Logo

Assuric

US Data Protection

HIPAA

Understand the Health Insurance Portability and Accountability Act (HIPAA) and how it affects your business

Framework

HIPAA
compliance

HIPAA is a US federal law to safeguard Protected Health Information (PHI), and is something every digital company needs to be away of if processing the data of US citizens

Request a demo

HIPAA

Health Insurance and Accountability Act (HIPAA)

70%71 tasks
Not started (16)
In progress (5)
Completed (50)

We are trusted by

  • Kanjo
  • Rosenfield
  • VitVio
  • Megi Your Health Assistant
  • Tandem
  • Chequp
  • Rhades
  • Joy
  • ONION AI
  • Heim
  • Think Divergent
  • Theta
  • Healthnix
  • Kanjo
  • Rosenfield
  • VitVio
  • Megi Your Health Assistant
  • Tandem
  • Chequp
  • Rhades
  • Joy
  • ONION AI
  • Heim
  • Think Divergent
  • Theta
  • Healthnix
Product

How Assuric can help

We can assist you with all aspects of HIPAA including:

Automated compliance tracking

Easily fill any gaps, automate tasks, track compliance, and receive proactive alerts - ensuring requirements are met in record time.

Automated compliance tracking

HIPAA Policies

Access our library of customisable templates, documents and procedures, including HIPAA Compliance Policies, HIPAA Breach Notification Procedures and more.

HIPAA Policies

Implement controls

Implement the necessary HIPAA security controls including encryption, back ups, access controls, screen locking and more.

Implement controls

Supplier Management

Automate supplier security assessments and due diligence processes, including implementation and tracking of Business Associate Agreements (BAAs).

Supplier Management

Asset Management

Identify and track information assets including company devices.

Asset Management

Risk Register

Develop actionable mitigation strategies and track the risk treatment process to maintain continuous compliance in line with HIPAA requirements.

Risk Register

Training and Staff Compliance

All the necessary staff training you’ll need, including HIPAA Security Awareness Training, combined with automated tracking and reminders to ensure compliance.

Training and Staff Compliance

Internal and external audits

Automate internal audits, sail through external audits, and obtain all necessary certifications in record time.

Internal and external audits

Map to other frameworks

Use intelligent automation and AI to avoid duplication of work, easily meeting UK Cyber Essentials, NHS DSPT and NHS DTAC requirements in tandem.

Map to other frameworks
FAQS

Frequently Asked Questions

Get in touch if we haven’t answered your question below, we are always happy to help!

What is HIPAA?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a U.S. federal law that sets national standards for protecting the privacy and security of US citizen medical information and for standardising electronic healthcare transactions. It created both Privacy and Security Rules that govern how “protected health information” (PHI) is used, disclosed, stored, and transmitted by healthcare organisations and their service providers.

Who does HIPAA apply to? What is a Covered Entity or Business Associate?

HIPAA directly governs Covered Entities - health plans, healthcare clearinghouses, and healthcare providers that transmit health data electronically. Business Associates are vendors (suppliers) or subcontractors that create, receive, maintain, or transmit PHI on behalf of a covered entity. Cloud providers, billing services, telehealth platforms and other digital health suppliers are common examples of Business Associates. This relationship is comparable to the GDPR Data Controller and Data Processor relationship.

What is PHI?

Protected Health Information (PHI) is any individually identifiable health data (past, present, or future) created, received, or maintained by a covered entity or business associate. This can be broad including items like medical records and lab results, but also appointment reminders, insurance IDs, biometric identifiers, and even device IDs when they can reasonably link back to a person’s health status.

What is a Business Associate Agreement (BAA) and when is one required?

A BAA is a legally binding contract that spells out each party’s HIPAA responsibilities and allocates liability for safeguarding PHI. Covered entities must execute a BAA before any PHI flows to a vendor or subcontractor. Without one, both organisations are non-compliant, even if no breach occurs. A BAA is comparable to a DPA (Data Processing Agreement).

What are the core HIPAA Rules that digital health teams need to address?

  • Privacy Rule - Governs how, when, and why protected health information (PHI) may be used or disclosed, enforces the “minimum-necessary” standard, and grants patients rights to access or amend their data.
  • Security Rule - Requires a risk-based implementation of administrative, physical, and technical safeguards - think policies, facility controls, encryption, access management, and audit logging-to protect electronic PHI (ePHI).
  • Breach Notification Rule - Mandates that business associates must notify the covered entity of a breach of PHI without unreasonable delay, and that the covered entity must alert the affected individuals and the HHS.

What security safeguards does the HIPAA Security Rule expect?

