Frameworks · HIPAA (Security & Privacy Rules)
HIPAA: protect health information and demonstrate compliance.
We prepare and support you in complying with HIPAA — with safeguards over protected health information (PHI) and evidence ready.
Who it applies to
HIPAA applies to U.S. healthcare entities and their business associates that handle protected health information (PHI).
What the framework requires
HIPAA isn’t certified: it’s a regulation that requires administrative, physical and technical safeguards over PHI, plus privacy, security and breach-notification rules.
Privacy Rule
Security Rule
Breach notification
Business associates
Risks of not acting
- Regulatory sanctions for improper handling of PHI.
- Exposure of highly sensitive health data.
- Being unable to operate with U.S. healthcare customers.
- Third parties (business associates) with no oversight or agreements.
The i-Prot proposal
We assess how PHI is handled, implement the administrative, physical and technical safeguards, and leave the evidence ready to demonstrate HIPAA compliance. Integrated into the CGF cycle.
How we work with this framework
PHI assessment
Gap analysis
Safeguards
Agreements and third parties
Evidence and upkeep
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses HIPAA as a source of requirements. This framework mainly covers the Assess, Design, Implement and Improve stages of the cycle.
See the CGF methodology →
Complyze and HIPAA
Complyze centralizes the safeguards, the third-party agreements and the HIPAA compliance evidence, with traceability.
Frequently asked questions
Do you need to comply with HIPAA?
Tell us how you handle health information and we’ll define the approach.
By submitting you accept our privacy policy.