Health information

HIPAA and HITRUST Readiness

HIPAA is an obligation to follow the Privacy Rule and the Security Rule. HITRUST is a private certification you can hand to a customer.

Who this applies to. Covered entities, business associates, and health technology companies handling protected health information.

What HIPAA & HITRUST actually asks of you

HIPAA is a regulation, not a certification. There is no body that issues a HIPAA certificate. What the law asks is that you follow the Privacy Rule, which governs how protected health information may be used and disclosed, and the Security Rule, which sets the administrative, physical, and technical safeguards for that information in electronic form. Compliance is a state you maintain and can evidence, not a document you obtain.

The two rules are different obligations and organizations routinely resource only one of them. Security teams tend to own the Security Rule and treat the Privacy Rule as somebody else’s problem, which is how minimum necessary, patient rights, and disclosure accounting end up unowned.

HITRUST is the commercial answer to the fact that HIPAA gives you nothing to hand over. It is a private, paid certification scheme, not a government programme, and it incorporates HIPAA requirements alongside other authoritative sources. Health systems and large payers increasingly ask for it by name, which is generally the only reason to pursue it.

So the sequencing question is who is asking. A regulator asks whether you follow the rules. A prospective customer asks for HITRUST or SOC 2. The underlying safeguards overlap heavily, so it is worth answering that before the control work starts rather than after.

The engagement

What readiness covers

Security Rule risk analysis

The accurate and thorough risk analysis the Security Rule requires, documented as a record with a date rather than as a one-time exercise. This is the most commonly cited deficiency in enforcement actions.

Safeguard implementation

Administrative, physical, and technical safeguards implemented and documented, with addressable specifications either implemented or justified in writing.

Privacy Rule practices

The half of HIPAA that security teams tend not to own: permitted uses and disclosures, minimum necessary, patient access and amendment rights, accounting of disclosures, and the notice of privacy practices. A strong Security Rule posture does not cover any of it.

Business associate management

Agreements in place with the vendors that handle protected health information on your behalf, and a process for keeping them current as the vendor set changes.

Breach notification readiness

A documented process for assessing and reporting a breach, rehearsed before it is needed rather than drafted during one.

HITRUST readiness

Scoping the assessment, mapping controls to requirement statements, and preparing the evidence an authorised external assessor will test.

What you are left holding

Deliverables

  • Documented Security Rule risk analysis and risk management plan
  • Policy and procedure set covering the required safeguards
  • Business associate agreement inventory and gap list
  • Breach notification runbook
  • HITRUST scoping and control mapping, where in scope

FAQ

HIPAA & HITRUST questions we get asked

Can we be HIPAA certified?

No, and neither can anyone else. HIPAA is a regulation enforced by the Department of Health and Human Services. There is no certification scheme and no certificate. The obligation is to follow the Privacy Rule and the Security Rule, and what you can hold is documented evidence that you do.

What is HITRUST, and do we need it?

HITRUST is a private, commercially available certification aimed at HIPAA and healthcare organizations. It is run by a company, it is paid for, and it exists because HIPAA itself gives you nothing to hand a customer. It incorporates HIPAA requirements alongside other authoritative sources.

You need it if a customer is asking for it, and health systems and large payers increasingly do. If nobody has asked, the money is usually better spent on the underlying safeguards, which you are obliged to have either way.

Do you perform the HITRUST assessment?

No. A HITRUST validated assessment is performed by an authorised external assessor organisation. We prepare you for it.

Start with scope, not with a proposal

The first conversation is about what is actually in scope, because that governs the cost of everything after it.

Talk to an expert