Framework · HIPAA
HIPAA continuous. Not HIPAA compliant once a year.
The Security Rule, Privacy Rule and Breach Notification Rule of the US HIPAA law, for covered entities and their business associates, monitored continuously.
HIPAA (Health Insurance Portability and Accountability Act) is the US federal law governing the protection of health information (PHI). It applies to covered entities (health plans, providers, clearinghouses) and their business associates, and is enforced by the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS). A point-in-time risk analysis conducted once a year is not enough: controls must operate continuously.
Key facts
- 3 rules: Security Rule, Privacy Rule, Breach Notification Rule.
- 3 safeguard families: administrative, physical and technical, in the Security Rule.
- 60 days: deadline to notify HHS and patients after a breach is discovered.
- BAA: a Business Associate Agreement is required with every third party that handles PHI.
What HIPAA requires
The Security Rule defines administrative, physical and technical safeguards. The Privacy Rule governs PHI use and disclosure. The Breach Notification Rule requires HHS and patient notification within 60 days.
- Administrative safeguards: risk analysis, workforce training, contingency planning
- Physical safeguards: facility access, workstation use, device controls
- Technical safeguards: access control, audit controls, integrity, transmission security
- Privacy Rule: use and disclosure of PHI
- Breach Notification Rule: HHS and patient notification within 60 days of discovery
- Business associates: an agreement (BAA) with every third party and tracking of its compliance posture
What Sentrix provides for HIPAA
Risk analysis and management
Sentrix maintains a living risk analysis tied to your actual infrastructure, updated as your systems change rather than rebuilt annually from scratch.
BAA management
Track all Business Associate Agreements, monitor covered vendor compliance continuously, and get an alert when a BAA partner's SOC 2 lapses or their security posture drifts from your requirements.
PHI data flow mapping
Automated inventory of where PHI exists across your systems, which integrations touch it, and which controls apply to each data store. Required for both HIPAA risk analyses and audits.
Breach notification workflow
Automated breach classification, 60-day notification deadline tracker, HHS notification documentation, and patient notification letter templates, ready before OCR asks.
Workforce training tracking
HIPAA requires regular security awareness training for the workforce. Sentrix tracks completion, stores certificates as evidence, and alerts when training cycles expire.
SOC 2 and HIPAA combined
HIPAA does not require a formal audit, but healthcare SaaS companies need SOC 2 for enterprise customers. Sentrix runs both from one evidence set.
Crosswalks
- SOC 2: HIPAA controls map to the Trust Services Criteria.
- ISO 27001: pre-mapped to the controls shared with HIPAA.
- Law 25: incident classification and notification for healthcare organizations operating in Québec.
- GDPR: data subject rights and DPIAs for EU operations.
Further reading
Healthcare and life sciences solution.
See your HIPAA posture on your real stack.
Frequently asked questions
- Who does HIPAA apply to?
- HIPAA applies to covered entities, meaning health plans, healthcare providers and clearinghouses, and to their business associates, the third parties that create, receive, maintain or transmit protected health information (PHI) on their behalf. Every business associate relationship must be governed by a Business Associate Agreement (BAA), and the partner's compliance posture must be tracked.
- What is the breach notification deadline under HIPAA?
- The Breach Notification Rule requires notification to the Department of Health and Human Services (HHS) and to affected patients within 60 days of discovering the breach. Sentrix provides automated breach classification, a 60-day deadline tracker, HHS notification documentation and patient notification letter templates, ready before the Office for Civil Rights asks for them.
- Does HIPAA require a formal audit or certification?
- No. HIPAA does not require a formal audit or certification, but healthcare SaaS companies need a SOC 2 report for their enterprise customers. Sentrix runs both from one evidence set: HIPAA controls map to the SOC 2 Trust Services Criteria, and the risk analysis required by the Security Rule stays current as your systems change.
Related pages
Framework · SOC 2
SOC 2 is a continuous program, not a one-time audit
AICPA attestation framework across five Trust Services Criteria categories, reported as Type I or Type II. Continuous evidence, drift alerts, auditor access.
Framework · ISO 27001:2022
ISO 27001:2022: from ISMS to certification in one program
The international standard for information security management systems: clauses 4 to 10, 93 Annex A controls, and a two-stage certification audit.
Framework · Law 25
Law 25: PIAs, incidents, access and portability, documented
Québec's private-sector privacy law, in full force since September 2023: privacy impact assessments, confidentiality incidents, access rights and portability.
Framework · GDPR
GDPR: Article 32, DPIAs and data subject rights, all mapped
The EU regulation for any organization processing data of EU residents: lawful basis, DPIAs, data subject rights, Article 32 measures and processor contracts.
Let's talk about your compliance program.
Last updated: 2026-09-17
