HIPAA Compliance
For healthcare organizations and their vendors

Delivered by a cybersecurity firm, not a compliance shop.
Led by a CISSP, CISA, and CISM certified security leader.
Risk Analysis. Remediation. Policies. Business Associates. Ongoing Compliance.
HIPAA basics

What is HIPAA compliance?

The Health Insurance Portability and Accountability Act (HIPAA) sets national rules for protecting health information. It applies to covered entities, such as providers, health plans, and clearinghouses, and to the business associates that create, receive, store, or transmit protected health information (PHI) on their behalf, including many SaaS and IT vendors.
There is no official HIPAA certification. Compliance is enforced by the HHS Office for Civil Rights (OCR), and it starts with an accurate, thorough risk analysis of where your electronic PHI lives and how it could be exposed.
HIPAA in 2026

Where the Security Rule stands today

A major update is proposed

In January 2025, HHS proposed the first major overhaul of the HIPAA Security Rule in two decades. As of 2026 it is not yet final, and the finalization date has moved more than once.

What it would change

Most safeguards would become required rather than addressable, including encryption of ePHI, multi-factor authentication, an asset inventory and network map, regular vulnerability scanning and penetration testing, and the ability to restore critical systems within 72 hours.

What OCR enforces now

The current rule is fully in force. OCR continues to bring enforcement actions, and a missing or outdated risk analysis is one of the most common findings.

The proposed rule largely writes down what good security already looks like.
Getting there now lowers your risk either way.

Why it matters

Protect patients, your reputation, and your revenue

Lower breach risk

Stop the incidents that become headlines
Healthcare is a top ransomware target. Real safeguards, not just policies, keep PHI out of attackers’ hands.

Enforcement readiness

Be ready if OCR comes calling
A current risk analysis, documented safeguards, and evidence of follow-through are what investigators ask for first.

Healthcare sales

Get your business associate agreements signed faster
Hospitals and health plans vet vendors before signing a BAA. A strong HIPAA program shortens that review, so you win and keep healthcare customers.

Ready for the new rule

Get ahead of the proposed Security Rule
Encryption, MFA, asset inventories, and tested recovery put you in position when the update is finalized.
The HIPAA rules

Four parts every program must cover

HIPAA compliance is not one checklist. It spans privacy, security, breach response, and the vendors who handle PHI for you.
Privacy Rule

How PHI is used and shared

Permitted uses and disclosures, minimum necessary access, and patients’ rights to their own information.
Security Rule

How ePHI is protected

Administrative, physical, and technical safeguards, starting with a documented risk analysis.
Breach Notification

What happens when PHI leaks

Assessing incidents and notifying individuals, HHS, and in larger breaches the media, within required timeframes.
Business Associates

Who else handles your PHI

Business associate agreements and oversight of the vendors and subcontractors that touch PHI.
Our HIPAA approach

Cybersecurity at our core. Compliance built on it

Compliance should validate good cybersecurity, not substitute for it.

InfoGuard has protected healthcare organizations for years, including a multi-location healthcare provider we have supported for more than 15 years, with secure networks and practical HIPAA programs.

Real healthcare experience

Programs that fit how care is delivered
We understand clinics, multi-site practices, and health tech vendors, so safeguards protect PHI without slowing down care.

Risk analysis that holds up

A risk analysis OCR would accept
We follow HHS guidance to produce an accurate, thorough risk analysis, then turn it into a prioritized remediation plan.

Hands-on senior leadership

Senior experts on your engagement, start to finish
Senior practitioners work alongside your team, not a junior analyst running a checklist.

One effort, multiple frameworks

Do the work once, reuse it for SOC 2 and more
We map your HIPAA safeguards to SOC 2, ISO 27001, and other frameworks, so customer security reviews reuse the same evidence.

Your compliance investment should deliver more than checklists and documentation.
It should improve your cybersecurity as well.

How we help

From risk analysis to ongoing compliance

01

Scoping & PHI Mapping

We identify where PHI and ePHI are created, stored, and sent, across systems, locations, devices, and vendors.
02

Security Risk Analysis

We assess threats and vulnerabilities to ePHI, rate the risks, and document the analysis the Security Rule requires.
03

Remediation & Safeguards

We implement the administrative, physical, and technical safeguards your risks call for, from MFA and encryption to backups and logging.
04

Policies & Business Associates

We write practical policies and procedures, review your business associate agreements, and assess the vendors that handle PHI.
05

Training & Readiness

We train your workforce and run a readiness review that mirrors an OCR investigation, so your evidence is ready when it is needed.
06

Ongoing Compliance

We keep your risk analysis, safeguards, and documentation current as your systems change, and support you through incidents.
FAQ

HIPAA questions, answered

Requirements

No. HHS does not certify organizations or endorse any HIPAA certification. What matters is a documented program: a current risk analysis, implemented safeguards, policies, training, and business associate agreements.
Yes. Business associates are directly liable for complying with the Security Rule and parts of the Privacy and Breach Notification Rules, and they must sign business associate agreements with the covered entities they serve.
HIPAA requires an accurate and thorough risk analysis that is kept current. In practice that means reviewing it at least annually and whenever your systems, locations, or vendors change significantly.
You must assess the incident and, for breaches of unsecured PHI, notify affected individuals without unreasonable delay and no later than 60 days after discovery. HHS must also be notified, and breaches affecting 500 or more residents of a state or jurisdiction require notifying prominent media as well.
No. The current rule is enforced today, and the proposed changes mostly codify practices such as encryption, MFA, and tested backups that already reduce breach risk. Starting now spreads the work out and lowers risk either way.

Scope, timing, and cost

Often, yes. HIPAA is the legal requirement, while many healthcare customers also ask for a SOC 2 report as proof. We map the two together so one set of controls and evidence serves both.
It depends on your size, locations, and current safeguards. A risk analysis typically takes weeks, and remediation follows a prioritized plan over the following months.
Cost depends on the number of locations, systems, and vendors in scope and how much remediation is needed. There is no flat fee. We provide a firm quote after an initial assessment.
Yes. Small and mid-size practices face the same rules with far fewer resources, and that is exactly where InfoGuard helps most.
Cybersecurity first

A checkbox compliance provider won't cut it

You need real cybersecurity expertise to keep patient data safe from ransomware and breaches, not just a binder of policies.
InfoGuard is a cybersecurity firm first. Explore our cybersecurity services →
Next step

Tell us where you stand

Tell us about your organization and where PHI lives. We’ll reply with next steps, whether that’s a security risk analysis, a remediation plan, or a combined HIPAA and SOC 2 program.