomaly detection, security testing | §164.308(a)(1)(ii)(D) Information System Activity Review; §164.312(b) Audit Controls | |
| RS — Respond | Incident management, analysis, mitigation, communication | §164.308(a)(6) Security Incident Procedures; §164.404 Individual Breach Notification | |
| RC — Recover | Recovery planning, improvements, communications | §164.308(a)(7) Contingency Plan (Data Backup, Disaster Recovery, Emergency Mode Operations, Testing & Revision, Applications & Data Criticality Analysis) |
What this means for you: If you've already invested in a NIST CSF program — or purchased a Rhodigital NIST Policy Package — your HIPAA Security Rule foundation is largely in place. A HIPAA gap assessment identifies which §164.308–.312 safeguards your existing documentation satisfies and which still require dedicated HIPAA evidence (BAA register, Breach Notification playbook, minimum-necessary access reviews, documented risk analysis under §164.308(a)(1)(ii)(A)). See the NIST Policy Package →
Most healthcare and life-sciences companies face overlapping privacy and assurance obligations. HIPAA is mandatory federal regulation with tiered penalties — SOC 2 is a voluntary attestation you commission for enterprise buyers, HITRUST is a certifiable framework often required by large healthcare customers, and GDPR covers EU personal data with a 72-hour breach clock. Knowing how they relate prevents redundant work and missed obligations.
HIPAA protects Protected Health Information held by covered entities and business associates; GDPR covers any personal data of EU subjects. Both require breach notification but on very different clocks — HIPAA 60 days, GDPR 72 hours to the supervisory authority. HIPAA penalties are tiered by culpability (up to ~$2M/violation/year per OCR tier structure); GDPR penalties are capped at 4% of global turnover.
HIPAA is a binding federal regulation with mandatory safeguards and breach notification. SOC 2 is a voluntary attestation report that service organizations commission to win enterprise SaaS deals. SOC 2 covers a broader set of trust services criteria but HIPAA-specific controls (BAA register, §164.308 risk analysis, minimum-necessary access enforcement, breach notification playbook) are not directly addressed by SOC 2 criteria.
HIPAA is the floor: minimum safeguards and breach notification obligations. HITRUST CSF is a certifiable framework that layers additional controls from NIST, ISO, PCI, and HIPAA into a single assurance model. HITRUST certification is often required by enterprise healthcare customers, large payers, and prime vendors. Many healthcare SaaS organizations pursue HITRUST not in place of HIPAA but alongside it — certification against a recognized framework with HIPAA evidence as baseline.
HITECH tightened HIPAA breach notification, raised penalties, and extended direct obligations to business associates. Most states have separate breach notification laws (California, New York, Texas, Massachusetts) that trigger on additional data categories with their own clocks and AG notification channels. A defensible program runs HIPAA plus the relevant state-law matrix — especially for organizations handling PHI alongside other state-regulated personal data.
HIPAA readiness is not a single project — it's a living program. We follow a phased engagement that ends with sustained operational coverage (quarterly posture reviews, annual incident-response testing, ongoing BAA management) rather than an open-ended consulting relationship.
Clarify your role: covered entity, business associate, or subcontractor. Map every PHI flow in your environment, every BAA you've signed and need to sign, every downstream subcontractor BAA required. This is the most consequential decision in the engagement — mis-identifying your role propagates errors through every later artifact.
Conduct the §164.308(a)(1)(ii)(A) entity-level risk analysis if you haven't already. Layer in a NIST CSF baseline assessment for the technical controls (Access Control per §164.312(a), Audit Controls per §164.312(b), Integrity per §164.312(c), Transmission Security per §164.312(e)). Output: a prioritized gap register with remediation effort and OCR-defense rationale for every risk-acceptance decision.
Close the gaps. This phase produces policy documentation (Privacy & Security policies aligned to §164.316(b)), technical control hardening (RBAC, encryption-at-rest for ePHI, audit logging mapped to §164.312(b)), a BAA template library with sub-contractor BAA flow-down language, and the §164.404 Breach Notification playbook with 60-day decisioning and HHS/state-notification routes pre-mapped to >500 vs ≤500 scenarios.
Sustained coverage: quarterly posture reviews, annual incident-response test (including breach-notification dry run), BAA register maintenance with renewal reminders for expiring agreements, and ongoing monitoring of HHS OCR enforcement trends that affect healthcare entities of your size. Yes — we sign BAAs. HIPAA doesn't end at the initial gap assessment.
Start with a free security posture check. Find your §164.308 gaps — and your missing BAAs — before your next enterprise deal or board meeting. Yes — we sign BAAs.