Skip to main content
HIPAA · US healthcare data

Sell to health systems with ePHI protections you can document.

Hospitals and insurers ask vendors to show how patient data is protected. Summit supports your risk analysis with penetration testing and control validation, then documents the fixes so contracts move ahead.

Human-led VAPT · NDA first · report in 48h

3
rules to know: Privacy, Security and Breach Notification
3
safeguard types: administrative, physical and technical
60 days
outer limit to notify individuals after discovering a breach of unsecured PHI
18
identifiers listed in the Safe Harbor de-identification method
Board and leadership view

Why HIPAA matters to your board

The work is technical. The consequences of getting HIPAA wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Healthcare contracts

Health systems and insurers require a BAA and evidence of safeguards. Missing evidence stalls deals.

Regulatory exposure and liability

A breach of unsecured PHI triggers notification duties and possible regulator review.

Patient and customer trust

Patient data is deeply personal. A breach damages relationships with clinics and their patients.

Annual review and ownership

The risk analysis must be kept current. Clear owners ensure it is updated after major change.

Fit

Who needs HIPAA readiness

Digital health and telehealth

Apps that handle patient records, messages or scheduling are often business associates.

Cloud and SaaS for healthcare

Hosting or processing PHI for clinics and insurers brings a BAA and Security Rule duties.

Billing and revenue-cycle vendors

Anyone handling claims or patient accounts touches PHI daily.

Analytics and AI vendors

Training or analysing patient data needs clear permissions and strong safeguards.

Scope of work

What Summit delivers for HIPAA

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

Safeguards compared with the Security Rule for systems that create, receive or transmit ePHI.

Penetration testing

Human-led testing of the applications and infrastructure that hold ePHI.

Control validation

Checks on access, audit logging and transmission security against documented controls.

Evidence pack

Dated test results and fix records that support your risk analysis.

Remediation support and retest

Fix guidance for engineers, then a retest and confirmation letter.

Board-ready report

ePHI risk and progress in executive language.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical HIPAA readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Know where PHI lives

    Weeks 1 to 2

    Map every application, database, vendor and device that touches ePHI.

  2. 2

    Complete a risk analysis

    Weeks 3 to 6

    Identify threats and vulnerabilities and score the risk. Date and sign the output.

  3. 3

    Close the gaps

    Months 2 to 3

    Implement safeguards, MFA, logging, backups, training and policies.

  4. 4

    Test technical safeguards

    Month 3

    Run a penetration test on systems with ePHI and track fixes to closure.

  5. 5

    Sign BAAs and review vendors

    Month 3 to 4

    Put BAAs in place and collect security evidence from each vendor.

  6. 6

    Review every year

    Annual

    Update the risk analysis after major changes and at least once a year.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • An executive summary

    Where ePHI is exposed and the priority fixes.

  • Inputs for your risk analysis

    Tested vulnerability findings with severity and impact.

  • Customer-ready evidence

    Test summaries and retest letters for health system reviews.

  • A remediation tracker

    Each finding with an owner, severity and status.

  • Support through reviews

    The same Summit team stays with you through customer security reviews.

The detail

What HIPAA actually is

HIPAA is a US federal law with rules that protect protected health information (PHI). It applies to covered entities such as health plans, clearinghouses and most healthcare providers, and to business associates, the vendors and software companies that handle PHI for them. If you build software for clinics, hospitals or insurers, you are probably a business associate.

The Privacy Rule governs when PHI may be used or disclosed. The Security Rule covers electronic PHI and requires administrative, physical and technical safeguards backed by a documented risk analysis. The Breach Notification Rule requires notice to affected individuals, the regulator and sometimes the media after a breach of unsecured PHI.

There is no official HIPAA certification. Vendors usually show compliance through a risk analysis, policies, a business associate agreement and independent evidence such as penetration test reports or a SOC 2 or HITRUST report. In January 2025 the US Department of Health and Human Services proposed updates to the Security Rule, so check current status before planning.

