HIPAA Compliance
for Covered Entities and Business Associates
HIPAA governs how Protected Health Information is handled in the United States. Basenorm centralises the Privacy Rule, Security Rule, Breach Notification Rule and Business Associate oversight, with controls mapped to the Unified Control Library and evidence collected continuously.
Privacy Rule and PHI Governance
Document uses and disclosures, minimum necessary standards, notices of privacy practices and patient rights, with every process linked to the Governance Graph.
- PHI inventory across systems, suppliers and workflows
- Notice of Privacy Practices management
- Minimum necessary standard and access controls
- Patient rights: access, amendment, accounting of disclosures
- Authorisations, consents and restriction tracking
Three Safeguard Categories
HIPAA Security Rule Compliance
PHI Data Flow
Processing Activities
ePHI flows require BAA coverage
Security Rule Safeguards
Implement administrative, physical and technical safeguards for electronic PHI, with control mappings to ISO 27001, NIST 800-53 and HITRUST.
- Risk analysis and risk management programme
- Administrative safeguards: policies, workforce training, sanctions
- Physical safeguards: facility access and device controls
- Technical safeguards: access, audit, integrity and transmission
- Cross-mapping with ISO 27001, NIST CSF and HITRUST
Breach Notification and Business Associates
Operate structured breach assessment and notification workflows, manage Business Associate Agreements and maintain ongoing oversight of downstream vendors.
- Four-factor breach risk assessment workflow
- Notifications to individuals, HHS and media within HIPAA timelines
- Business Associate Agreement lifecycle management
- Subcontractor oversight and chain of trust
- Lessons learned and control adjustments
BAA Management
Business Associate Agreement tracking
Ready to operationalise HIPAA?
Join covered entities and business associates using Basenorm to manage HIPAA across privacy, security, breach notification and vendor oversight.