HIPAA Compliance Services — Security Rule & Privacy Rule Readiness
HIPAA is the US federal law governing the privacy and security of Protected Health Information (PHI), enforced by the HHS Office for Civil Rights. It applies to two categories of organisation — Covered Entities (healthcare providers, health plans, and healthcare clearinghouses) and Business Associates (any vendor that creates, receives, maintains, or transmits PHI on a covered entity's behalf) — and is built around three core rules: the Privacy Rule governing use and disclosure of PHI, the Security Rule governing electronic PHI (ePHI) safeguards, and the Breach Notification Rule.
Mutex Systems runs HIPAA Security Rule risk assessments, Privacy Rule policy builds, and breach-notification readiness programmes for covered entities and business associates, including software vendors and telehealth platforms handling US patient data for the first time.
- Category
- Compliance Framework
- Jurisdiction
- United States
- Issuing Body
- US Department of Health & Human Services (HHS), Office for Civil Rights (OCR)
- Current Version
- HIPAA as amended by HITECH and the 2013 Omnibus Rule — HHS has proposed further updates to the Security Rule tightening encryption, MFA, and asset-inventory requirements
- Who It's For
- US healthcare providers, health plans, healthcare clearinghouses, and any business associate — including SaaS vendors, billing companies, and telehealth platforms — that creates, receives, stores, or transmits patient health information on a covered entity's behalf.
Core Domains
A Practical Compliance Path
- 01
Security Risk Analysis
The mandatory starting point under the Security Rule — a documented risk analysis identifying where ePHI lives, how it flows, and where the current safeguards fall short.
- 02
Safeguard Remediation
Close administrative, physical, and technical safeguard gaps identified in the risk analysis, with particular attention to access control, encryption, and audit logging for ePHI.
- 03
Privacy Rule & BAA Build
Build Privacy Rule policies, patient-rights procedures, and Business Associate Agreements covering every vendor with ePHI access.
- 04
Breach Response Readiness
Build and test the breach-notification procedure against the Breach Notification Rule's timelines, including the 60-day HHS reporting requirement for breaches affecting 500 or more individuals.
A Risk Analysis That Actually Holds Up to an OCR Investigation
HIPAA compliance work centres on a defensible, documented Security Rule risk analysis — the single most commonly cited gap in HHS OCR enforcement actions — rather than a policy-binder exercise that looks complete but was never tested against how ePHI actually flows through the business.
- Security Risk Analysis scoped to how ePHI actually moves through your systems and vendors, not a generic template
- Business Associate Agreement review and drafting for every vendor touching patient data
- Breach-notification procedures tested against HIPAA's specific reporting timelines before they are ever needed for real
The Security Risk Analysis, Kept Current Between Audits
grComply loads the HIPAA Security Rule's administrative, physical, and technical safeguards as a versioned control set, so the risk analysis HHS OCR expects to see stays a living record instead of a document frozen at the moment it was written.
- Agent-based internal scanning evidences technical safeguards — access control, audit logging, encryption status — directly, rather than relying on a self-reported checklist
- Business Associate tracking via the Dynamic Schema Engine keeps every vendor's BAA status, PHI-access scope, and last review date in one queryable record
- The raise / respond / review / close workflow gives breach-notification response the same structured, timestamped audit trail an OCR investigation would expect to see
- Cross-framework mapping reuses ePHI access-control and encryption evidence against overlapping SOC 2 or ISO 27001 controls where a business associate holds both
grComply is Mutex Systems' own multi-tenant GRC automation platform — the framework library, hybrid scanning, risk and audit workflow, and AI-assisted compliance behind every point above are live in production today.
See How grComply WorksCommon Questions About HIPAA
Is HIPAA a certification like ISO 27001?
No. There is no official "HIPAA certified" status issued by HHS or any government body — HIPAA compliance is a legal obligation assessed through risk analysis, policy documentation, and (if investigated) OCR enforcement review, not an accredited certification audit. Some organisations pursue a third-party framework such as HITRUST CSF, which does offer a formal certifiable assessment mapped to HIPAA requirements, as a way to demonstrate compliance to business partners.
What is the difference between a Covered Entity and a Business Associate?
A Covered Entity is a healthcare provider, health plan, or healthcare clearinghouse that directly handles patient health information as part of delivering care or coverage. A Business Associate is any vendor or contractor that creates, receives, maintains, or transmits PHI on a covered entity's behalf — software vendors, billing companies, cloud hosts, and telehealth platforms are common examples. Both are directly liable under HIPAA, and a Business Associate Agreement is required between them.
How quickly must a HIPAA breach be reported?
Breaches affecting 500 or more individuals must be reported to HHS and affected individuals without unreasonable delay and no later than 60 days after discovery, with media notification also required for breaches of that size within the same state or jurisdiction. Smaller breaches affecting fewer than 500 individuals must still be reported to HHS, but on an annual basis rather than immediately.
What triggers a HIPAA Security Risk Analysis requirement?
Any covered entity or business associate handling electronic PHI is required to conduct a Security Risk Analysis under the Security Rule — it is not optional and not triggered by an incident. It is consistently the single most cited deficiency in HHS OCR enforcement actions and settlements, making it the highest-priority starting point for any HIPAA compliance programme.
Can Mutex Systems support HIPAA compliance for a software vendor or telehealth platform?
Yes. Mutex Systems runs HIPAA Security Rule risk assessments, Business Associate Agreement review, Privacy Rule policy builds, and breach-notification readiness for covered entities and business associates, including software vendors and telehealth platforms handling US patient data.
Ready to Start Your HIPAA Programme?
Send us your current posture and timeline. Within two working days you will receive a written response and a proposed scoping call.