HIPAA

HIPAA compliance that holds up under OCR scrutiny

The US law governing protected health information. GRXForce's AI Evidence Agent operationalizes the Privacy, Security, and Breach Notification Rules, testing each safeguard and drafting the workpaper, so PHI safeguards are provable, not just written down.

Overview

What is HIPAA?

HIPAA (the Health Insurance Portability and Accountability Act) governs how covered entities and their business associates handle Protected Health Information (PHI) in the US. The Security Rule requires administrative, physical, and technical safeguards; the Privacy Rule governs use and disclosure of PHI; the Breach Notification Rule sets reporting timelines to affected individuals, HHS, and sometimes the media. Enforcement sits with the HHS Office for Civil Rights (OCR), which can levy penalties per violation category.

Requirements

What it takes, at a glance

  • A current Security Rule risk analysis covering all systems that touch PHI
  • Administrative, physical, and technical safeguards implemented and evidenced
  • Business Associate Agreements executed with every vendor that touches PHI
  • Workforce training on PHI handling, documented and refreshed regularly
  • A breach notification process meeting HHS and affected-individual timelines
Checklist

Your readiness checklist

  • Run or refresh the Security Rule risk analysis across all PHI-touching systems
  • Close gaps in administrative, physical, and technical safeguards
  • Execute Business Associate Agreements with every vendor touching PHI
  • Deliver and document workforce PHI training on a recurring cadence
  • Build and rehearse breach notification timelines to HHS and affected individuals
Implementation roadmap

How the timeline actually breaks down

Weeks 1-3Risk analysisIdentify every system touching PHI and assess risk to confidentiality, integrity, availability.
Weeks 4-9SafeguardsImplement administrative, physical, and technical safeguards against the identified risks.
Weeks 10-11Vendor accountabilityBusiness Associate Agreements executed with every relevant vendor.
OngoingOperate continuouslyNo certificate exists, training, risk analysis, and breach readiness need to stay current.
Gap assessment

Where most programs actually stand

A HIPAA gap assessment checks Security Rule safeguards, Business Associate coverage, and breach-notification readiness against what OCR actually tests during an investigation. GRXForce's assessment gives you a preliminary exposure view in minutes.

Check My HIPAA Readiness
Evidence

What auditors actually expect to see

  • A current, dated Security Rule risk analysis with identified risks and mitigations
  • Executed Business Associate Agreements for every vendor handling PHI
  • Workforce training completion records, current year
  • Access control and audit logging evidence for systems storing or transmitting PHI
  • A rehearsed breach notification runbook with the HHS and individual timelines mapped
Common mistakes

Where programs like yours lose time

  • Treating a HIPAA risk analysis as a one-time exercise instead of a living document
  • Missing a Business Associate Agreement with a vendor that clearly touches PHI
  • Physical safeguards, workstation and device controls, getting far less attention than technical ones
  • Workforce training that happened once at hire and never again
  • No rehearsed path to the breach notification timeline, discovering the process during an actual incident
Compare frameworks

How HIPAA compares

FrameworkTypeTypical timelineRenewalBest for
ISO 27001:2022Certification6-12 months typical3-year cycle + annual surveillanceAny company selling globally, especially outside the US
SOC 2 Type IIAttestation (CPA report)3-12 month observation windowAnnual Type II reportSaaS companies selling to US enterprise customers
GDPRRegulationOngoing, no certificateContinuousAnyone processing EU residents' personal data
DPDPA 2023RegulationOngoing, no certificateContinuousAnyone processing Indian residents' digital personal data
HITRUST CSFCertification6-18 months by tier1-2 year cycle by tierHealthcare and health-tech handling PHI
NIST CSFVoluntary frameworkOngoing, self-assessedContinuousUS federal contractors and critical infrastructure
PCI DSSIndustry mandate3-6 months typicalAnnual (ROC or SAQ)Anyone storing, processing or transmitting card data
SOX ITGCRegulatory (internal controls)Ongoing, tested annuallyAnnual audit cycleUS public companies and their auditors
HIPAARegulationOngoing, no certificateContinuousUS healthcare providers, payers and business associates
Two ways to get there

Run it yourself, or hand us the programme

Run it yourself, the platform Controls pre-mapped to HIPAA, an AI Evidence Agent that discovers and reviews evidence and drafts the workpaper for every control, and a human sign-off trail your auditor can inspect line by line. Explore the platform →
Hand it over, managed services A named compliance lead runs your entire HIPAA programme: gap analysis, policies, evidence, auditor liaison, and surveillance after the milestone. Get it handled →

See exactly how GRXForce runs a HIPAA control test: the AI Evidence Agent discovers and reviews the evidence and drafts the workpaper, you make the final call.

See It Run in the Audit Engine →
FAQ

Frequently asked

Who counts as a Business Associate under HIPAA?

Any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity, cloud hosts, analytics tools, billing services. Each one needs a signed Business Associate Agreement before PHI ever reaches them.

Is HIPAA compliance the same as HITRUST certification?

No. HIPAA is law with no certificate; HITRUST is a certifiable framework that incorporates HIPAA's requirements. Many healthcare enterprises treat HITRUST certification as strong proof of HIPAA alignment.

What triggers a breach notification under HIPAA?

Any unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy, unless a risk assessment shows low probability of compromise. Notification timelines run to HHS and affected individuals, and to media for breaches affecting 500+ people in a jurisdiction.

Also covered: ISO 27001:2022 SOC 2 Type II GDPR DPDPA 2023 HITRUST CSF NIST CSF PCI DSS SOX ITGC

Find My Gaps

3 minutes. No sales pitch. Get a preliminary HIPAA readiness score.