The Security Rule requires every covered entity or business associate to build a risk-based program that keeps electronic PHI confidential, intact, and available when needed. It groups safeguards into three mutually reinforcing layers:

  • Administrative - Perform and update a risk analysis, name a security officer, adopt policies, train staff, assess
  • Physical  - Restrict and monitor facility access, secure workstations, mobile devices and hardware, and control the handling, reuse, and disposal of servers or media.
  • Technical  - Enforce unique log-ins and least-privilege roles, audit and review logs, encrypt data in transit and at rest, verify data integrity, and auto-logoff idle sessions.

All controls must be documented, periodically tested, and adjusted as technology, threats, or the business change - HIPAA cares less about the specific tools you buy than about proving that the safeguards you chose are effective and continually improved.

If we host data with a recognised “HIPAA-eligible” cloud service like AWS or Azure, are we automatically compliant?

No. A compliant-ready infrastructure only solves a fraction of the obligations. You still need a signed BAA with the cloud provider and must configure services securely, control application-layer access, document policies, train staff, maintain audit trails, manage incident response, and monitor for new risks. HIPAA liability ultimately stays with the covered entity or business associate, not the cloud vendor.

Who enforces HIPAA?

U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy and Security Rules.

What are the penalties for non-compliance or a data breach?

The HHS Office for Civil Rights uses a four-tier civil penalty scale that currently ranges from about $137 to $68,000 per violation, with an annual cap of roughly $2 million per violation category. Uncorrected wilful neglect can escalate to criminal charges prosecuted by the Department of Justice, with fines up to $250,000 and prison terms of up to 10 years. Beyond government penalties, OCR routinely publishes settlement agreements that often reach seven or eight figures and require multi-year corrective-action plans, while organisations also shoulder breach-response costs, lawsuits, and reputational fallout.

Is there an official “HIPAA certification” to obtain?

HHS does not issue or recognise any formal certification. Independent auditors and third party organisations can perform external HIPAA audits and assessments, which can be advantageous but not an absolute requirement. Ultimately, compliance is demonstrated through continuous adherence to the rules and the ability to show evidence during an OCR investigation.

How does Assuric make HIPAA compliance easier?

Assuric centralises the entire HIPAA program in one workspace - mapping each HIPAA requirement to straight-forward tasks and controls, across multiple frameworks, along with automated evidence collection. Guided workflows walk teams through the necessary risk analyses, policy management, employee training, vendor/supplier assessments and BAAs, and much more.

testimonials

What our customers say

Compliance is complex, but our AI tools simplify it. Discover features to stay ahead of regulations.

Kelly Klifa
Heim

Kelly Klifa

CEO at Heim

Assuric has been transformative for Heim as we looked to achieve DCB0129 and DTAC compliance. The platform is easy to use, and the AI tools and automated reminders make previously dreaded compliance tasks a breeze. Paul and Matt supported us every step of the way.

Katie Baker
Tandem

Katie Baker

Director UK & Ireland at Tandem

Assuric has been fantastic in helping us quickly and safely navigate regulatory compliance in the UK. From completing Cybersecurity requirements to DSPT, DCB0129, and DTAC, the team was supportive, extremely knowledgeable, and the platform made everything quick and straightforward. A separate regulatory company we consulted at the beginning even remarked on how quickly we achieved compliance!

Maks Kozarzewski
VitVio

Maks Kozarzewski

COO at VitVio

We couldn't speak highly enough of both the Assuric team and the platform itself, which is incredibly easy to use, and with the skill and hardworking nature of the Assuric team. They've been a key component in accelerating our progress and deployments!

Maja Mazur
Healthnix

Maja Mazur

CEO at Healthnix

Assuric has been such a blessing in getting our DTAC and GDPR compliance done - completing all the documentation and deciding what needs to be done whilst running the business is very hard, but the team really helped us through that. The platform is easy to use, helps keep track of things and it even allows us to coordinate all the team training easily. Highly recommend them!

Dean Mawson
DPM

Dean Mawson

Clinical Director at DPM

Assuric streamlines the process of achieving and maintaining compliance with DCB0129 standards for digital health technologies. The user-friendly interface simplifies collaboration across multidisciplinary teams, while the built-in templates and workflows save significant time and effort during compliance projects. Assuric’s ability to centralise documentation and provide real-time visibility into project progress is particularly beneficial for Clinical Safety Officers and digital project teams, enhancing both efficiency and assurance.

Blog

Latest articles from the team

View all

Make your life easier
and talk to us to simplify compliance

Goodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.

CTA Image