HIPAA, without the spreadsheets.
Protect health data and prove it to US healthcare customers.
What is HIPAA?
HIPAA sets the rules for protecting electronic protected health information (ePHI) in the United States. The Security Rule requires administrative, physical and technical safeguards; covered entities and the business associates who handle ePHI for them are both liable.
Who needs it
- Health tech companies processing ePHI
- SaaS vendors signing Business Associate Agreements with US providers or insurers
- Teams selling into US healthcare whose customers audit their vendors
What HIPAA looks at
Risk analysis
An accurate, documented assessment of risks to the confidentiality, integrity and availability of ePHI.
Access and audit controls
Unique user IDs, automatic logoff, encryption and logs of who accessed ePHI.
Workforce training
Security awareness training and sanctions for workforce members who break policy.
Business associate agreements
Written assurances from every vendor that creates, receives or stores ePHI on your behalf.
How Beviso gets you there
- Security Rule safeguards pre-loaded with evidence from identity, endpoint and logging tools
- BAA tracking in the vendor register
- Training evidence from your security awareness platform
- Breach workflow that tracks the 60-day notification deadline
11 HIPAA controls, ready on day one
These controls are loaded when you enable HIPAA, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
164.312.a.1
Access Control
Implement technical policies and procedures to allow access only to authorized persons.
Evidence from
- Okta
- AWS
- Microsoft Azure
- Google Workspace
- JumpCloud
- HashiCorp Vault
164.312.a.2.i
Unique User Identification
Assign a unique name/number for identifying and tracking user identity.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- GitHub
- AWS
164.312.a.2.ii
Emergency Access Procedure
Establish and implement as needed procedures for obtaining necessary ePHI during an emergency.
Evidence from
- PagerDuty
- ServiceNow
- HashiCorp Vault
164.312.a.2.iv
Encryption and Decryption
Implement a mechanism to encrypt and decrypt electronic protected health information.
Evidence from
- HashiCorp Vault
- Doppler
- Bitwarden
- 1Password
- AWS
164.312.b
Audit Controls
Implement hardware, software, and/or procedural mechanisms to record and examine activity in information systems.
Evidence from
- Datadog
- AWS
- Okta
- Splunk
- HashiCorp Vault
- Salesforce
- Bitwarden
- 1Password
164.312.c.1
Integrity Controls
Implement policies and procedures to protect electronic PHI from improper alteration or destruction.
Evidence from
- GitHub
- GitLab
- AWS
- HashiCorp Vault
164.312.d
Person or Entity Authentication
Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.
Evidence from
- Okta
- Duo
- Microsoft Azure
- Google Workspace
- 1Password
164.312.e.1
Transmission Security
Implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic networks.
Evidence from
- Cloudflare
- HashiCorp Vault
- AWS
164.308.a.1
Security Management Process
Implement policies and procedures to prevent, detect, contain, and correct security violations.
Evidence from
- CrowdStrike
- SentinelOne
- Wiz
- Snyk
- Rapid7
164.308.a.5
Security Awareness Training
Implement a security awareness and training program for all members of the workforce.
Evidence from
- KnowBe4
164.308.a.6
Security Incident Procedures
Implement policies and procedures to address security incidents, including reporting and response.
Evidence from
- PagerDuty
- ServiceNow
- Jira
- CrowdStrike
HIPAA questions
- Is there a HIPAA certification?
- No official one exists. Customers usually ask for evidence of your safeguards, a signed BAA and often a SOC 2 report. Beviso maps shared controls between HIPAA and SOC 2.
- Does HIPAA apply to a European company?
- It applies when you are a business associate of a US covered entity, wherever you are based.
Often run alongside HIPAA
SOC 2
Give US customers the SOC 2 report their procurement team asks for.
ISO 27001
Build an information security management system an auditor will certify.
NIST CSF 2.0
Measure and improve your security programme against a common language.
GDPR
Show, not just claim, that personal data is handled lawfully.
Start your HIPAA programme today.
Free while Beviso is in beta. No credit card required.
Get started free