The US standard for protecting health information. HIPAA sets mandatory privacy and security rules for any organisation that handles protected health information — from providers and insurers to the vendors who serve them.
The Health Insurance Portability and Accountability Act establishes federal requirements for protected health information (PHI) in the United States, through its Privacy Rule, Security Rule, and Breach Notification Rule.
It applies both to covered entities — healthcare providers, health plans, and clearinghouses — and to the business associates that process PHI on their behalf, which is where most technology vendors fall.
HIPAA has no single government certification. Organisations demonstrate compliance through a documented risk analysis, implemented safeguards, and an independent assessment — and many adopt a certifiable framework to evidence it to partners.
Hospitals, clinics, and practices handling patient records.
Any SaaS or service touching PHI as a business associate.
Health plans and clearinghouses processing member data.
Delivered through our specialist network. We conduct the required risk analysis, implement the administrative, physical, and technical safeguards, and prepare you for an independent assessment — so you can give healthcare partners credible evidence, not just a self-attestation.
We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.
A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.
We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.
The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.
We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.
No — the US government doesn't certify HIPAA compliance. Organisations demonstrate it through a documented risk analysis, implemented safeguards, and an independent assessment. Some adopt a certifiable framework on top to give partners stronger proof.
If your company creates, receives, maintains, or transmits PHI on behalf of a covered entity, then yes — and you carry direct HIPAA obligations plus a business associate agreement. We help you scope exactly where you stand.
Book a free advisory session and we'll map your fastest credible route to compliance.
Book a free advisory session