So HIPAA is on your plate — here's where to start
Legal, Sales, or Product forwarded a thread with HIPAA in it. Maybe you're integrating with a health system. Maybe you store something that looks like PHI. Maybe a BAA showed up in DocuSign. You're the CIO/CISO, and "figure it out" landed on your calendar.
This guide is for that Monday morning. It will not recite the Security Rule section-by-section — that would be irresponsible from a blog. It will help you ask the right questions and start orderly.
Important: HIPAA compliance is legal + operational. Involve counsel. BreachBits does not "HIPAA certify" you; we can support technical evidence and testing mapped to control frameworks — your obligations and any OCR scrutiny are separate.
Core concepts (read this first)
HIPAA (Health Insurance Portability and Accountability Act) is U.S. federal law. For security leaders, the pieces you hear about most are:
- Privacy Rule — when and how PHI may be used/disclosed
- Security Rule — administrative, physical, and technical safeguards for electronic PHI (ePHI)
- Breach Notification Rule — what happens if PHI is compromised
There is no official "HIPAA certification" you buy that makes you done. Customers often want a Business Associate Agreement (BAA) plus proof you run a serious security program. OCR (HHS's Office for Civil Rights) enforces; that is not the same mechanic as a SOC 2 report from a CPA.
Covered entity vs business associate (learn this on day one):
- Covered entity (CE) — generally health plans, most health care providers who conduct certain electronic transactions, and health care clearinghouses
- Business associate (BA) — a vendor/partner that creates, receives, maintains, or transmits PHI for a covered entity (many SaaS/health-tech companies land here)
Your counsel confirms which you are. Guessing wrong breaks contracts.
PHI is protected health information — individually identifiable health information in the HIPAA sense. If you're unsure whether a data element is PHI, treat that as a counsel question, not a Slack poll.
BAA — the contract that sets BA obligations when PHI flows. Sales should not sign BAAs your controls can't support.
Ongoing, not annual-trophy. HIPAA duties continue as long as you handle PHI. Product changes, new vendors, and new log pipelines can create new exposure overnight.
What the mandate often means
Someone believes your organization creates, receives, maintains, or transmits PHI in a way that triggers HIPAA expectations — often as a business associate to a covered entity, sometimes as a covered entity yourself.
Clarify these before you build a program deck
- Are we a covered entity, a business associate, or neither? Counsel should confirm — this changes contracts and duties.
- What data do we actually touch? List systems and data elements; "we might see PHI in support tickets" counts.
- Who is requiring this? Customer BAA, investor, internal caution, state overlay — keep the trigger document.
- What contracts are already signed? BAAs, DPAs, customer security exhibits — inventory them.
- Where does PHI live — and where must it never live? Prod, logs, analytics, backups, vendors, laptops, screenshots in Slack.
If you can't inventory PHI touchpoints, you're not ready to claim a posture.
Who you'll need in the room
- Counsel (healthcare-savvy if possible)
- Security / IT / Eng owners for systems that may hold PHI
- Privacy / compliance owner if you have one (or assign one)
- Vendor management for subprocessors who might see PHI
- Executive sponsor — HIPAA is not an IT-only hobby
External assessors or specialized consultants are optional depending on your risk and customer demands — counsel can advise when a formal assessment is warranted. Don't invent a certification product that HIPAA doesn't work like SOC 2.
What the journey usually feels like
There isn't a single "HIPAA certificate" you hang on the wall the way people talk about SOC 2 reports. Customers often want BAAs + demonstrable security practice + evidence. Exact expectations vary — ask the customer what artifact satisfies them.
A sane internal sequence:
- Determine role & PHI map
- Contractual baseline — BAAs and customer terms you can actually meet
- Gap look across admin / physical / technical safeguards as they apply to you (with counsel/SMEs — not from memory of a Twitter thread)
- Remediate & operate — access, encryption, logging, incident response, vendor oversight, workforce training — whatever your gap look prioritized
- Evidence pack for customers and for your own incident readiness
- Ongoing — HIPAA is continuous obligation; revisit when products or vendors change
Evidence categories customers often ask for
Without listing fake controls:
- Policies and procedures that match operations
- Access and authentication evidence for systems with PHI
- Vendor / subprocessor lists and how you oversee them
- Incident response plans and any tabletop or ticket history you can share appropriately
- Technical testing outputs — vulnerability/pen-test style evidence for systems in play
Share under NDA; don't over-disclose patient data in the evidence pack.
Common surprises
- PHI in "harmless" places — logs, error trackers, CRM notes, screenshots
- Support and success teams who can see production data without the same controls Eng has
- Subprocessors added by product for AI/analytics without a BAA path
- Sales signing BAAs your controls can't support yet
First 30 days — starter checklist
- Meeting with counsel: role (CE/BA/other) + what the customer ask legally means
- PHI data-flow sketch across apps, logs, vendors, backups
- Inventory executed BAAs and security exhibits
- Name privacy/security owners for each PHI-touching system
- Freeze new PHI use cases until the map exists
- Ask the requesting customer what evidence they expect (don't guess)
- List subprocessors; flag any missing contractual coverage for counsel
Where continuous testing helps (lightly)
Customers increasingly want proof that systems handling sensitive data aren't casually exposed on the internet. Continuous outside-in discovery and verification — plus reports that can map into compliance-oriented control language — helps you show technical diligence.
It does not replace counsel, a BAA strategy, or OCR-facing judgment.
When you're ready for that technical layer beside the legal work, see Compliance or book a demo.
Authoritative sources
- HHS — HIPAA for professionals — starting hub
- HHS — Privacy Rule
- HHS — Security Rule
- HHS — Breach Notification Rule
- HHS — Business Associates — CE vs BA orientation
- OCR — Enforcement / complaint process — who enforces
- Your healthcare counsel and the customer BAA / security exhibit — the contract still defines what you promised