HIPAA Security & Privacy Readiness
HIPAA governs how US protected health information is kept private and secure — and it reaches every organization that touches that data, including offshore teams. We deliver the Security Risk Analysis HIPAA requires, close the gaps against its Administrative, Physical and Technical safeguards, and validate your technical controls the way an attacker would — so your compliance is demonstrable, not just documented.
There is no official HIPAA certificate — there is defensible, evidence-backed readiness. CERT-In Empaneled. We test the safeguards we assess.
One law, three rules, one obligation: protect the patient's data
HIPAA — the US Health Insurance Portability and Accountability Act — sets the federal standard for protecting health information in the United States.
Its requirements live in the federal regulations at 45 CFR Parts 160, 162 and 164, and three rules do the heavy lifting. The Privacy Rule governs how protected health information (PHI) — health data tied to an identifiable person, in any form — may be used and disclosed. The Security Rule sets the safeguards that protect that information when it is held or transmitted electronically (ePHI), built around three families of controls: Administrative, Physical and Technical. The Breach Notification Rule dictates what must happen when unsecured PHI is exposed — who must be told, and how quickly. Enforcement sits with the US Department of Health and Human Services, through its Office for Civil Rights (OCR).
What HIPAA does not have is a certificate. No government body, and no auditor, issues an official "HIPAA certification." Anyone who claims to make you "HIPAA certified" is selling a badge that does not exist. What you can — and should — have is a current, documented Security Risk Analysis, safeguards that genuinely meet the rule, Business Associate Agreements in place, and the evidence to demonstrate all of it to OCR if asked. That is what we build.
"There is no HIPAA certificate to hang on the wall. There is only the question OCR actually asks after an incident: can you show that your safeguards were real? We make sure the answer is yes."
Who HIPAA reaches — including teams outside the US
HIPAA's obligations flow down a chain. They begin with Covered Entities and extend, by contract, to every Business Associate that handles protected health information on their behalf — wherever that work is performed.
Covered Entities
Health plans, healthcare clearinghouses and healthcare providers that transmit health information electronically. They hold the primary obligation under all three Rules.
Business Associates
Any organization that creates, receives, maintains or transmits PHI to perform a function for a Covered Entity — billing, analytics, cloud hosting, IT services, support. Business Associates are directly liable under the Security Rule and parts of the Privacy and Breach Notification Rules.
Indian healthcare IT, BPO & SaaS
Offshore teams in medical billing, coding, RCM, transcription, telehealth, clinical analytics and healthcare SaaS are Business Associates the moment they touch US PHI. HIPAA follows the data across the border — your distance from the US doesn't dilute the obligation.
Subcontractors (downstream BAs)
A Business Associate's own vendors that handle PHI are themselves Business Associates, bound by the same safeguards through a downstream Business Associate Agreement.
The BAA chain
A Covered Entity may share PHI with a Business Associate only after obtaining satisfactory written assurances — the Business Associate Agreement — and that requirement flows all the way down the chain. No BAA, no lawful flow of PHI.
Wherever you sit on the chain, the safeguards are the same family of controls — calibrated to the data you hold and the role you play.
What the Security Rule actually asks for
The Security Rule (45 CFR Part 164, Subpart C) protects electronic PHI through three safeguard families — Administrative, Physical and Technical — supported by Organizational requirements (chiefly Business Associate contracts) and Policies, Procedures & Documentation.
Each family contains standards, and many standards carry implementation specifications marked Required or Addressable — "addressable" does not mean optional; it means you implement it, or document a reasoned, equivalent alternative. At the centre of it all is one Required specification that drives everything else: the Security Risk Analysis.
Administrative safeguards (164.308) — The governance layer: the Security Management Process — anchored by the Required Risk Analysis and Risk Management — plus assigned security responsibility, workforce security, access management, training, security-incident procedures, contingency planning and Business Associate contracts.
Physical safeguards (164.310) — Protecting the facilities, devices and media that hold ePHI: facility access controls, workstation use and security, and device and media controls.
