Skip to content
The //Zyber// Security
All services

07 · HIPAA · HITECH · Breach Rule

HIPAA Assessment

HIPAA readiness without the checkbox theater.

A HIPAA Security Rule + Privacy Rule + Breach Notification Rule assessment, tuned to your role — Covered Entity, Business Associate, or Subcontractor. Includes the Risk Analysis required by § 164.308(a)(1)(ii)(A) — the single control most organizations fail an OCR audit on — built to NIST SP 800-66 rev2 guidance so it withstands scrutiny.

Outcomes

  • +A Risk Analysis built to meet Security Rule expectations (§ 164.308(a)(1)(ii)(A))
  • +Gap analysis across Administrative, Physical, and Technical Safeguards
  • +Breach-preparedness playbook + notification templates
  • +An OCR-defensible documentation package

01Scope

What we cover

In scope

  • +Security Rule — all Administrative, Physical, Technical safeguards
  • +Privacy Rule — Notice of Privacy Practices, minimum necessary, patient rights
  • +Breach Notification Rule — response readiness, documentation, templates
  • +Business Associate Agreements — audit + template review
  • +Enterprise Risk Analysis meeting § 164.308(a)(1)(ii)(A)
  • +HITECH + OCR guidance interpretation (2013 Omnibus + recent updates)

Out of scope

  • State-level privacy laws (available as add-on: TX HB300, CA CMIA)
  • GDPR / DPDP — see our Compliance Audits offering

02Approach

How the engagement runs

01

Role scoping

Covered Entity, Business Associate, or Subcontractor? Different rules apply — we map your role to your regulatory obligations.

02

Safeguards review

Every implementation specification (required + addressable) across Administrative, Physical, and Technical safeguards.

03

Risk Analysis

Enterprise-wide, per § 164.308(a)(1)(ii)(A), to NIST SP 800-66 rev2 method. Built to be defensible on its face — this is where most orgs fail an OCR audit.

04

BAA + vendor review

Business Associate Agreement templates + downstream vendor mapping.

05

Report + playbook

Findings + remediation + breach-response playbook + OCR-audit-ready documentation package.

03Deliverables

What you receive

Every artifact is defensible under external audit and actionable for engineering.

  • 01HIPAA Security Rule Gap Analysis
  • 02Enterprise Risk Analysis (meeting § 164.308(a)(1)(ii)(A))
  • 03Breach Response Playbook + Notification Templates
  • 04BAA Review + Template Library
  • 05OCR-Audit Documentation Package

04Frameworks

Regulator-defensible mapping

HIPAA
45 CFR § 164.308 (Admin)§ 164.310 (Physical)§ 164.312 (Technical)§ 164.400 (Breach)
HITECH
Meaningful Use security
NIST
SP 800-66 rev. 2 (HIPAA Security Rule guide)
HITRUST CSF
v11 mapping for advanced clients

05Timeline

Typical engagement pace

Phase 01

Scoping + role review

1 week

Phase 02

Safeguards + risk analysis

3–4 weeks

Phase 03

Reporting + playbook

1–2 weeks

06FAQ

Common questions

Different question? Raise it on a scoping call — we'd rather flag surprises early.

Are you a HIPAA-certified auditor?+

There is no OCR-issued HIPAA-auditor certification; anyone claiming one is bending the truth. Our operators hold industry certifications (CISSP, CISA, HCISPP), and every assessment is built to the documentation standard OCR looks for in an audit request.

Can this help a Business Associate demonstrate compliance?+

Yes — the documentation package is designed to be shared upstream with Covered Entities as evidence of BA compliance.

Do you review our BAAs?+

Yes, both incoming and outgoing. We flag terms that expose you and terms that expose your counterparties.

Ship HIPAA-defensible operations.

Scoping call, engagement letter within a week, complete assessment within 6–8 weeks of kickoff.

Book a scoping call