Skip to main content
HIPAA

HIPAA Compliance
for Covered Entities and Business Associates

HIPAA governs how Protected Health Information is handled in the United States. Basenorm centralises the Privacy Rule, Security Rule, Breach Notification Rule and Business Associate oversight, with controls mapped to the Unified Control Library and evidence collected continuously.

Privacy Rule and PHI Governance

Document uses and disclosures, minimum necessary standards, notices of privacy practices and patient rights, with every process linked to the Governance Graph.

  • PHI inventory across systems, suppliers and workflows
  • Notice of Privacy Practices management
  • Minimum necessary standard and access controls
  • Patient rights: access, amendment, accounting of disclosures
  • Authorisations, consents and restriction tracking

Three Safeguard Categories

Administrative
Risk AnalysisWorkforce TrainingSecurity Officer
Technical
Access ControlEncryptionAudit Logs
Physical
Facility AccessDevice SecurityDisposal

HIPAA Security Rule Compliance

PHI Data Flow

Covered EntityHealthcare Provider
ePHI SystemsEHR, Databases
Business AssociateCloud Vendor

Processing Activities

Patient RecordsProtected
Claims ProcessingProtected
AnalyticsDe-identified

ePHI flows require BAA coverage

Security Rule Safeguards

Implement administrative, physical and technical safeguards for electronic PHI, with control mappings to ISO 27001, NIST 800-53 and HITRUST.

  • Risk analysis and risk management programme
  • Administrative safeguards: policies, workforce training, sanctions
  • Physical safeguards: facility access and device controls
  • Technical safeguards: access, audit, integrity and transmission
  • Cross-mapping with ISO 27001, NIST CSF and HITRUST

Breach Notification and Business Associates

Operate structured breach assessment and notification workflows, manage Business Associate Agreements and maintain ongoing oversight of downstream vendors.

  • Four-factor breach risk assessment workflow
  • Notifications to individuals, HHS and media within HIPAA timelines
  • Business Associate Agreement lifecycle management
  • Subcontractor oversight and chain of trust
  • Lessons learned and control adjustments

BAA Management

2/3 Active
Cloud Storage Provider
BAA SignedActive
EHR Platform
BAA SignedActive
Analytics Service
BAA RequiredReview
BAA Coverage67%

Business Associate Agreement tracking

Ready to operationalise HIPAA?

Join covered entities and business associates using Basenorm to manage HIPAA across privacy, security, breach notification and vendor oversight.

Frequently Asked Questions

Explore frequently asked questions about HIPAA and related compliance topics.