Technical safeguards (164.312) — The controls an attacker meets first: access control, audit controls, integrity, person-or-entity authentication and transmission security — the ones we don't just review, we test.
Two more rules wrap the Security Rule. The Privacy Rule (Subpart E) governs permitted uses and disclosures of PHI and requires Business Associate Agreements before PHI may be shared. The Breach Notification Rule (Subpart D) sets the clock when unsecured PHI is exposed: notify affected individuals and HHS without unreasonable delay and no later than 60 calendar days after discovery — and where a breach affects 500 or more residents of a state or jurisdiction, notify prominent media and HHS contemporaneously.
From data flows to demonstrable readiness
HIPAA compliance is not a one-time project; it is a risk-management cycle the Security Rule expects you to run and keep current.
Our approach mirrors that cycle: we map where PHI actually lives and moves, run the Security Risk Analysis the rule requires, manage the gaps down, remediate the safeguards, prove the technical ones work, put the policies, agreements and training in place, ready you for a breach you hope never comes — and help you sustain all of it.
FIG. 02 — HIPAA risk-analysis & readiness lifecycle · 02 the Required keystone · 05 the offensive-edge differentiator
The Security Rule treats security as an ongoing process, not a finish line — and the proposed 2025 update would tighten that expectation further. We build the cycle so it keeps proving itself, not just clears one review.
What an engagement includes
We scope to your role — Covered Entity, Business Associate or offshore Business Associate — and cover the work end to end.
PHI / ePHI discovery and data-flow mapping across applications, infrastructure, endpoints and third parties
Definition of the HIPAA boundary
systems, sites, functions and offshore locations in scope
Role determination
Covered Entity, Business Associate or subcontractor, and the obligations that follow
The Security Risk Analysis required by 164.308(a)(1)
confidentiality, integrity and availability of ePHI
Gap assessment against the Privacy, Security and Breach Notification Rules
Risk register and prioritized risk-management plan
Safeguard remediation support across Administrative, Physical and Technical families
Control design and configuration guidance for access control, encryption, logging and authentication
A prioritized remediation roadmap with clear ownership and sequencing
Technical control validation
penetration testing and configuration review that proves the Technical safeguards actually work
Evidence collection and an audit-ready artifact pack mapped to the safeguard families
Remediation retest after fixes
Policy and procedure suite aligned to the Security and Privacy Rules
Business Associate Agreement review and remediation, up and down the chain
Workforce security-awareness training aligned to the Administrative safeguards
Incident-response and breach-notification playbook tested against the 60-day clock
Periodic re-analysis cadence and post-change reassessment
Continuous evidence management to stay audit-ready
Readiness guidance for the proposed 2025 Security Rule update as it develops
We audit like we attack
The Security Rule's Technical safeguards are not policy statements — they are controls that either hold or don't. A paper review confirms they're written down. We confirm they work.
Most HIPAA work stops at the document
The conventional path to HIPAA readiness reviews policies, samples evidence and checks that an access-control or encryption policy exists. That satisfies the documentation — but a written access-control policy and an access-control system an attacker can walk through are not the same thing. The Security Rule's Technical safeguards — access control, audit controls, integrity, authentication, transmission security — are exactly the controls that fail quietly in a document review and loudly in a breach.
We test the safeguard, not just the claim
Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the Security Rule expects access control, encryption, logging and transmission security to be effective, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the safeguard performs. It is also where HIPAA is heading: the proposed 2025 Security Rule update would make routine vulnerability scanning and penetration testing explicit obligations. Testing your controls isn't only stronger assurance today — it's getting ahead of where the rule is going.
A Security Risk Analysis tells you where the risk should be. Testing tells you where it actually is.
PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the artefacts your team needs to run a HIPAA programme — and the evidence pack you'd want in hand if OCR ever asks.
Security Risk Analysis report
The accurate, thorough risk analysis the Security Rule requires (164.308(a)(1)), covering the confidentiality, integrity and availability of your ePHI.
Gap assessment report
Your current state mapped against the Privacy, Security and Breach Notification Rules, with a prioritized roadmap to readiness.
Risk-management & remediation plan
A defensible risk register and prioritized treatment plan with clear ownership and sequencing.