Key terms in plain English

PHI / ePHI
Individually identifiable health information, and its electronic form, held by a covered entity or business associate.
Business associate
A vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity.
BAA
Business Associate Agreement: a contract setting out how PHI is protected and used.
Minimum necessary
Using, disclosing or requesting only the PHI needed for a task.
Requirements

The Security Rule, in plain language

The Security Rule is flexible: it asks for safeguards that fit your size and risk, but requires you to analyse that risk and document your decisions.

Risk

Risk analysis and risk management

The foundation of the Security Rule. Identify where ePHI lives, the threats and vulnerabilities to it, and the likelihood and impact of each. Then put measures in place to reduce risks to a reasonable level and keep documentation.

What it looks like in practice

  • An inventory of systems that touch ePHI
  • A written, dated risk analysis
  • A risk management plan with owners and dates
Admin

Administrative safeguards

Policies, procedures and people: security management, workforce training, access authorisation, incident procedures, contingency planning and periodic evaluation.

What it looks like in practice

  • Security officer named
  • Training records for staff
  • Contingency and incident plans that are tested
Physical

Physical safeguards

Controls for facilities, workstations and devices that hold ePHI, including access to premises, device disposal and media reuse.

What it looks like in practice

  • Device inventory and disposal records
  • Workstation use rules
  • Facility access controls
Tech

Technical safeguards

Access control with unique user IDs, audit controls, integrity protection, person or entity authentication and transmission security. Encryption is an “addressable” specification, which in practice means you should do it or document an equivalent.

What it looks like in practice

  • Unique logins and multi-factor authentication
  • Audit logs reviewed for suspicious access
  • Encryption in transit and at rest
Breach

Breach Notification Rule

After discovering a breach of unsecured PHI, you must notify affected individuals and the regulator. Larger breaches also require notice to media. Business associates must tell the covered entity. Encrypted data that meets guidance may be considered “secured”.

What it looks like in practice

  • A defined breach assessment process
  • Pre-drafted notices
  • BAA terms that match your notification duties
Where testing fits

How penetration testing supports HIPAA

The Security Rule requires periodic technical and non-technical evaluation, and risk analysis requires you to find vulnerabilities. HIPAA does not use the words “penetration test”, but regulators and customers increasingly expect to see one.

164.308(a)(1)

Risk analysis

Penetration testing identifies real vulnerabilities in systems with ePHI and strengthens the accuracy of the risk analysis.

164.308(a)(8)

Evaluation

Periodic technical evaluation of safeguards, supported by independent test reports.

164.312(a)

Access control

Testing verifies that users can only reach the ePHI they are authorised to see.

164.312(e)

Transmission security

Testing confirms that data in transit is protected against interception and tampering.

Avoid these

Common HIPAA mistakes, and how to avoid them

!

Copying a generic risk analysis

Regulators look for analysis specific to your systems and data flows, not a template with the company name swapped in.

!

No BAA with a vendor

A vendor that touches PHI needs a BAA even if it only stores encrypted data in some cases.

!

Calling a product “HIPAA compliant”

Compliance depends on how you configure and use it, not on a product label.

!

Skipping evaluation after changes

Major releases or infrastructure moves should trigger an updated risk analysis and tests.

FAQ

HIPAA questions, answered

Is there a HIPAA certification?

No. HHS does not certify organisations or products. Vendors show readiness through risk analysis, policies, BAAs and independent reports.

Does HIPAA require penetration testing?

Not in so many words. The Security Rule requires risk analysis and periodic evaluation, and penetration testing is a widely accepted way to meet both.

Who is a business associate?

Any person or company that creates, receives, maintains or transmits PHI for a covered entity, including SaaS, hosting and billing vendors.

What happens after a breach?

You assess whether PHI was compromised, then notify affected individuals without unreasonable delay and no later than 60 days after discovery, plus the regulator and sometimes the media.

Is this legal advice?

No. It is educational. Summit focuses on security assessment, testing evidence and board-ready reporting, and stays with your team through reviews while your legal team interprets the rules.

Ready to get HIPAA sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →