07 · HIPAA · HITECH · Breach Rule
HIPAA Assessment
HIPAA readiness without the checkbox theater.
A HIPAA Security Rule + Privacy Rule + Breach Notification Rule assessment, tuned to your role — Covered Entity, Business Associate, or Subcontractor. Includes the Risk Analysis required by § 164.308(a)(1)(ii)(A) — the single control most organizations fail an OCR audit on — built to NIST SP 800-66 rev2 guidance so it withstands scrutiny.
Outcomes
- +A Risk Analysis built to meet Security Rule expectations (§ 164.308(a)(1)(ii)(A))
- +Gap analysis across Administrative, Physical, and Technical Safeguards
- +Breach-preparedness playbook + notification templates
- +An OCR-defensible documentation package
01Scope
What we cover
In scope
- +Security Rule — all Administrative, Physical, Technical safeguards
- +Privacy Rule — Notice of Privacy Practices, minimum necessary, patient rights
- +Breach Notification Rule — response readiness, documentation, templates
- +Business Associate Agreements — audit + template review
- +Enterprise Risk Analysis meeting § 164.308(a)(1)(ii)(A)
- +HITECH + OCR guidance interpretation (2013 Omnibus + recent updates)
Out of scope
- −State-level privacy laws (available as add-on: TX HB300, CA CMIA)
- −GDPR / DPDP — see our Compliance Audits offering
02Approach
How the engagement runs
Role scoping
Covered Entity, Business Associate, or Subcontractor? Different rules apply — we map your role to your regulatory obligations.
Safeguards review
Every implementation specification (required + addressable) across Administrative, Physical, and Technical safeguards.
Risk Analysis
Enterprise-wide, per § 164.308(a)(1)(ii)(A), to NIST SP 800-66 rev2 method. Built to be defensible on its face — this is where most orgs fail an OCR audit.
BAA + vendor review
Business Associate Agreement templates + downstream vendor mapping.
Report + playbook
Findings + remediation + breach-response playbook + OCR-audit-ready documentation package.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01HIPAA Security Rule Gap Analysis
- 02Enterprise Risk Analysis (meeting § 164.308(a)(1)(ii)(A))
- 03Breach Response Playbook + Notification Templates
- 04BAA Review + Template Library
- 05OCR-Audit Documentation Package
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Scoping + role review
1 week
Safeguards + risk analysis
3–4 weeks
Reporting + playbook
1–2 weeks
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
Are you a HIPAA-certified auditor?+
There is no OCR-issued HIPAA-auditor certification; anyone claiming one is bending the truth. Our operators hold industry certifications (CISSP, CISA, HCISPP), and every assessment is built to the documentation standard OCR looks for in an audit request.
Can this help a Business Associate demonstrate compliance?+
Yes — the documentation package is designed to be shared upstream with Covered Entities as evidence of BA compliance.
Do you review our BAAs?+
Yes, both incoming and outgoing. We flag terms that expose you and terms that expose your counterparties.
Ship HIPAA-defensible operations.
Scoping call, engagement letter within a week, complete assessment within 6–8 weeks of kickoff.
Book a scoping call