i-Prot

Frameworks · HIPAA (Security & Privacy Rules)

HIPAA: protect health information and demonstrate compliance.

We prepare and support you in complying with HIPAA — with safeguards over protected health information (PHI) and evidence ready.

diagram · frameworks · hipaa (security & privacy rules)

Who it applies to

HIPAA applies to U.S. healthcare entities and their business associates that handle protected health information (PHI).

What the framework requires

HIPAA isn’t certified: it’s a regulation that requires administrative, physical and technical safeguards over PHI, plus privacy, security and breach-notification rules.

Privacy Rule

Permitted use and disclosure of PHI.

Security Rule

Administrative, physical and technical safeguards.

Breach notification

The obligation to report incidents involving PHI.

Business associates

Agreements and oversight of third parties that process PHI.

Risks of not acting

  • Regulatory sanctions for improper handling of PHI.
  • Exposure of highly sensitive health data.
  • Being unable to operate with U.S. healthcare customers.
  • Third parties (business associates) with no oversight or agreements.

The i-Prot proposal

We assess how PHI is handled, implement the administrative, physical and technical safeguards, and leave the evidence ready to demonstrate HIPAA compliance. Integrated into the CGF cycle.

How we work with this framework

PHI assessment

Where health information lives and how it’s handled.

Gap analysis

State against the HIPAA rules.

Safeguards

Administrative, physical and technical controls.

Agreements and third parties

Business associate agreements and oversight.

Evidence and upkeep

Compliance evidence and improvement.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses HIPAA as a source of requirements. This framework mainly covers the Assess, Design, Implement and Improve stages of the cycle.

See the CGF methodology →

Complyze and HIPAA

Complyze centralizes the safeguards, the third-party agreements and the HIPAA compliance evidence, with traceability.

Frequently asked questions

Do you need to comply with HIPAA?

Tell us how you handle health information and we’ll define the approach.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.