HIPAA
Who needs it
Healthcare providers, health plans, and healthcare clearinghouses directly, and any technology vendor, cloud provider, or contractor that creates, receives, maintains, or transmits ePHI on their behalf.
Key requirements
Documented risk analysis and risk management process, access controls and audit logging for ePHI, encryption of ePHI at rest and in transit (addressable but expected in practice), workforce training, and signed Business Associate Agreements with every vendor touching ePHI.
Cyber/privacy implications
The Security Rule's risk analysis requirement means controls must be justified by a documented risk assessment specific to your environment, not a generic policy template copied from another organization.
Assessment methodology
ePHI data-flow mapping, risk analysis against the Security Rule's administrative, physical, and technical safeguard categories, and a Business Associate Agreement inventory and review.
Implementation phases
Assess
Map ePHI flows and complete a formal risk analysis.
Remediate
Close safeguard gaps and formalize Business Associate Agreements.
Sustain
Ongoing workforce training and periodic risk analysis refresh.
Evidence & documentation requirements
Documented risk analysis, signed Business Associate Agreements, access and audit logs for systems handling ePHI, workforce training records, and breach-response procedures.
Common mistakes
Treating HIPAA as satisfied by a signed Business Associate Agreement alone without actually implementing the underlying safeguards; skipping the formal, documented risk analysis, which is the specific requirement regulators check first during an investigation.
Related standards
Expert review
FAQ
Request a Risk Analysis
Get the documented risk analysis HIPAA actually requires, not a generic template.
Request a Risk Analysis →