Compliance · HIPAA 45 CFR Parts 160, 162 & 164 · Privacy · Security · Breach

HIPAA Security & Privacy Readiness

HIPAA governs how US protected health information is kept private and secure — and it reaches every organization that touches that data, including offshore teams. We deliver the Security Risk Analysis HIPAA requires, close the gaps against its Administrative, Physical and Technical safeguards, and validate your technical controls the way an attacker would — so your compliance is demonstrable, not just documented.

There is no official HIPAA certificate — there is defensible, evidence-backed readiness. CERT-In Empaneled. We test the safeguards we assess.

Privacy Rule Security Rule Breach Notification Rule 45 CFR Part 164 CERT-In Empaneled
Law
US HIPAA — 45 CFR Parts 160, 162 & 164
Rules
Privacy · Security · Breach Notification
Role
Readiness & audit support — no HIPAA certification exists
Validation
Pentest-backed technical safeguard validation
02

One law, three rules, one obligation: protect the patient's data

HIPAA — the US Health Insurance Portability and Accountability Act — sets the federal standard for protecting health information in the United States.

Its requirements live in the federal regulations at 45 CFR Parts 160, 162 and 164, and three rules do the heavy lifting. The Privacy Rule governs how protected health information (PHI) — health data tied to an identifiable person, in any form — may be used and disclosed. The Security Rule sets the safeguards that protect that information when it is held or transmitted electronically (ePHI), built around three families of controls: Administrative, Physical and Technical. The Breach Notification Rule dictates what must happen when unsecured PHI is exposed — who must be told, and how quickly. Enforcement sits with the US Department of Health and Human Services, through its Office for Civil Rights (OCR).

What HIPAA does not have is a certificate. No government body, and no auditor, issues an official "HIPAA certification." Anyone who claims to make you "HIPAA certified" is selling a badge that does not exist. What you can — and should — have is a current, documented Security Risk Analysis, safeguards that genuinely meet the rule, Business Associate Agreements in place, and the evidence to demonstrate all of it to OCR if asked. That is what we build.

"There is no HIPAA certificate to hang on the wall. There is only the question OCR actually asks after an incident: can you show that your safeguards were real? We make sure the answer is yes."
03

Who HIPAA reaches — including teams outside the US

HIPAA's obligations flow down a chain. They begin with Covered Entities and extend, by contract, to every Business Associate that handles protected health information on their behalf — wherever that work is performed.

01

Covered Entities

Health plans, healthcare clearinghouses and healthcare providers that transmit health information electronically. They hold the primary obligation under all three Rules.

Privacy RuleSecurity Rule
02

Business Associates

Any organization that creates, receives, maintains or transmits PHI to perform a function for a Covered Entity — billing, analytics, cloud hosting, IT services, support. Business Associates are directly liable under the Security Rule and parts of the Privacy and Breach Notification Rules.

Security RuleDirectly liable
03

Indian healthcare IT, BPO & SaaS

Offshore teams in medical billing, coding, RCM, transcription, telehealth, clinical analytics and healthcare SaaS are Business Associates the moment they touch US PHI. HIPAA follows the data across the border — your distance from the US doesn't dilute the obligation.

Business AssociateCross-border
04

Subcontractors (downstream BAs)

A Business Associate's own vendors that handle PHI are themselves Business Associates, bound by the same safeguards through a downstream Business Associate Agreement.

Downstream BAA
05

The BAA chain

A Covered Entity may share PHI with a Business Associate only after obtaining satisfactory written assurances — the Business Associate Agreement — and that requirement flows all the way down the chain. No BAA, no lawful flow of PHI.

BAA required

Wherever you sit on the chain, the safeguards are the same family of controls — calibrated to the data you hold and the role you play.

04

What the Security Rule actually asks for

The Security Rule (45 CFR Part 164, Subpart C) protects electronic PHI through three safeguard families — Administrative, Physical and Technical — supported by Organizational requirements (chiefly Business Associate contracts) and Policies, Procedures & Documentation.

Each family contains standards, and many standards carry implementation specifications marked Required or Addressable — "addressable" does not mean optional; it means you implement it, or document a reasoned, equivalent alternative. At the centre of it all is one Required specification that drives everything else: the Security Risk Analysis.

05

From data flows to demonstrable readiness

HIPAA compliance is not a one-time project; it is a risk-management cycle the Security Rule expects you to run and keep current.

Our approach mirrors that cycle: we map where PHI actually lives and moves, run the Security Risk Analysis the rule requires, manage the gaps down, remediate the safeguards, prove the technical ones work, put the policies, agreements and training in place, ready you for a breach you hope never comes — and help you sustain all of it.

