All frameworks
HIPPrivacy & Security

HIPAA compliance

Safeguards for protected health information.

HIPAA governs how protected health information (PHI) is handled in the US. The Security Rule mandates administrative, physical and technical safeguards; the Privacy Rule governs use and disclosure; the Breach Notification Rule sets response obligations.

Start from the basics

The standard

HIPAA — US Health Insurance Portability and Accountability Act

Who needs it

Covered entities (providers, health plans) and their business associates — including any software vendor that creates, receives, maintains or transmits PHI.

3

Rules: Security · Privacy · Breach

The basics

What is HIPAA?

HIPAA is the US law that governs how protected health information (PHI) is handled. If your product touches health data — or your customers' does — it sets the rules for keeping that data private and secure, and for what happens if it leaks.

For software companies, the Security Rule is where most of the work lives: administrative, physical and technical safeguards for electronic PHI. The Privacy Rule governs how PHI can be used and shared, and the Breach Notification Rule starts a clock ticking the moment something goes wrong.

Why it matters

What HIPAA does for your business

It's the price of entry in healthcare

No healthcare customer will touch a vendor that can't demonstrate HIPAA safeguards — and they'll want a signed BAA before go-live.

The penalties are real

Violations carry serious fines and reputational damage. Getting the safeguards right protects the business, not just the data.

It earns trust in a cautious market

Healthcare buyers are risk-averse by nature. Demonstrable HIPAA compliance is how you earn the benefit of the doubt.

What it covers

Security Rule

Administrative, physical and technical safeguards for electronic PHI.

Privacy Rule

Rules for the permitted use and disclosure of PHI.

Breach notification

Defined obligations and timelines when PHI is exposed.

Business Associate Agreements

Contracts that flow safeguards down the supply chain.

The hard way

HIPAA has no certificate to hang on the wall, which tempts teams to treat it as a paperwork exercise — until a customer's security review or an actual incident exposes the gaps. Evidence you can produce on demand beats a policy nobody's read.

The easier way, with Compliance One

  • Maps the HIPAA Security Rule safeguards to concrete, evidenced controls.
  • Tracks BAAs, risk analyses and workforce training in one register.
  • Encrypts and isolates evidence per-organisation, with data-region choice.
  • Reuses safeguards already implemented for SOC 2 or ISO 27001.

Do it once, reuse it everywhere. Evidence you collect for HIPAAis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is there a HIPAA certification?
Not officially — HIPAA is a legal obligation, not a certificate. You implement the safeguards, document them, and demonstrate compliance (often via a third-party assessment). Compliance One keeps that evidence audit-ready.
What's a BAA?
A Business Associate Agreement — a contract that flows HIPAA obligations to vendors handling PHI on your behalf. We help you track them so none slip through.
We have SOC 2 — does that cover HIPAA?
It's a strong head start. Many security safeguards overlap, so Compliance One reuses that work and layers on HIPAA's specific requirements.

Ready to tackle HIPAA?

See exactly how Compliance One maps HIPAA to your environment in a 30-minute walkthrough — and how much of it we handle for you.