Policy & procedure suite
The HIPAA documentation set — Administrative, Physical and Technical safeguard policies — written to the rule and to how you actually operate.
Business Associate Agreement review
An assessment and remediation of your BAAs up and down the chain, so every flow of PHI is lawfully covered.
Technical control validation report
Pentest-backed evidence that your Technical safeguards genuinely work, with remediation guidance and retest.
Breach-readiness playbook
A tested incident-response and notification plan built around the 60-day clock and OCR's requirements.
Audit-ready evidence pack
Collected, organized artefacts mapped cleanly to the safeguard families and rules.
Why teams choose Intect for HIPAA
CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility that travels with the evidence we produce.
We assess and we test — Most consultancies only review policy. We run the Security Risk Analysis and then test your Technical safeguards like attackers, so your evidence is proven, not asserted.
Researcher-led, not template-led — Senior practitioners scope your HIPAA programme to your real data flows and risk — not a copy-paste documentation kit.
Built for cross-border teams — A Delhi-based team fluent in what US Covered Entities and OCR expect of offshore Business Associates — so your readiness holds up on both sides of the border.
Frequently asked questions
Can Intect make us "HIPAA certified"?
No — because there is no such thing. HIPAA is a US federal law, and neither HHS nor any auditor issues an official HIPAA certificate. Anyone promising to make you "HIPAA certified" is offering a badge that doesn't exist. What we deliver is genuine, demonstrable readiness: the required Security Risk Analysis, safeguards that meet the rule, Business Associate Agreements in place, and an evidence pack you can stand behind if the Office for Civil Rights ever asks.
We're based in India and only handle US patient data for a client — does HIPAA apply to us?
Yes. The moment you create, receive, maintain or transmit US protected health information to perform a function for a Covered Entity, you are a Business Associate — and Business Associates are directly liable under the Security Rule. HIPAA follows the data across the border; being outside the US does not exempt you. It does mean your Business Associate Agreement with your client is central, and we review it as part of the engagement.
What is a Security Risk Analysis, and why does everyone start there?
The Security Risk Analysis is the single Required implementation specification that the rest of the Security Rule depends on (164.308(a)(1)). It is an accurate, thorough assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of your ePHI. OCR looks for it after almost every incident, and its absence is one of the most common findings in enforcement. We conduct it properly, document it, and keep it current.
What's the difference between "required" and "addressable" safeguards?
Both must be addressed. A "required" implementation specification must be implemented as written. An "addressable" one means you implement it, or — if it isn't reasonable and appropriate for you — document why and put an equivalent alternative in place. "Addressable" never means "optional," and treating it that way is a frequent and costly mistake.
How quickly do we have to report a breach?
The Breach Notification Rule requires you to notify affected individuals and HHS without unreasonable delay and no later than 60 calendar days after you discover a breach of unsecured PHI. Where a breach affects 500 or more residents of a state or jurisdiction, you must also notify prominent media in that area and notify HHS contemporaneously. We build and test the playbook so that clock is met, not missed.
Is HIPAA changing?
The Security Rule is poised to. In December 2024, OCR issued a Notice of Proposed Rulemaking — published in the Federal Register on 6 January 2025 — to significantly strengthen the Security Rule for the first time in over two decades: making "addressable" specifications mandatory, requiring encryption of ePHI, multi-factor authentication, network segmentation, and routine vulnerability scanning and penetration testing. As of mid-2026 it remains a proposed rule — not yet finalized — and its requirements and timing could still change. We scope to the rule in force today and help you get ahead of where it's heading.
Do you fix the findings, or just report them?
Both. We deliver a prioritized remediation plan, support your team through safeguard remediation, and re-verify the technical fixes so closure is evidenced — not just claimed.
One programme, many frameworks
A well-run HIPAA programme shares its backbone with the standards your customers also ask for.
Prove your safeguards. Stay ready for OCR.
Tell us your role — Covered Entity, Business Associate or offshore team handling US PHI — and we'll scope a HIPAA readiness assessment that fits, or connect you with an assessor.