Health Insurance Portability and Accountability Act compliance software
Run the required risk analysis, evidence administrative, physical and technical safeguards, and manage business associate obligations.
What HIPAA requires
HIPAA governs how protected health information is handled by covered entities — health plans, healthcare clearinghouses and most healthcare providers — and by the business associates that process PHI on their behalf. The Security Rule sets out administrative, physical and technical safeguards; the Privacy Rule governs use and disclosure; the Breach Notification Rule sets reporting duties.
The Security Rule requires a documented risk analysis. This is the most frequently cited deficiency in enforcement actions, and it must be a genuine, periodically refreshed assessment of risks to the confidentiality, integrity and availability of electronic PHI — not a one-off checklist.
Artificial intelligence has sharpened the exposure. Clinical decision-support tools, transcription services and scheduling assistants routinely ingest PHI, and staff pasting patient information into consumer chatbots moves regulated data outside the controlled environment entirely. Each AI system touching PHI needs to appear in the risk analysis and, where a vendor is involved, be covered by a business associate agreement.
Who it applies to
- Healthcare providers, health plans and clearinghouses
- Business associates processing PHI on behalf of covered entities
- Software vendors whose products handle electronic PHI
- Organisations deploying AI tools that process patient information
At a glance
- Regulator: HHS Office for Civil Rights
- Main rules: Security Rule, Privacy Rule, Breach Notification Rule
- Safeguard categories: Administrative, Physical, Technical
- Core requirement: Documented, periodically updated risk analysis
How GRCLens supports HIPAA
HIPAA runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Security Rule risk analysis
Conduct and document the required risk analysis against electronic PHI, with findings tracked to remediation.
Safeguard assessment
Assess administrative, physical and technical safeguards individually, recording implementation status and evidence.
Business associate tracking
Maintain a register of business associates and their agreements alongside vendor risk assessments.
AI systems in scope
Record AI tools that process PHI as assessable components, so they appear in the risk analysis rather than escaping it.
HIPAA frequently asked questions
How often must a HIPAA risk analysis be updated?
HIPAA does not fix a calendar interval, but the analysis must be reviewed and updated periodically and whenever there is a material change to the environment — such as adopting a new system that processes electronic PHI.
Do AI tools that process patient data fall under HIPAA?
Yes. If an AI system creates, receives, maintains or transmits electronic PHI, it falls within scope, and a vendor providing it will generally be a business associate requiring an agreement.
Does HIPAA apply outside the United States?
HIPAA is US law, but it reaches any organisation acting as a covered entity or business associate in relation to US protected health information, including service providers located abroad.
One platform, many obligations
Talk to us about HIPAA
Security Solution Consultants provides HIPAA compliance advisory services alongside the platform, so you can combine tooling with hands-on expertise.
Contact us