Security-First Compliance
Platform for HIPAA
The Security Rule is 18 standards and 36 implementation specifications, and the hard part is knowing which of them your ePHI touches. Comply finds the ePHI first on Strac's DLP foundation, tracks Business Associate Agreements per vendor, and keeps the written rationale for every Addressable specification you do not implement, whether you meet it by an equivalent measure or conclude that none is reasonable and appropriate.
54
Controls covered
100+
Continuous tests
1
Evidence platform
Skip the sales call
See what HIPAA costs
One flat price covers HIPAA and the security modules. We'll email you the number and a free readiness assessment, no call required.
Framework
HIPAA Security and Breach Notification Rules (45 CFR Part 164, Subparts A, C and D)
Health Insurance Portability and Accountability Act
Healthcare data security
What it is
HIPAA is the U.S. law governing protected health information. Its Security Rule (45 CFR Part 164, Subparts A and C) binds covered entities and, since HITECH, business associates directly: 18 standards across Administrative (§164.308), Physical (§164.310), and Technical (§164.312) safeguards, plus 36 implementation specifications, 14 Required and 22 Addressable. Addressable does not mean optional: you either implement the specification, or you document in writing why it is not reasonable and appropriate and put an equivalent alternative measure in its place where one is reasonable and appropriate. A healthcare buyer's security review and an OCR investigation ask for the same thing: the risk analysis, the safeguards you implemented, the determinations you wrote down, the agreements you signed, and the records that show all of it operating.
Why Strac Comply for HIPAA
OCR says the Risk Analysis at §164.308(a)(1)(ii)(A) is the most commonly cited Security Rule deficiency in its enforcement actions, and it fails on scope, because ePHI does not stay in the EHR: it is in the shared inbox, the Slack thread, the S3 export, the analyst's laptop backup. Most HIPAA platforms hand you a questionnaire and take your word for where it lives. Strac Comply is built on Strac's DLP foundation, so we find the ePHI first and scope the safeguards to where it is, which makes your risk analysis a finding instead of an assertion.
How Strac Comply automates HIPAA
Continuous evidence, not annual scramble.
ePHI discovery across SaaS, cloud, and endpoints: health identifiers and clinical data located in Google Drive, Slack, email, S3, and 40+ apps by Strac's DLP engine, so the Risk Analysis at §164.308(a)(1)(ii)(A) is scoped to where ePHI lives
37 continuous AWS tests an auditor reading your Security Rule safeguards would already be looking at: encryption at rest and in transit, CloudTrail audit controls, root-account restriction and account deprovisioning, and backup and point-in-time recovery, re-run every day
Business Associate Agreements tracked per vendor: every vendor with access to ePHI carries its agreement status, so the §164.308(b)(1) and §164.314(a) evidence is a register you hand over rather than a folder somebody assembles
Addressable determinations that survive an investigation: file the written rationale, and the equivalent alternative measure where one is reasonable and appropriate, as versioned documents on the same review cycle as your policies, which is the written rationale §164.306(d)(3) requires you to document
Retention that matches §164.316(b)(2)(i): policies, acknowledgements, training completions, incident records, and evidence, each version-pinned at the moment it was current and kept six years from creation or from the date it was last in effect, whichever is later
54 controls. One evidence base.
A sample of how the heaviest controls are automated.
§164.308(a)(1)
Security management process
ePHI discovery + risk register with dated approvals
§164.308(a)(5)
Security awareness and training
Training campaigns + per-person completion evidence
§164.308(b)(1)
Business associate contracts
Vendor register + agreement status per vendor
§164.310(d)(1)
Device and media controls
Policy library + media disposal records on file
§164.312(a)(1)
Access control
Root-account restriction and deprovisioning tests
§164.312(b)
Audit controls
CloudTrail enablement, log validation, retention tests
Frequently asked
What do we send a customer who asks for HIPAA proof?
Four things, and the platform produces all of them as you go rather than the week you are asked. A trust portal page you send as a link, carrying the frameworks you run, your posture, and the documents you have chosen to publish. An audit binder, where every policy version, document, test result and written determination is pinned at the moment it was current, exported as a packet or opened through a magic link so a reviewer works in their own portal instead of inside your tenant. A current risk analysis carrying a dated management approval. And the population records a reviewer samples from: training completions per person, policy acknowledgments per person, and Business Associate Agreements per vendor. Most healthcare buyers ask for a SOC 2 report alongside it, which the same evidence base produces.
Which parts of HIPAA does this cover?
The Security Rule (45 CFR Part 164, Subparts A and C) is the control program: 18 standards and 36 implementation specifications across the Administrative, Physical, and Technical Safeguards, plus the organizational requirements at §164.314 and the documentation requirements at §164.316. Breach notification (§164.400 to §164.414) is a seeded control set too, not merely a policy: the notification duties, the four-factor breach risk assessment that decides whether you notify at all, and the log of breaches affecting fewer than 500 individuals each carry their own control and their own evidence. Note that the individual notice is due without unreasonable delay and no later than 60 calendar days after discovery, which is a deadline rather than a grace period. The Privacy Rule (minimum necessary, notice of privacy practices, accounting of disclosures) is advisory here: the AI vCISO answers on it, but it is not run as a control program. Which of these are yours depends on what you are. A business associate, which is what most health technology companies are, owes the Security Rule, the breach notification duties, and its own subcontractor agreements. A covered entity owes all of that plus the Privacy Rule administrative requirements at §164.530: a privacy official, privacy training, a sanctions policy, and a complaints process. Those stay yours to run.
What does "Addressable" actually require?
An implementation specification marked Addressable is not optional, and it is never simply not applicable. You assess whether it is reasonable and appropriate for your environment, and where it is not, you document why in writing and implement an equivalent alternative measure if one is reasonable and appropriate. §164.306(d)(3) requires that written rationale, and §164.316(b)(2)(i) requires you to keep it for six years from creation or from the date it was last in effect, whichever is later. Comply keeps that determination as a versioned document on the same review cycle as your policies, so the decision is still retrievable years later instead of living in one person's memory. Encryption is the specification this comes up on most: §164.312(a)(2)(iv) and §164.312(e)(2)(ii) are both Addressable rather than Required, which surprises people. It is still the one to implement anyway, because ePHI encrypted to HHS guidance, where the key was not compromised, is not a reportable breach at all.
Does HIPAA work carry over to SOC 2 or ISO 27001?
Yes, and it is most of the work. The Technical Safeguards at §164.312 overlap heavily with SOC 2 CC6 and CC7 and ISO 27001 Annex A 8.x: the same encryption, access control, and audit logging tests satisfy all three, collected once. Cross-framework mapping means one control set sits behind every framework, so adding HIPAA to a running SOC 2 program is largely a scoping and documentation exercise rather than a second evidence collection.
Also automated by Strac Comply
Ready to get HIPAA done without the scramble?
See how Strac Comply runs your HIPAA program: continuous evidence, AI vCISO, and an audit binder your auditor will actually thank you for.
Book a Demo