AccuSights
PartnersBlogAbout
Book my 30-minute demo

Healthcare · HHS Office for Civil Rights

HIPAA Security, Privacy and Breach Notification Rules

A documented, accurate risk analysis is the first thing OCR asks for after a breach. Keep it current every day.

One control set, every frameworkPractitioner-led, CRISC and CISAPublic pricing

Who it applies to

The businesses that carry HIPAA, and the pages written for them.

Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.

Which packages satisfy it

Practice Cybersecurity, Data Protection and HIPAA Package

Medical and dental practices, clinics, surgery centers, hospital departments and the business associates that serve them

Fixed feescoped in 30 minutes
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

Organizations within 90 days of a SOC 2 audit, an OCR inquiry or a C3PAO assessment, and any leadership team that wants to know before it counts

Fixed feescoped in 30 minutes
Details →

What it asks for

In plain English, what HIPAA expects you to have in place.

  • A documented risk analysisAccurate and thorough, covering every system that holds ePHI, and kept current. It is the first document an investigator asks for.
  • Administrative safeguardsA named security official, workforce training, sanction policy, access management and business associate agreements.
  • Physical safeguardsFacility access, workstation use and device and media controls, including disposal.
  • Technical safeguardsUnique user identification, access control, audit controls, integrity controls, transmission security and encryption where reasonable and appropriate.
  • Breach notificationDetect, assess, and notify individuals, HHS and where required the media, within the windows the rule sets.
  • Privacy Rule dutiesA notice of privacy practices, minimum necessary use, and a process for patient rights requests.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

Or start with the 3-minute test

Questions we get about HIPAA

Do you certify HIPAA compliance?
No. HHS Office for Civil Rights and the auditors or assessors it recognizes have the final say. We interpret the requirements for your business, scope what applies, close the gaps and keep the evidence current so the assessment or examination is a formality.
Where do we start with HIPAA?
With the 3-minute Cyber Hygiene Test if you want a number today, or with the 30-minute call if you want a written scope and a fixed fee. Either way the first deliverable is a gap list ranked by what would fail and what would hurt.
We also need other frameworks. Do we do HIPAA separately?
No. We build one control set and map it to every framework you carry, so evidence is produced once and reused. Adding a framework later is a mapping exercise, not a second program.

Next step

Thirty minutes, an engineer, a written scope for HIPAA.

Book the demo and see how one control set carries HIPAA and everything else you owe. Or leave your details and an engineer replies within one business day.

3-min test