Automated HIPAA Compliance

Security-First Compliance
Platform for HIPAA

The Security Rule is 18 standards and 36 implementation specifications, and the hard part is knowing which of them your ePHI touches. Comply finds the ePHI first on Strac's DLP foundation, tracks Business Associate Agreements per vendor, and keeps the written rationale for every Addressable specification you do not implement, whether you meet it by an equivalent measure or conclude that none is reasonable and appropriate.

54

Controls covered

100+

Continuous tests

1

Evidence platform

Skip the sales call

See what HIPAA costs

One flat price covers HIPAA and the security modules. We'll email you the number and a free readiness assessment, no call required.

No spam. Your data is protected by our own DLP. Unsubscribe anytime.

Framework

HIPAA Security and Breach Notification Rules (45 CFR Part 164, Subparts A, C and D)

Health Insurance Portability and Accountability Act

Healthcare data security

What it is

HIPAA is the U.S. law governing protected health information. Its Security Rule (45 CFR Part 164, Subparts A and C) binds covered entities and, since HITECH, business associates directly: 18 standards across Administrative (§164.308), Physical (§164.310), and Technical (§164.312) safeguards, plus 36 implementation specifications, 14 Required and 22 Addressable. Addressable does not mean optional: you either implement the specification, or you document in writing why it is not reasonable and appropriate and put an equivalent alternative measure in its place where one is reasonable and appropriate. A healthcare buyer's security review and an OCR investigation ask for the same thing: the risk analysis, the safeguards you implemented, the determinations you wrote down, the agreements you signed, and the records that show all of it operating.

Why Strac Comply for HIPAA

OCR says the Risk Analysis at §164.308(a)(1)(ii)(A) is the most commonly cited Security Rule deficiency in its enforcement actions, and it fails on scope, because ePHI does not stay in the EHR: it is in the shared inbox, the Slack thread, the S3 export, the analyst's laptop backup. Most HIPAA platforms hand you a questionnaire and take your word for where it lives. Strac Comply is built on Strac's DLP foundation, so we find the ePHI first and scope the safeguards to where it is, which makes your risk analysis a finding instead of an assertion.

How Strac Comply automates HIPAA

Continuous evidence, not annual scramble.

ePHI discovery across SaaS, cloud, and endpoints: health identifiers and clinical data located in Google Drive, Slack, email, S3, and 40+ apps by Strac's DLP engine, so the Risk Analysis at §164.308(a)(1)(ii)(A) is scoped to where ePHI lives

37 continuous AWS tests an auditor reading your Security Rule safeguards would already be looking at: encryption at rest and in transit, CloudTrail audit controls, root-account restriction and account deprovisioning, and backup and point-in-time recovery, re-run every day

Business Associate Agreements tracked per vendor: every vendor with access to ePHI carries its agreement status, so the §164.308(b)(1) and §164.314(a) evidence is a register you hand over rather than a folder somebody assembles

Addressable determinations that survive an investigation: file the written rationale, and the equivalent alternative measure where one is reasonable and appropriate, as versioned documents on the same review cycle as your policies, which is the written rationale §164.306(d)(3) requires you to document

Retention that matches §164.316(b)(2)(i): policies, acknowledgements, training completions, incident records, and evidence, each version-pinned at the moment it was current and kept six years from creation or from the date it was last in effect, whichever is later

54 controls. One evidence base.

A sample of how the heaviest controls are automated.

§164.308(a)(1)

Security management process

ePHI discovery + risk register with dated approvals

§164.308(a)(5)

Security awareness and training

Training campaigns + per-person completion evidence

§164.308(b)(1)

Business associate contracts

Vendor register + agreement status per vendor

§164.310(d)(1)

Device and media controls

Policy library + media disposal records on file

§164.312(a)(1)

Access control

Root-account restriction and deprovisioning tests

§164.312(b)

Audit controls

CloudTrail enablement, log validation, retention tests

Frequently asked

What do we send a customer who asks for HIPAA proof?

Four things, and the platform produces all of them as you go rather than the week you are asked. A trust portal page you send as a link, carrying the frameworks you run, your posture, and the documents you have chosen to publish. An audit binder, where every policy version, document, test result and written determination is pinned at the moment it was current, exported as a packet or opened through a magic link so a reviewer works in their own portal instead of inside your tenant. A current risk analysis carrying a dated management approval. And the population records a reviewer samples from: training completions per person, policy acknowledgments per person, and Business Associate Agreements per vendor. Most healthcare buyers ask for a SOC 2 report alongside it, which the same evidence base produces.

Which parts of HIPAA does this cover?

The Security Rule (45 CFR Part 164, Subparts A and C) is the control program: 18 standards and 36 implementation specifications across the Administrative, Physical, and Technical Safeguards, plus the organizational requirements at §164.314 and the documentation requirements at §164.316. Breach notification (§164.400 to §164.414) is a seeded control set too, not merely a policy: the notification duties, the four-factor breach risk assessment that decides whether you notify at all, and the log of breaches affecting fewer than 500 individuals each carry their own control and their own evidence. Note that the individual notice is due without unreasonable delay and no later than 60 calendar days after discovery, which is a deadline rather than a grace period. The Privacy Rule (minimum necessary, notice of privacy practices, accounting of disclosures) is advisory here: the AI vCISO answers on it, but it is not run as a control program. Which of these are yours depends on what you are. A business associate, which is what most health technology companies are, owes the Security Rule, the breach notification duties, and its own subcontractor agreements. A covered entity owes all of that plus the Privacy Rule administrative requirements at §164.530: a privacy official, privacy training, a sanctions policy, and a complaints process. Those stay yours to run.

What does "Addressable" actually require?

An implementation specification marked Addressable is not optional, and it is never simply not applicable. You assess whether it is reasonable and appropriate for your environment, and where it is not, you document why in writing and implement an equivalent alternative measure if one is reasonable and appropriate. §164.306(d)(3) requires that written rationale, and §164.316(b)(2)(i) requires you to keep it for six years from creation or from the date it was last in effect, whichever is later. Comply keeps that determination as a versioned document on the same review cycle as your policies, so the decision is still retrievable years later instead of living in one person's memory. Encryption is the specification this comes up on most: §164.312(a)(2)(iv) and §164.312(e)(2)(ii) are both Addressable rather than Required, which surprises people. It is still the one to implement anyway, because ePHI encrypted to HHS guidance, where the key was not compromised, is not a reportable breach at all.

Does HIPAA work carry over to SOC 2 or ISO 27001?

Yes, and it is most of the work. The Technical Safeguards at §164.312 overlap heavily with SOC 2 CC6 and CC7 and ISO 27001 Annex A 8.x: the same encryption, access control, and audit logging tests satisfy all three, collected once. Cross-framework mapping means one control set sits behind every framework, so adding HIPAA to a running SOC 2 program is largely a scoping and documentation exercise rather than a second evidence collection.

Ready to get HIPAA done without the scramble?

See how Strac Comply runs your HIPAA program: continuous evidence, AI vCISO, and an audit binder your auditor will actually thank you for.

Book a Demo

Not ready for a call?

Get pricing and a free readiness assessment

Tell us where to send it. We’ll show you what Strac Comply costs and where your gaps are. No call required.

No spam. Your data is protected by our own DLP. Unsubscribe anytime.