HealthcareUnited States

HIPAA compliance

Health Insurance Portability and Accountability Act

HIPAA sets requirements for protecting patient health information (PHI) in the United States, spanning administrative, physical and technical safeguards. Pelta helps healthcare and health-tech organisations map HIPAA safeguards to controls and keep the supporting evidence continuously linked.

Who it's for

Does HIPAA apply to you?

  • Healthcare providers, payers and clearinghouses
  • Health-tech companies and business associates handling PHI
  • Organisations aligning HIPAA with ISO 27001

Understand the three rules

HIPAA governs how protected health information (PHI) is handled in the United States. If you are a health-tech company, you are most often a business associate — a vendor handling PHI on behalf of a covered entity — which means HIPAA applies to you directly. It is organised into three rules.

  • Privacy Rule: governs the use and disclosure of PHI, and individuals' rights over their health information.
  • Security Rule: sets requirements for protecting electronic PHI (ePHI) through administrative, physical and technical safeguards.
  • Breach Notification Rule: requires notification of breaches of unsecured PHI within defined timeframes.
This is a general overview, not legal advice. Confirm your status and obligations under HIPAA with qualified counsel.

The Security Rule safeguards

The Security Rule is where most technical work sits. It is organised into three safeguard categories, each with required and addressable specifications.

HIPAA Security Rule safeguards
SafeguardExamples
AdministrativeRisk analysis, workforce training, access management, contingency planning
PhysicalFacility access controls, workstation and device security, media disposal
TechnicalAccess controls, audit logging, encryption, integrity and transmission security

The risk analysis is the anchor

The Security Rule requires an accurate, thorough risk analysis of the risks to ePHI, and a plan to manage them. This is not a one-off document; it is expected to be maintained. Enforcement actions frequently cite a missing or inadequate risk analysis as the root failure, so treat it as the anchor of your programme.

A practical route to HIPAA readiness

Scope PHI

Where ePHI lives

Risk analysis

Threats to ePHI

Safeguards

Admin/physical/tech

BAAs

Down the chain

Evidence

Maintain & prove

Business Associate Agreements

A Business Associate Agreement (BAA) is the contract that flows HIPAA obligations down the chain. You need a BAA with the covered entities you serve, and with any of your own subcontractors that touch PHI. No BAA, no lawful sharing of PHI. HIPAA also overlaps heavily with ISO 27001 and SOC 2, so most of the security work — and its evidence — is reusable.

Common pitfalls to avoid

  • Skipping or under-scoping the risk analysis — the single most-cited enforcement failure.
  • Missing BAAs with subcontractors that handle PHI on your behalf.
  • Treating addressable specifications as optional rather than documenting your reasoning.
How Pelta helps

Run HIPAA on one connected platform

Safeguards mapped

Manage administrative, physical and technical safeguards as a single control set.

Evidence-backed

Link each safeguard to the evidence that demonstrates it.

Vendor / BA risk

Assess and monitor the business associates that touch PHI.

Reuse with ISO 27001

Share overlapping controls and evidence to reduce duplicate effort.

HIPAA FAQs

Who must comply with HIPAA?+

Covered entities (providers, payers, clearinghouses) and their business associates — vendors that handle protected health information on their behalf. Health-tech companies are usually business associates.

What are the HIPAA Security Rule safeguards?+

Three categories: administrative (risk analysis, training, access management), physical (facility and device controls) and technical (access controls, audit logging, encryption). Each has required and addressable specifications.

What is a Business Associate Agreement?+

A BAA is the contract that passes HIPAA obligations to a vendor handling PHI. You need one with the covered entities you serve and with any subcontractors that touch PHI on your behalf.

Is a HIPAA risk analysis mandatory?+

Yes. The Security Rule requires an accurate and thorough risk analysis of risks to electronic PHI, maintained over time. A missing or inadequate risk analysis is a frequent cause of enforcement findings.

Does SOC 2 cover HIPAA?+

They overlap on security controls but are not the same — SOC 2 is a broad attestation, HIPAA a specific legal requirement for PHI. Much of the security evidence can be reused across both.

Does Pelta cover HIPAA and vendor risk together?+

Yes. Pelta maps HIPAA safeguards to controls and evidence, and its third-party risk module tracks the business associates that handle PHI.

See HIPAA compliance on Pelta

Manage HIPAA compliance on Pelta — map the Security and Privacy Rule safeguards to controls and evidence, and protect patient health information.