Sentrix

Framework · HIPAA

HIPAA continuous. Not HIPAA compliant once a year.

The Security Rule, Privacy Rule and Breach Notification Rule of the US HIPAA law, for covered entities and their business associates, monitored continuously.

HIPAA (Health Insurance Portability and Accountability Act) is the US federal law governing the protection of health information (PHI). It applies to covered entities (health plans, providers, clearinghouses) and their business associates, and is enforced by the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS). A point-in-time risk analysis conducted once a year is not enough: controls must operate continuously.

Key facts

  • 3 rules: Security Rule, Privacy Rule, Breach Notification Rule.
  • 3 safeguard families: administrative, physical and technical, in the Security Rule.
  • 60 days: deadline to notify HHS and patients after a breach is discovered.
  • BAA: a Business Associate Agreement is required with every third party that handles PHI.

What HIPAA requires

The Security Rule defines administrative, physical and technical safeguards. The Privacy Rule governs PHI use and disclosure. The Breach Notification Rule requires HHS and patient notification within 60 days.

  1. Administrative safeguards: risk analysis, workforce training, contingency planning
  2. Physical safeguards: facility access, workstation use, device controls
  3. Technical safeguards: access control, audit controls, integrity, transmission security
  4. Privacy Rule: use and disclosure of PHI
  5. Breach Notification Rule: HHS and patient notification within 60 days of discovery
  6. Business associates: an agreement (BAA) with every third party and tracking of its compliance posture

What Sentrix provides for HIPAA

Risk analysis and management

Sentrix maintains a living risk analysis tied to your actual infrastructure, updated as your systems change rather than rebuilt annually from scratch.

BAA management

Track all Business Associate Agreements, monitor covered vendor compliance continuously, and get an alert when a BAA partner's SOC 2 lapses or their security posture drifts from your requirements.

PHI data flow mapping

Automated inventory of where PHI exists across your systems, which integrations touch it, and which controls apply to each data store. Required for both HIPAA risk analyses and audits.

Breach notification workflow

Automated breach classification, 60-day notification deadline tracker, HHS notification documentation, and patient notification letter templates, ready before OCR asks.

Workforce training tracking

HIPAA requires regular security awareness training for the workforce. Sentrix tracks completion, stores certificates as evidence, and alerts when training cycles expire.

SOC 2 and HIPAA combined

HIPAA does not require a formal audit, but healthcare SaaS companies need SOC 2 for enterprise customers. Sentrix runs both from one evidence set.

Crosswalks

  • SOC 2: HIPAA controls map to the Trust Services Criteria.
  • ISO 27001: pre-mapped to the controls shared with HIPAA.
  • Law 25: incident classification and notification for healthcare organizations operating in Québec.
  • GDPR: data subject rights and DPIAs for EU operations.

Further reading

Healthcare and life sciences solution.

See your HIPAA posture on your real stack.

Contact us

Frequently asked questions

Who does HIPAA apply to?
HIPAA applies to covered entities, meaning health plans, healthcare providers and clearinghouses, and to their business associates, the third parties that create, receive, maintain or transmit protected health information (PHI) on their behalf. Every business associate relationship must be governed by a Business Associate Agreement (BAA), and the partner's compliance posture must be tracked.
What is the breach notification deadline under HIPAA?
The Breach Notification Rule requires notification to the Department of Health and Human Services (HHS) and to affected patients within 60 days of discovering the breach. Sentrix provides automated breach classification, a 60-day deadline tracker, HHS notification documentation and patient notification letter templates, ready before the Office for Civil Rights asks for them.
Does HIPAA require a formal audit or certification?
No. HIPAA does not require a formal audit or certification, but healthcare SaaS companies need a SOC 2 report for their enterprise customers. Sentrix runs both from one evidence set: HIPAA controls map to the SOC 2 Trust Services Criteria, and the risk analysis required by the Security Rule stays current as your systems change.

Let's talk about your compliance program.

Last updated: 2026-09-17