Regulation · US

HIPAA, without the spreadsheets.

Protect health data and prove it to US healthcare customers.

What is HIPAA?

HIPAA sets the rules for protecting electronic protected health information (ePHI) in the United States. The Security Rule requires administrative, physical and technical safeguards; covered entities and the business associates who handle ePHI for them are both liable.

Who needs it

  • Health tech companies processing ePHI
  • SaaS vendors signing Business Associate Agreements with US providers or insurers
  • Teams selling into US healthcare whose customers audit their vendors

What HIPAA looks at

Risk analysis

An accurate, documented assessment of risks to the confidentiality, integrity and availability of ePHI.

Access and audit controls

Unique user IDs, automatic logoff, encryption and logs of who accessed ePHI.

Workforce training

Security awareness training and sanctions for workforce members who break policy.

Business associate agreements

Written assurances from every vendor that creates, receives or stores ePHI on your behalf.

How Beviso gets you there

  • Security Rule safeguards pre-loaded with evidence from identity, endpoint and logging tools
  • BAA tracking in the vendor register
  • Training evidence from your security awareness platform
  • Breach workflow that tracks the 60-day notification deadline

11 HIPAA controls, ready on day one

These controls are loaded when you enable HIPAA, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

164.312.a.1

Access Control

Implement technical policies and procedures to allow access only to authorized persons.

Evidence from

  • Okta
  • AWS
  • Microsoft Azure
  • Google Workspace
  • JumpCloud
  • HashiCorp Vault

164.312.a.2.i

Unique User Identification

Assign a unique name/number for identifying and tracking user identity.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • GitHub
  • AWS

164.312.a.2.ii

Emergency Access Procedure

Establish and implement as needed procedures for obtaining necessary ePHI during an emergency.

Evidence from

  • PagerDuty
  • ServiceNow
  • HashiCorp Vault

164.312.a.2.iv

Encryption and Decryption

Implement a mechanism to encrypt and decrypt electronic protected health information.

Evidence from

  • HashiCorp Vault
  • Doppler
  • Bitwarden
  • 1Password
  • AWS

164.312.b

Audit Controls

Implement hardware, software, and/or procedural mechanisms to record and examine activity in information systems.

Evidence from

  • Datadog
  • AWS
  • Okta
  • Splunk
  • HashiCorp Vault
  • Salesforce
  • Bitwarden
  • 1Password

164.312.c.1

Integrity Controls

Implement policies and procedures to protect electronic PHI from improper alteration or destruction.

Evidence from

  • GitHub
  • GitLab
  • AWS
  • HashiCorp Vault

164.312.d

Person or Entity Authentication

Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • Google Workspace
  • 1Password

164.312.e.1

Transmission Security

Implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic networks.

Evidence from

  • Cloudflare
  • HashiCorp Vault
  • AWS

164.308.a.1

Security Management Process

Implement policies and procedures to prevent, detect, contain, and correct security violations.

Evidence from

  • CrowdStrike
  • SentinelOne
  • Wiz
  • Snyk
  • Rapid7

164.308.a.5

Security Awareness Training

Implement a security awareness and training program for all members of the workforce.

Evidence from

  • KnowBe4

164.308.a.6

Security Incident Procedures

Implement policies and procedures to address security incidents, including reporting and response.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira
  • CrowdStrike

HIPAA questions

Is there a HIPAA certification?
No official one exists. Customers usually ask for evidence of your safeguards, a signed BAA and often a SOC 2 report. Beviso maps shared controls between HIPAA and SOC 2.
Does HIPAA apply to a European company?
It applies when you are a business associate of a US covered entity, wherever you are based.

Start your HIPAA programme today.

Free while Beviso is in beta. No credit card required.

Get started free