Who it's for
Startups facing their first health-system or enterprise security questionnaire, teams that inherited a product with no compliance record, and research platforms moving from IRB-covered use to commercial use. We are engineers who have built HIPAA-covered systems, so the advice is specific to software rather than generic policy.
What's included
- Gap assessment — administrative, physical, and technical safeguards reviewed against the Security Rule and Privacy Rule, with findings rated by risk.
- Risk analysis — the documented risk analysis the Security Rule requires, written so you can maintain it.
- Technical safeguards review — encryption, access control, audit logs, backups, logging, and secrets handling, checked in the running system rather than on paper.
- Vendor and BAA inventory — every service that touches PHI, whether a Business Associate Agreement exists, and what to do where one does not.
- Policies and procedures — right-sized for your stage, not a binder copied from a hospital.
- Verification — after remediation we test that the policy and the system agree, and issue a memo you can hand to a customer.
- SOC 2 and questionnaire readiness — mapping your HIPAA controls to what security reviewers will ask next.
How it runs
- Scope and evidence requestConfirm systems in scope and collect architecture, policies, vendor list, and access.
- AssessmentInterviews with engineering and leadership, configuration review, and a read of the code paths that handle PHI.
- Findings and roadmapA risk-rated report with a sequenced remediation plan and effort estimates.
- VerificationRe-test after remediation and a written verification memo.
Questions
Is this a HIPAA certification?
There is no official HIPAA certification. What we provide is an independent assessment and a verification memo stating what we reviewed and what we found, which is what customers and partners actually ask for.
Do we need a BAA with you?
Only if exposure to PHI is unavoidable. We work from read-only access and de-identified or synthetic data wherever possible, and we sign a Business Associate Agreement before any PHI is involved.
How does this relate to SOC 2?
HIPAA is a legal requirement for covered entities and business associates; SOC 2 is an audit standard customers may demand. The controls overlap heavily, so we map the HIPAA work to SOC 2 criteria and tell you how far you are from an audit.
Related services
Scope it in 30 minutes
Book a scoping call and we'll name the smallest engagement that moves you forward. Most teams start with the fixed-scope Initial Audit.
Book a 30-min scoping callPrefer to write? Send a short note.