Regulatory & Privacy · HIPAA Security & Privacy Rules
HIPAA compliance assessments for the health-tech teams that touch PHI.
We assess your safeguards against the HIPAA Security, Privacy, and Breach Notification Rules, run the Security Risk Analysis the law requires, and give you evidence your healthcare customers will accept.
A HIPAA compliance assessment is an independent review of how your administrative, physical, and technical safeguards measure up against the HIPAA Security and Privacy Rules, including the Security Risk Analysis the law requires. FinAudit CPA assesses your handling of protected health information and attests to where you stand, so your healthcare customers can trust you with their patients’ data.
Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)
Last updated July 2026
What HIPAA compliance actually requires
HIPAA is the Health Insurance Portability and Accountability Act, and for a technology company the part that bites is the set of rules governing protected health information. Three rules do most of the work. The Privacy Rule governs how you may use and disclose PHI in any form. The Security Rule governs how you protect electronic PHI, usually written ePHI. The Breach Notification Rule tells you exactly what to do, and how fast, when protected data is exposed.
The Security Rule organizes its requirements into three families of safeguards. Administrative safeguards cover the policies, training, workforce clearance, and risk management that steer your program. Physical safeguards cover facility access, device controls, and how you handle and dispose of hardware that stores ePHI. Technical safeguards cover access control, audit logging, integrity protection, and encryption of data in transit and at rest. You have to address every required specification and make a documented, defensible decision on each addressable one.
At the center of the Security Rule sits one non-negotiable task: the Security Risk Analysis. It is the accurate, thorough assessment of the risks to the confidentiality, integrity, and availability of the ePHI you hold. Regulators treat a missing or shallow risk analysis as the single most common HIPAA failure, and it is the first document an investigator asks for after an incident. Everything else in your program should trace back to it.
There is no such thing as a government HIPAA certificate. What protects you is a documented Security Risk Analysis and safeguards a stranger’s privacy officer can read and believe. We build that record to hold up.
Who must comply, and when
HIPAA divides the world into two roles. A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically — hospitals, clinics, insurers. A business associate is any company that creates, receives, maintains, or transmits PHI on behalf of a covered entity. If you run a SaaS platform, an analytics tool, a scheduling system, or a hosting service that touches patient data for a healthcare customer, you are almost certainly a business associate.
That distinction matters because since the HITECH Act, business associates are directly liable under the Security Rule and much of the Privacy Rule. You cannot hide behind your customer’s compliance program. You must run your own Security Risk Analysis, implement your own safeguards, and answer to regulators for your own gaps. HITECH also strengthened the Breach Notification Rule and raised the penalties, which is why enterprise health customers now insist on evidence before they connect you to real PHI.
The trigger is usually commercial. A hospital system or a digital-health buyer sends a vendor security review, and a signed Business Associate Agreement plus proof of your safeguards becomes a condition of the contract. The honest advice: start before the questionnaire arrives. A Security Risk Analysis and the remediation it surfaces take time, and a deal stalled on missing HIPAA evidence is an expensive way to learn that.
Covered entity vs business associate: which are you?
Most health-tech companies are business associates, not covered entities, and that changes what you owe. Both roles carry direct HIPAA obligations since HITECH, but the reason PHI is in your hands is different.
| Covered Entity | Business Associate | |
|---|---|---|
| Who it is | Health plans, clearinghouses, and providers that bill electronically | Vendors that handle PHI on a covered entity’s behalf, including most health-tech SaaS |
| Why they hold PHI | They deliver or pay for care directly | They provide a service to a covered entity that involves PHI |
| Governing agreement | Notice of Privacy Practices to patients | A Business Associate Agreement (BAA) with each covered entity |
| Security Rule duty | Full compliance, including the Security Risk Analysis | Full compliance directly, including its own Security Risk Analysis |
| Where liability sits | Directly with the entity | Directly with the associate since HITECH, plus subcontractor flow-down |
How our HIPAA assessment runs
You always know where you are and what comes next. The Security Risk Analysis anchors the whole engagement, not an afterthought bolted on at the end.
-
01
Scoping
We map where PHI and ePHI live across your systems, confirm whether you are a business associate, and agree which rules and systems are in scope. You get a fixed fee before we begin.
-
02
Security Risk Analysis
We run the risk analysis the Security Rule requires, identifying threats to the confidentiality, integrity, and availability of your ePHI and rating each risk honestly.
-
03
Safeguards review
We assess your administrative, physical, and technical safeguards against each required and addressable specification, and document the reasoning behind every addressable decision.
-
04
Gap and remediation plan
We hand you a plain-language risk management plan that ranks the gaps, so you fix the exposures that matter most before they fix themselves the hard way.
-
05
BAA and policy check
We review your Business Associate Agreements, breach response procedures, and workforce policies so the paperwork matches what your systems actually do.
-
06
Attestation and report
We document where you stand against HIPAA, run it through independent quality review, and issue an assessment report and attestation you can share with customers.
What you get, and how long it takes
You receive a documented Security Risk Analysis, a safeguards assessment covering the administrative, physical, and technical requirements, a ranked risk management plan, and a HIPAA compliance attestation from a licensed CPA firm. Read together, they answer the question every healthcare customer is really asking: can we hand you patient data without inheriting your risk. That package is what a privacy officer wants to see attached to your Business Associate Agreement.