01
Scope PHI / ePHI & Data Flows
We map every place PHI and ePHI is created, received, stored and transmitted — across applications, infrastructure, endpoints, third parties and offshore locations. You cannot protect, or risk-analyse, data you haven't located.
02 · REQUIRED
Security Risk Analysis
We conduct the accurate, thorough Security Risk Analysis the Security Rule requires (164.308(a)(1)) — assessing the risks and vulnerabilities to the confidentiality, integrity and availability of your ePHI across all three safeguard families.
03
Gap & Risk Management
We measure your current state against the Security and Privacy Rules, rank gaps by risk and impact, and produce a prioritized risk-management plan — separating true safeguard gaps from documentation gaps.
04
Safeguard Remediation
We support remediation across Administrative, Physical and Technical safeguards — control design, configuration and the operational changes that close each gap correctly the first time.
05 · PENTEST-BACKED
Technical Validation
We test the Technical safeguards — access control, audit controls, integrity, authentication and transmission security — with penetration testing and configuration review, so "we have access controls" becomes demonstrated evidence of what an unauthorized user can and cannot reach.
06
Policies, BAAs & Training
We build the policy and procedure suite the rule requires, review and remediate your Business Associate Agreements up and down the chain, and stand up the workforce security-awareness training the Administrative safeguards expect.
07
Breach Readiness
We build and test the incident-response and breach-notification playbook against the 60-day clock — discovery, assessment, the four-factor risk assessment, and the individual, HHS and (at 500+) media notifications — so a real event is handled, not improvised.
08
Sustain
HIPAA's risk analysis must stay current. We help you re-run it on a defined cadence and after significant change, keep evidence audit-ready, and maintain the posture as your systems, vendors and risks evolve.

FIG. 02 — HIPAA risk-analysis & readiness lifecycle · 02 the Required keystone · 05 the offensive-edge differentiator

The Security Rule treats security as an ongoing process, not a finish line — and the proposed 2025 update would tighten that expectation further. We build the cycle so it keeps proving itself, not just clears one review.

06

What an engagement includes

We scope to your role — Covered Entity, Business Associate or offshore Business Associate — and cover the work end to end.

Scope
01

PHI / ePHI discovery and data-flow mapping across applications, infrastructure, endpoints and third parties

02

Definition of the HIPAA boundary

systems, sites, functions and offshore locations in scope

03

Role determination

Covered Entity, Business Associate or subcontractor, and the obligations that follow

Risk-analyse
04

The Security Risk Analysis required by 164.308(a)(1)

confidentiality, integrity and availability of ePHI

05

Gap assessment against the Privacy, Security and Breach Notification Rules

06

Risk register and prioritized risk-management plan

Remediate
07

Safeguard remediation support across Administrative, Physical and Technical families

08

Control design and configuration guidance for access control, encryption, logging and authentication

09

A prioritized remediation roadmap with clear ownership and sequencing

Validate (the offensive edge)
10

Technical control validation

penetration testing and configuration review that proves the Technical safeguards actually work

11

Evidence collection and an audit-ready artifact pack mapped to the safeguard families

12

Remediation retest after fixes

Govern
13

Policy and procedure suite aligned to the Security and Privacy Rules

14

Business Associate Agreement review and remediation, up and down the chain

15

Workforce security-awareness training aligned to the Administrative safeguards

16

Incident-response and breach-notification playbook tested against the 60-day clock

Sustain
17

Periodic re-analysis cadence and post-change reassessment

18

Continuous evidence management to stay audit-ready

19

Readiness guidance for the proposed 2025 Security Rule update as it develops

07

We audit like we attack

The Security Rule's Technical safeguards are not policy statements — they are controls that either hold or don't. A paper review confirms they're written down. We confirm they work.

Safeguards on paper

Most HIPAA work stops at the document

The conventional path to HIPAA readiness reviews policies, samples evidence and checks that an access-control or encryption policy exists. That satisfies the documentation — but a written access-control policy and an access-control system an attacker can walk through are not the same thing. The Security Rule's Technical safeguards — access control, audit controls, integrity, authentication, transmission security — are exactly the controls that fail quietly in a document review and loudly in a breach.

Safeguards that have been proven

We test the safeguard, not just the claim

Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the Security Rule expects access control, encryption, logging and transmission security to be effective, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the safeguard performs. It is also where HIPAA is heading: the proposed 2025 Security Rule update would make routine vulnerability scanning and penetration testing explicit obligations. Testing your controls isn't only stronger assurance today — it's getting ahead of where the rule is going.

A Security Risk Analysis tells you where the risk should be. Testing tells you where it actually is.

PENTEST-BACKED EVIDENCE
08

What you receive

Every engagement produces the artefacts your team needs to run a HIPAA programme — and the evidence pack you'd want in hand if OCR ever asks.

01

Security Risk Analysis report

The accurate, thorough risk analysis the Security Rule requires (164.308(a)(1)), covering the confidentiality, integrity and availability of your ePHI.

164.308(a)(1)
02

Gap assessment report

Your current state mapped against the Privacy, Security and Breach Notification Rules, with a prioritized roadmap to readiness.

03

Risk-management & remediation plan

A defensible risk register and prioritized treatment plan with clear ownership and sequencing.

04

Policy & procedure suite

The HIPAA documentation set — Administrative, Physical and Technical safeguard policies — written to the rule and to how you actually operate.

05

Business Associate Agreement review

An assessment and remediation of your BAAs up and down the chain, so every flow of PHI is lawfully covered.

06

Technical control validation report

Pentest-backed evidence that your Technical safeguards genuinely work, with remediation guidance and retest.

PENTEST-BACKED
07

Breach-readiness playbook

A tested incident-response and notification plan built around the 60-day clock and OCR's requirements.

08

Audit-ready evidence pack

Collected, organized artefacts mapped cleanly to the safeguard families and rules.

Privacy Rule Security Rule Breach Notification Rule 45 CFR Part 164 CERT-In Empaneled Supports ISO 27001, SOC 2 & ISO 27701 readiness
09

Why teams choose Intect for HIPAA

CERT-In Empaneled Researcher-led · cross-border fluency

CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility that travels with the evidence we produce.

We assess and we test — Most consultancies only review policy. We run the Security Risk Analysis and then test your Technical safeguards like attackers, so your evidence is proven, not asserted.

Researcher-led, not template-led — Senior practitioners scope your HIPAA programme to your real data flows and risk — not a copy-paste documentation kit.

Built for cross-border teams — A Delhi-based team fluent in what US Covered Entities and OCR expect of offshore Business Associates — so your readiness holds up on both sides of the border.

10

Frequently asked questions

Can Intect make us "HIPAA certified"?

No — because there is no such thing. HIPAA is a US federal law, and neither HHS nor any auditor issues an official HIPAA certificate. Anyone promising to make you "HIPAA certified" is offering a badge that doesn't exist. What we deliver is genuine, demonstrable readiness: the required Security Risk Analysis, safeguards that meet the rule, Business Associate Agreements in place, and an evidence pack you can stand behind if the Office for Civil Rights ever asks.

We're based in India and only handle US patient data for a client — does HIPAA apply to us?

Yes. The moment you create, receive, maintain or transmit US protected health information to perform a function for a Covered Entity, you are a Business Associate — and Business Associates are directly liable under the Security Rule. HIPAA follows the data across the border; being outside the US does not exempt you. It does mean your Business Associate Agreement with your client is central, and we review it as part of the engagement.

What is a Security Risk Analysis, and why does everyone start there?

The Security Risk Analysis is the single Required implementation specification that the rest of the Security Rule depends on (164.308(a)(1)). It is an accurate, thorough assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of your ePHI. OCR looks for it after almost every incident, and its absence is one of the most common findings in enforcement. We conduct it properly, document it, and keep it current.

What's the difference between "required" and "addressable" safeguards?

Both must be addressed. A "required" implementation specification must be implemented as written. An "addressable" one means you implement it, or — if it isn't reasonable and appropriate for you — document why and put an equivalent alternative in place. "Addressable" never means "optional," and treating it that way is a frequent and costly mistake.

How quickly do we have to report a breach?

The Breach Notification Rule requires you to notify affected individuals and HHS without unreasonable delay and no later than 60 calendar days after you discover a breach of unsecured PHI. Where a breach affects 500 or more residents of a state or jurisdiction, you must also notify prominent media in that area and notify HHS contemporaneously. We build and test the playbook so that clock is met, not missed.

Is HIPAA changing?

The Security Rule is poised to. In December 2024, OCR issued a Notice of Proposed Rulemaking — published in the Federal Register on 6 January 2025 — to significantly strengthen the Security Rule for the first time in over two decades: making "addressable" specifications mandatory, requiring encryption of ePHI, multi-factor authentication, network segmentation, and routine vulnerability scanning and penetration testing. As of mid-2026 it remains a proposed rule — not yet finalized — and its requirements and timing could still change. We scope to the rule in force today and help you get ahead of where it's heading.

Do you fix the findings, or just report them?

Both. We deliver a prioritized remediation plan, support your team through safeguard remediation, and re-verify the technical fixes so closure is evidenced — not just claimed.

11

One programme, many frameworks

A well-run HIPAA programme shares its backbone with the standards your customers also ask for.

Scope an engagement

Prove your safeguards. Stay ready for OCR.

Tell us your role — Covered Entity, Business Associate or offshore team handling US PHI — and we'll scope a HIPAA readiness assessment that fits, or connect you with an assessor.