Skip to main content
HIPAA Compliance

HIPAA Compliance Services — Security Rule & Privacy Rule Readiness

HIPAA is the US federal law governing the privacy and security of Protected Health Information (PHI), enforced by the HHS Office for Civil Rights. It applies to two categories of organisation — Covered Entities (healthcare providers, health plans, and healthcare clearinghouses) and Business Associates (any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf) — and is built around three core rules: the Privacy Rule governing use and disclosure of PHI, the Security Rule governing electronic PHI (ePHI) safeguards, and the Breach Notification Rule.

Mutex Systems runs HIPAA Security Rule risk assessments, Privacy Rule policy builds, and breach-notification readiness programmes for covered entities and business associates, including software vendors and telehealth platforms handling US patient data for the first time.

Category
Compliance Framework
Jurisdiction
United States
Issuing Body
US Department of Health & Human Services (HHS), Office for Civil Rights (OCR)
Current Version
HIPAA as amended by HITECH and the 2013 Omnibus Rule — HHS has proposed further updates to the Security Rule tightening encryption, MFA, and asset-inventory requirements
Who It's For
US healthcare providers, health plans, healthcare clearinghouses, and any business associate — including SaaS vendors, billing companies, and telehealth platforms — that creates, receives, stores, or transmits patient health information on a covered entity's behalf.
Read the official source
What It Covers

Core Domains

Administrative Safeguards — risk analysis, workforce training, access management, and a formal security management process
Physical Safeguards — facility access controls, workstation security, and device and media disposal
Technical Safeguards — access control, audit controls, integrity controls, and transmission security for ePHI
Privacy Rule — minimum necessary use, patient access rights, and permitted disclosures
Breach Notification Rule — timelines and content for notifying HHS, affected individuals, and in some cases the media
Business Associate Agreements (BAAs) — contractual flow-down of HIPAA obligations to vendors and subcontractors
How It Works

A Practical Compliance Path

  1. 01

    Security Risk Analysis

    The mandatory starting point under the Security Rule — a documented risk analysis identifying where ePHI lives, how it flows, and where the current safeguards fall short.

  2. 02

    Safeguard Remediation

    Close administrative, physical, and technical safeguard gaps identified in the risk analysis, with particular attention to access control, encryption, and audit logging for ePHI.

  3. 03

    Privacy Rule & BAA Build

    Build Privacy Rule policies, patient-rights procedures, and Business Associate Agreements covering every vendor with ePHI access.

  4. 04

    Breach Response Readiness

    Build and test the breach-notification procedure against the Breach Notification Rule's timelines, including the 60-day HHS reporting requirement for breaches affecting 500 or more individuals.

Our Approach

A Risk Analysis That Actually Holds Up to an OCR Investigation

HIPAA compliance work centres on a defensible, documented Security Rule risk analysis — the single most commonly cited gap in HHS OCR enforcement actions — rather than a policy-binder exercise that looks complete but was never tested against how ePHI actually flows through the business.

  • Security Risk Analysis scoped to how ePHI actually moves through your systems and vendors, not a generic template
  • Business Associate Agreement review and drafting for every vendor touching patient data
  • Breach-notification procedures tested against HIPAA's specific reporting timelines before they are ever needed for real
View Cybersecurity Services
Compliance, Continuously

The Security Risk Analysis, Kept Current Between Audits

grComply loads the HIPAA Security Rule's administrative, physical, and technical safeguards as a versioned control set, so the risk analysis HHS OCR expects to see stays a living record instead of a document frozen at the moment it was written.

  • Agent-based internal scanning evidences technical safeguards — access control, audit logging, encryption status — directly, rather than relying on a self-reported checklist
  • Business Associate tracking via the Dynamic Schema Engine keeps every vendor's BAA status, PHI-access scope, and last review date in one queryable record
  • The raise / respond / review / close workflow gives breach-notification response the same structured, timestamped audit trail an OCR investigation would expect to see
  • Cross-framework mapping reuses ePHI access-control and encryption evidence against overlapping SOC 2 or ISO 27001 controls where a business associate holds both

grComply is Mutex Systems' own multi-tenant GRC automation platform — the framework library, hybrid scanning, risk and audit workflow, and AI-assisted compliance behind every point above are live in production today.

See How grComply Works
FAQs

Common Questions About HIPAA

Is HIPAA a certification like ISO 27001?

No. There is no official "HIPAA certified" status issued by HHS or any government body — HIPAA compliance is a legal obligation assessed through risk analysis, policy documentation, and (if investigated) OCR enforcement review, not an accredited certification audit. Some organisations pursue a third-party framework such as HITRUST CSF, which does offer a formal certifiable assessment mapped to HIPAA requirements, as a way to demonstrate compliance to business partners.

What is the difference between a Covered Entity and a Business Associate?

A Covered Entity is a healthcare provider, health plan, or healthcare clearinghouse that directly handles patient health information as part of delivering care or coverage. A Business Associate is any vendor or contractor that creates, receives, maintains, or transmits PHI on a covered entity's behalf — software vendors, billing companies, cloud hosts, and telehealth platforms are common examples. Both are directly liable under HIPAA, and a Business Associate Agreement is required between them.

How quickly must a HIPAA breach be reported?

Breaches affecting 500 or more individuals must be reported to HHS and affected individuals without unreasonable delay and no later than 60 days after discovery, with media notification also required for breaches of that size within the same state or jurisdiction. Smaller breaches affecting fewer than 500 individuals must still be reported to HHS, but on an annual basis rather than immediately.

What triggers a HIPAA Security Risk Analysis requirement?

Any covered entity or business associate handling electronic PHI is required to conduct a Security Risk Analysis under the Security Rule — it is not optional and not triggered by an incident. It is consistently the single most cited deficiency in HHS OCR enforcement actions and settlements, making it the highest-priority starting point for any HIPAA compliance programme.

Can Mutex Systems support HIPAA compliance for a software vendor or telehealth platform?

Yes. Mutex Systems runs HIPAA Security Rule risk assessments, Business Associate Agreement review, Privacy Rule policy builds, and breach-notification readiness for covered entities and business associates, including software vendors and telehealth platforms handling US patient data.

Let's Talk

Ready to Start Your HIPAA Programme?

Send us your current posture and timeline. Within two working days you will receive a written response and a proposed scoping call.

No commitment requiredResponse within 2 working daysConfidential brief handling