Skip to main content
Documentation

Other frameworks

HIPAA: the U.S. Security Rule for health-tech vendors

HIPAA's Security Rule (45 CFR §§ 164.302-318) requires covered entities and their business associates to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI) through three categories of safeguards: Administrative (risk analysis, workforce security, training, incident procedures), Physical (facility access, workstation and device controls), and Technical (access control, audit controls, integrity, authentication, and transmission security). A recurring, frequently misunderstood distinction runs through all three: each implementation specification is either Required or Addressable, and Addressable does not mean optional -- it means you must assess it and either implement it, implement a reasonable equivalent, or document why it isn't appropriate for you.

Transcript

HIPAA is the U.S. federal standard for protecting patient data. If you are a European health tech company selling into the U.S. market, this is the framework your hospital customers will ask about.

Enabling it adds the Administrative, Physical, and Technical Safeguards. Six checks are platform managed today, all reusing evidence already built for other frameworks.

The Security Rule Compliance Matrix is explicit about Required versus Addressable. Addressable does not mean optional, it means you must assess it and document your decision.

The Business Associate Agreement Tracker reuses your existing vendor register, because a written agreement is a written agreement whether it is called a BAA or a DPA.

The rest are honest manual tasks: workforce security, contingency planning, and the physical safeguards no automated scan can verify for you.

This overlap with SOC 2 and ISO 27001 is not a coincidence. The same access control and audit logging work satisfies all three, once you track it here.

Why this is required

45 CFR 164.312(a) and (d) require unique user identification and person/entity authentication for anyone accessing ePHI -- the Technical Safeguards' core access-control requirement, both Required.

45 CFR 164.312(b) requires audit controls: hardware, software, or procedural mechanisms that record and examine activity in systems containing ePHI. 45 CFR 164.312(c) separately requires a mechanism to authenticate ePHI -- confirming it hasn't been improperly altered or destroyed.

45 CFR 164.312(e) requires transmission security for ePHI sent over a network, including encryption where appropriate.

45 CFR 164.308(b) and 164.314 require a written Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits ePHI on your behalf -- the same underlying obligation as a GDPR Data Processing Agreement, just under a different name.

What EuroCompliant does

Enabling HIPAA adds a curated set of Administrative, Physical, and Technical Safeguard obligations to your Obligations page. Six are platform-managed today, all reusing evidence checks already built for other frameworks -- a real sign of genuine overlap, not one-off plumbing: access control (identity audit), audit controls and the ePHI-integrity mechanism (this platform's SHA-256 tamper-evident audit log -- not Ed25519 signing, which exists in this platform only for signing generated documents, never applied to the audit log itself), transmission security (CSPM cloud-configuration scan), business associate risk (vendor risk assessment), and policies/procedures (staff policy acknowledgment).

Two documents are available from the Documents section: a HIPAA Security Rule Compliance Matrix (the same live obligation-readiness scorecard the Obligations page shows, explicit about Required vs. Addressable) and a Business Associate Agreement Tracker (your existing vendor/processor register, reused honestly -- a BAA and a GDPR DPA cover the same underlying written-agreement commitment, so this platform doesn't duplicate that data in a separate HIPAA-only table).

Everything else is an honest tenant_action, naming the specific Required or Addressable specification rather than a generic placeholder.

Walking through it

1

Enable HIPAA

Adds the curated obligation set, including the 6 platform-managed checks.

Open /settings/profile?tab=frameworks →
2

Connect identity, cloud-configuration, and vendor-risk evidence

An identity connector drives access-control readiness; a cloud/CSPM scan drives transmission-security readiness; your vendor register (with DPAs/BAAs tracked) drives business-associate risk; your platform audit trail already drives the audit-controls and integrity checks.

Open /settings/integrations →
3

Generate the Compliance Matrix and BAA Tracker

Review both, confirm every 'Signed' BAA row is actually a HIPAA-compliant agreement (not just any vendor contract), and back every manual attestation with real evidence before sharing either document with a prospective U.S. healthcare client.

Open /compliance-docs →

The law

Penalties for non-compliance

HHS civil monetary penalties run on a four-tier culpability scale (45 CFR 160.404): roughly $100-$50,000 per violation where the entity had no knowledge, up to at least $50,000 per violation for uncorrected willful neglect, each tier capped around $1.5 million per year for violations of an identical requirement.

Frequently asked

We're an EU company with no US operations -- does HIPAA apply to us?

It can. HIPAA applies based on the data and relationship, not the vendor's location: if you're a business associate handling ePHI on behalf of a US covered entity (a hospital, health plan, or another business associate), the Security Rule's safeguards and a signed BAA apply to you regardless of where your company is based.

How does HIPAA relate to the frameworks we already track, like SOC 2 and ISO 27001?

There's substantial control overlap -- access control, audit logging, encryption, incident response, and vendor risk all show up in some form across HIPAA, SOC 2's Common Criteria, and ISO 27001's Annex A. That's why every platform-managed HIPAA check here reuses evidence already collected for those frameworks rather than requiring separate HIPAA-specific scans. A SOC 2 report or ISO 27001 certification can support a HIPAA risk analysis, but neither one substitutes for it.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial