Compliance · US regulation

HIPAA — safeguards for protected health information

There's no such thing as a HIPAA certificate — there is a required risk analysis.

HIPAA governs how covered entities and business associates protect protected health information. It is a US law enforced by HHS OCR, not a certification scheme — and its Security Rule has one requirement organizations fail more than any other: an accurate, thorough risk analysis.

3

Core rules

Required

Risk analysis

BAA

Contract control

What HIPAA requires

Three rules, and a set of safeguards that are deliberately technology-neutral.

Privacy, Security, Breach rules

The Privacy Rule governs use and disclosure of PHI, the Security Rule governs safeguards for electronic PHI, and the Breach Notification Rule governs what happens when it goes wrong.

Three safeguard families

Administrative (risk analysis, workforce training, sanctions), Physical (facility and device controls), and Technical (access control, audit controls, integrity, transmission security).

Required vs. addressable

'Addressable' does not mean optional. It means implement it, or document why an alternative is reasonable. Treating addressable as ignorable is a common and expensive misreading.

Who HIPAA applies to

Covered entities, and everyone handling PHI on their behalf.

  • Providers, health plans, and clearinghouses (covered entities)
  • SaaS, hosting, and IT vendors touching PHI (business associates)
  • Billing, transcription, and analytics companies
  • Subcontractors of business associates — HIPAA flows downhill

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Security Rule risk analysis

We perform the accurate, thorough risk analysis the rule requires — the single most cited failure in OCR enforcement.

Safeguard implementation

We close administrative, physical, and technical gaps, and document addressable decisions defensibly.

PHI mapping

We find where ePHI actually lives — including the shadow copies in inboxes, laptops, and test environments.

BAA governance

We get business associate agreements in place and flowing down to subcontractors.

Breach readiness

We build the detection, assessment, and notification process before you need it.

Workforce & evidence

We handle training, sanctions policy, and the documentation OCR asks for first.

How the engagement runs

1

Map ePHI

Find where protected health information lives and moves.

2

Risk analysis

Run the required analysis and produce a risk management plan.

3

Remediate

Implement safeguards and document addressable decisions.

4

Contract

Put BAAs in place across the chain.

5

Sustain

Train, monitor, review, and keep evidence current.

Frequently asked questions

Can we become 'HIPAA certified'?

No. HHS does not certify or endorse any HIPAA certification, and no vendor can make you officially certified. Third-party attestations of HIPAA alignment exist and have value in sales conversations, but compliance is demonstrated through your risk analysis, safeguards, and documentation — not a badge.

What does OCR actually cite most often?

Failure to conduct an accurate and thorough risk analysis, over and over. It's the foundation the entire Security Rule builds on, and it's the first document requested in an investigation. If yours is stale or superficial, everything after it is exposed.

Are we a business associate?

If you create, receive, maintain, or transmit PHI on behalf of a covered entity, yes — and that includes most SaaS and IT vendors serving healthcare, even if you never intentionally look at the data. Encryption doesn't exempt you, and neither does 'we just host it'.

How does HIPAA relate to HITRUST?

HIPAA tells you what to achieve but not how; HITRUST CSF gives you a prescriptive, certifiable control set that maps to HIPAA. Many healthcare organizations require HITRUST from vendors precisely because HIPAA itself has no certification. If your customers are pressing for proof, HITRUST is usually the answer.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

HIPAA for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.