HIPAA is three separate engagements, and satisfying one does not satisfy the others. Our Certified Information Systems Auditors cover the Security Rule, the Privacy and Breach Notification Rules, and the Security Risk Analysis, and tell you plainly which of them you actually need.
Get Your QuoteThe Health Insurance Portability and Accountability Act protects the confidentiality, integrity, and availability of protected health information (PHI). It is enforced by the Office for Civil Rights at the U.S. Department of Health and Human Services, and since the HITECH Act it applies directly to business associates, not only to the covered entities that hire them.
A covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a covered transaction. A business associate is anyone who creates, receives, maintains, or transmits protected health information on a covered entity’s behalf: billing companies, IT providers, cloud hosts, transcription services, analytics vendors, and their own subcontractors. If protected health information passes through your systems, the rule reaches you whether or not you treat a single patient.
This is the single most common misunderstanding we correct. Organizations tell us they have “done HIPAA” because they completed one assessment, and then discover during an investigation that the other two obligations were never addressed. A HIPAA Security Rule audit, a HIPAA Privacy Rule audit, and a HIPAA Security Risk Analysis (SRA) are three distinct requirements with three distinct sets of evidence, and the Breach Notification Rule sits with the second of them. Below is which is which, and which of our services delivers it.
Most organizations subject to HIPAA need all three, at different times and for different reasons. Each is scoped, performed, and reported separately.
The safeguards around electronic protected health information.
Delivered as part of our compliance audit, alongside ISO 27001, SOC 2 readiness, and other frameworks where you need them assessed together.
How protected health information may be used and disclosed, and what happens when it is not.
Delivered as part of our privacy audit, which also covers CCPA and CPRA, CIPA website tracking, and GDPR processor obligations where they apply to you.
A required implementation specification in its own right, not a by-product of the audit.
Delivered as part of our risk assessment. It is the requirement most often assumed to be covered by a Security Rule audit, and it is not.
The Department of Health and Human Services does not certify, accredit, or endorse any organization as HIPAA compliant, and no auditor or vendor can make you compliant by selling you a certificate. Treat any firm offering one with caution.
What an independent audit gives you instead is evidence: a documented, third-party assessment of your safeguards against the rule, a record that you performed the analysis the rule requires, and a dated plan showing what you did about what was found. That is what the Office for Civil Rights asks for, and it is what we produce. Where you need visible assurance to show a customer or a board, our auditor opinion letter states what was examined and what we found, under our own credential.
Every finding rated by risk, with the specific rule reference it relates to, the evidence we examined, and step-by-step remediation instructions your team can act on without a translator.
Where the engagement includes the Security Risk Analysis, you receive the documented analysis and risk management plan in the form the rule expects you to be able to produce on request.
Ninety days of free post-audit support while you remediate, so questions that come up during the work reach the auditor who did it rather than a help desk.
No. HHS does not certify or endorse any organization as HIPAA compliant, and there is no government-recognized HIPAA certificate. What you can obtain is an independent audit and a documented record of your safeguards, your risk analysis, and your remediation. That is what regulators and customers actually ask to see.
The Security Rule audit tests whether your administrative, physical, and technical safeguards are in place and working. The Security Risk Analysis is a separate required implementation specification: an assessment of the risks and vulnerabilities to electronic protected health information across your whole environment, with a documented risk determination for each. Passing the first does not satisfy the second.
Yes. Since the HITECH Act, business associates carry direct liability for the Security Rule and for parts of the Privacy Rule, and enforcement action can be taken against them without involving the covered entity. Subcontractors that handle protected health information on a business associate’s behalf are covered too.
The rule requires it to be accurate and current rather than setting a fixed interval. In practice that means annually for most organizations, and again whenever something material changes: a new system holding protected health information, a merger, a move to a new cloud provider, or a security incident.
Not on its own. A SOC 2 report addresses trust services criteria chosen for that engagement and is issued by a CPA firm. It can overlap usefully with the Security Rule, but it does not address the Privacy Rule, the Breach Notification Rule, or the Security Risk Analysis requirement. We are often asked to map the two so you can reuse evidence rather than gather it twice.
Individually identifiable health information held or transmitted by a covered entity or business associate, in any form. It is broader than medical records: appointment scheduling data, billing information, and IP addresses or device identifiers tied to a patient can all qualify. Scoping this correctly is usually the first thing an audit fixes.
Your current risk analysis and risk management plan, your policies and procedures with evidence they are followed, workforce training records, business associate agreements, and your breach determination documentation. Investigations frequently begin after a breach report or a complaint, and the first request is usually for the risk analysis.
It depends on the number of systems holding protected health information, the number of locations, and how many of the three engagements you need. We confirm scope and timeline in your proposal before work begins, and the proposal includes the CVs of the assigned audit team and sample reports.
No. HITECH is not a second framework you audit against. Its provisions were written into the HIPAA rules themselves by the 2013 Omnibus Rule, so a HIPAA audit already covers them. What HITECH changed is worth knowing: it extended direct liability to business associates, raised the penalty tiers, and led to the Breach Notification Rule. All three are in scope here, which is why this engagement covers business associates and breach determination rather than treating them as extras.