By industry

Patient data, and the proof you protect it

Patient data protection and the controls auditors expect to see.

Protected health information sets the floor, and the health systems you sell into set the ceiling. There is no HIPAA certificate — compliance is a state you build, operate and have to be able to prove on demand.


The regulatory picture

What this sector has to satisfy

HIPAA is the obligation; the certifications are how you prove it to a buyer who cannot audit you directly.


Where you are

The constraints at this stage

What tends to be true when companies come to us at this size.

There is no certificate to point at

HIPAA has no certification body, so buyers substitute their own assessments — or ask for ISO 27001 and SOC 2 as a proxy. Without one you are re-audited by every customer.

PHI is everywhere it should not be

Support tickets, logs, analytics, test fixtures and screenshots. The minimum necessary standard is a data-architecture requirement long before it is a policy one.

Every integration adds a BAA

Each vendor touching PHI needs a business associate agreement with real flow-down, and the absence of one is a violation on its own — no breach required.


How the engagement works

What actually happens

The same four beats every time, scoped to what this stage needs.

Find the PHI

A data inventory covering the places PHI leaks into — logs, tickets, analytics, backups — because you cannot safeguard what nobody has mapped.

Run the risk analysis

The formal risk analysis the Security Rule requires, done properly. It is the most-cited failure in enforcement actions and the backbone of every other control decision.

Implement and paper it

Administrative, physical and technical safeguards implemented, plus the policies, BAAs and training records that evidence them.

Rehearse and sustain

Breach response walked through before it is needed, access reviews on a cadence, and the certification audits carried for you.


Proof

Track record

Across every engagement we have run, at every size.

0+

Companies Secured

Zero

Failed Audits

4-8

Weeks to Compliance

0+

Team Certifications


What you walk away with

The artefacts

Everything below is a thing you own at the end, not a promise about the process.

  • A PHI inventory and data flow map, including the unintended stores
  • A documented Security Rule risk analysis and treatment plan
  • The full HIPAA policy and procedure set, with training records
  • Business associate agreements with correct subcontractor flow-down
  • Implemented technical safeguards: access control, audit logging, encryption
  • A rehearsed breach notification runbook
  • ISO 27001 certification where buyers require independent proof

Related

Where to go next

The problems this stage usually arrives with, and the services behind them.


Questions

What people ask at this stage

No — HIPAA has no certification body, and any vendor selling you a HIPAA certificate is selling you their own opinion. What buyers accept instead is a documented risk analysis, implemented safeguards, and usually an ISO 27001 or SOC 2 report as independent evidence.
The Security Rule applies to you directly, and your BAAs bind you contractually on top. In practice the work is the same; what differs is that your obligations flow from the agreement as well as the regulation, and subcontractors need flow-down agreements of their own.
More than in most sectors, because minimum necessary and audit logging are product requirements rather than documentation. We do the assessment, policy and evidence work; your engineers implement access scoping and logging with our specialists specifying what is needed.
If you handle data of people in the EU, yes — and health data is a special category with a higher bar. It maps onto the same control set, but the notices, lawful basis and records are handled separately.

Prove it before they ask.

Tell us who you are integrating with and what they have asked for. Thirty minutes is usually enough to scope it.