Compliance Training

HIPAA Compliance: What It Actually Covers

HIPAA compliance is frequently reduced to a policy binder and a training video. The actual regulation centers on a risk analysis most companies never do properly.

Talk to a CISO

The business problem

Companies handling health information often assume HIPAA compliance means having a policy binder and running an annual training — while the regulation itself, enforced by HHS Office for Civil Rights, centers on a specific, documented risk analysis that identifies where protected health information (PHI) lives, what threatens it, and what’s being done about each risk. Skipping or superficially completing that analysis is one of the most commonly cited OCR enforcement findings.

Who HIPAA actually applies to

HIPAA applies to "covered entities" (health plans, healthcare providers, healthcare clearinghouses) and their "business associates" — vendors and partners who handle PHI on a covered entity’s behalf. A growing company that processes health data for a healthcare client, even without direct patient relationships, is very likely a business associate and subject to the same Security Rule requirements.

What the Security and Privacy Rules require

The Security Rule requires administrative, physical, and technical safeguards for electronic PHI — access controls, audit logging, encryption where reasonable and appropriate, and critically, a documented risk analysis identifying threats and vulnerabilities to PHI’s confidentiality, integrity, and availability. The Privacy Rule governs how PHI can be used and disclosed, separate from the security-specific requirements.

“OCR doesn’t primarily ask to see your policy binder. It asks to see your risk analysis — and whether what you actually did matches what it said you would.”

Signs HIPAA compliance is superficial

  • There’s no documented, specific risk analysis identifying where PHI is stored, processed, and transmitted
  • Policies exist but were copied from a template and never adapted to how the company actually operates
  • Business associate agreements are missing or unsigned for vendors that handle PHI
  • Access to PHI isn’t restricted to those with a genuine job-related need
  • The last risk analysis, if one exists, predates significant changes to systems or vendors

Practical guidance

Start with a real, documented risk analysis — not a generic template — that maps exactly where PHI lives across your systems and identifies specific threats and current safeguards for each. Keep business associate agreements current for every vendor touching PHI, and revisit the risk analysis whenever systems or vendors change materially, not just on a fixed annual schedule.

See the platform’s HIPAA readiness tracker, built around a real, documented risk analysis.

Explore the HIPAA Tracker
FAQ

Questions, answered directly.

Possibly yes — if you handle protected health information on behalf of a covered entity (a healthcare provider, health plan, or clearinghouse), you’re likely a "business associate" and subject to the same Security Rule requirements as the covered entity itself.

A documented assessment identifying where electronic protected health information is created, received, maintained, or transmitted, along with the threats, vulnerabilities, and current safeguards for each — it’s a specific, required deliverable, not a general statement that "we take security seriously."

There is no official HIPAA certification issued by HHS — organizations demonstrate compliance through their documented risk analysis, policies, and safeguards, which can be independently reviewed, but "certified" vendors offering a HIPAA seal aren’t conferring a government-recognized credential.

It’s a direct compliance gap and a common OCR enforcement finding — both the covered entity and the business associate can face liability if PHI is shared without a properly executed agreement defining each party’s obligations.

Want a HIPAA risk analysis that actually holds up to scrutiny?

30 minutes. No obligation. No sales pitch.

Talk to a CISO