Timing depends on where you start and how much PHI you touch. A focused assessment for a single product with reasonably mature controls often runs a few weeks from kickoff to report. If the Security Risk Analysis surfaces meaningful gaps, the remediation you choose to do sets the pace, not our fieldwork. Because HIPAA compliance is an ongoing duty rather than a one-time event, most clients repeat the assessment annually or after any significant change to how their systems handle ePHI.
What actually drives the cost
We quote a fixed engagement fee, so you will not see a surprise hourly bill. The number depends on real factors, not guesswork:
How much PHI you touch
A single product with one data flow costs less to assess than a platform where ePHI moves across many services, integrations, and subcontractors.
Systems and environments
More applications, cloud accounts, and hosting arrangements mean more safeguards to review and more evidence to examine.
Control maturity
If your safeguards already run cleanly, the assessment moves quickly. If the risk analysis exposes gaps, the effort shifts to remediation you decide to take on.
Scope of rules
A Security Rule and Security Risk Analysis engagement is narrower than one that also assesses Privacy Rule use-and-disclosure practices and breach procedures in depth.
Why run your HIPAA assessment with FinAudit CPA
Many firms will sell you a HIPAA gap review. Fewer bring a licensed CPA who reads both your control environment and the business behind it. That matters when your platform handles patient billing, claims, or funds, because an assessor who understands the numbers and the safeguards spots risks a checklist vendor walks past. We assess against the actual language of the Security and Privacy Rules, not a watered-down template, and we tell you plainly where you stand.
You also get senior attention that stays on your file as the engagement grows, fixed scope you can budget around, and a delivery model that keeps work moving across time zones. Because so many HIPAA safeguards overlap with other frameworks, we map your controls once so the same evidence supports a SOC 2 report or ISO 27001 certification later. You assess once and reuse the work, instead of paying to rebuild nearly identical evidence for every buyer who asks.
Pair your HIPAA assessment with
- SOC 2, when enterprise health buyers want a CPA-signed report on your security controls alongside your HIPAA attestation
- ISO 27001, when international customers want a recognized information-security certification
- VAPT, to show buyers you actively test the technical safeguards your assessment describes
- A Business Associate Agreement review, so your contracts match the safeguards your systems actually run
HIPAA Compliance Assessment · questions buyers ask
No. There is no official government HIPAA certification, and no federal agency issues a "HIPAA certified" seal. Any vendor claiming to hand you a government certificate is misreading the law. What exists is a compliance assessment and attestation: FinAudit CPA assesses your safeguards and Security Risk Analysis against the HIPAA rules and documents where you stand. That documented evidence, not a badge, is what your healthcare customers actually accept.
A HIPAA security risk assessment, or Security Risk Analysis, is the accurate and thorough evaluation the Security Rule requires of the risks to the confidentiality, integrity, and availability of the ePHI you hold. It identifies threats and vulnerabilities across your administrative, physical, and technical safeguards and rates each risk. Regulators treat a missing or shallow risk analysis as the most common HIPAA failure, so we make it the anchor of every engagement.
Covered entities — health plans, clearinghouses, and providers that bill electronically — must comply, and so must business associates. A business associate is any company that creates, receives, maintains, or transmits PHI for a covered entity. If your software touches patient data for a healthcare customer, you are almost certainly a business associate, and since HITECH you are directly liable under the Security Rule for your own compliance.
A covered entity delivers or pays for care directly, such as a hospital, clinic, or insurer. A business associate provides a service to a covered entity that involves PHI, which describes most health-tech SaaS. The covered entity gives patients a Notice of Privacy Practices; the business associate signs a Business Associate Agreement. Since HITECH, both carry direct HIPAA liability, so being "just the vendor" no longer shields you.
Yes, if you handle PHI for a covered entity. A Business Associate Agreement is the contract that binds you to protect PHI and defines each party’s duties, and HIPAA requires one before you touch the data. If you use subcontractors who also see PHI, you must flow the same obligations down to them. We review your BAAs so the promises in the contract match the safeguards your systems actually run.
A SOC 2 audit is a CPA attestation against the AICPA Trust Services Criteria, and it applies to any service organization. A HIPAA assessment measures your safeguards against a specific federal law governing protected health information, and it centers on the required Security Risk Analysis. Many controls overlap, so we map them once. Health buyers often want both: SOC 2 for general security assurance and HIPAA evidence for the PHI specifically.
HIPAA compliance is an ongoing duty, not a one-time event. The Security Rule expects you to review and update your Security Risk Analysis periodically and whenever something significant changes — a new product, a major architecture shift, an acquisition, or a security incident. Most of our clients reassess annually so their documentation stays current and defensible, and so they can hand customers evidence that reflects how their systems work today.
No, because no such official certificate exists. FinAudit CPA issues a HIPAA compliance assessment report and attestation from a licensed US CPA firm, documenting your Security Risk Analysis, your safeguards, and where you stand against the HIPAA rules. That report is what your healthcare customers and their privacy officers read to decide whether they can trust you with PHI. It carries the weight of an independent CPA assessment, not a marketing badge.
Pair it with
Audit once, comply many.
ISO/IEC 27001 Certification
The international security certificate your global customers recognize on sight.
SOC 2 Audit
The report SaaS buyers ask for first — done by a licensed CPA firm.
VAPT (Penetration Testing)
We find the holes, then prove which ones an attacker can actually walk through.