info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeGRCHIPAA

HIPAA

There is no HIPAA certification. We deliver the §164.308(a)(1)(ii)(A) risk analysis and §164.308(a)(8) technical evaluation the Security Rule actually requires.

The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law governing how protected health information (PHI) is used, disclosed and safeguarded. It applies to covered entities — healthcare providers, health plans and clearinghouses — and to the business associates that handle PHI on their behalf.

There is no such thing as HIPAA certification. The US Department of Health and Human Services does not recognize, endorse or accredit any HIPAA certification, and no certificate provides a safe harbor in an OCR investigation. What the Security Rule does require is a documented risk analysis and a periodic technical evaluation — and that is what we deliver.

HIPAA compliance
HIPAA compliance
HIPAA compliance

HIPAA applies to covered entities — such as healthcare providers, health plans and clearinghouses — and their business associates.

What a HIPAA Security Rule assessment covers

  • §164.308(a)(1)(ii)(A) risk analysis — an accurate and thorough assessment of risks to the confidentiality, integrity and availability of ePHI
  • §164.308(a)(8) periodic technical evaluation — technical testing of the systems that create, receive, maintain or transmit ePHI
  • Administrative, physical and technical safeguards, each mapped to the required or addressable specification it satisfies
  • Privacy Rule obligations: minimum necessary, notice of privacy practices, patient access and accounting of disclosures
  • Business associate agreements and subcontractor flow-down
  • Breach Notification Rule procedures, including the four-factor risk assessment
  • Workforce training, sanction policy and documentation retention

What you receive

  • A written risk analysis that satisfies the §164.308(a)(1)(ii)(A) documentation requirement
  • Findings mapped to the specific safeguard each one affects, with remediation priorities
  • A risk management plan you can put in front of an OCR investigator or an enterprise customer
  • Where technical testing is in scope, a penetration test report and signed attestation letter (see Penetration Testing)

Who it is for

Digital health and telehealth platforms, EHR and practice management vendors, medical billing and revenue cycle companies, health plans, and any business associate whose covered-entity customers are asking for evidence before renewing a BAA.

Talk to us about certification or a penetration test

Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.