Skip to main content

Security Consulting & Compliance

HIPAA & HITRUST Compliance

Safeguards assessment and remediation for healthcare data.

Every engagement includes manual validation, a two audience report and free re-testing.

Get a scoped quote+91 96682 00222

What this actually is

HIPAA applies if you are a covered entity or, far more commonly for Indian companies, a business associate handling protected health information for one. The obligation reaches you through the business associate agreement your customer asked you to sign, often without either side reading it closely.

The Security Rule is the part that concerns us. It sets administrative, physical and technical safeguards, some required and some addressable. Addressable does not mean optional, which is the single most expensive misunderstanding in this area.

We assess against the Security Rule as written, produce the risk analysis it requires, and leave you with evidence that would survive an audit rather than a policy document nobody has read.

What we go after

  • The risk analysis required by the Security Rule, done properly rather than as a template
  • Administrative safeguards: workforce security, training, incident procedures
  • Physical safeguards covering facility access and device controls
  • Technical safeguards: access control, audit controls, integrity, transmission security
  • Encryption at rest and in transit, with the addressable decision documented
  • Business associate agreements up and down your chain
  • Breach notification process against the Breach Notification Rule
  • Minimum necessary access, tested rather than asserted

How we run it

  1. 01

    Gap assessment

    We measure you against the standard as it is actually audited, not as it reads on paper.

  2. 02

    Remediation plan

    Every gap gets an owner, an effort estimate and a date. You decide what lands this quarter.

  3. 03

    Implement and evidence

    We write the policy, build the control and collect the artefact that proves it is working.

  4. 04

    Internal audit

    A dry run under audit conditions, so nothing in the real one is a surprise.

  5. 05

    Certify and maintain

    We sit on your side of the table for the audit, then keep the evidence current between cycles.

What you receive

  • Security Rule risk analysis in the form auditors expect
  • Gap report mapped to each required and addressable specification
  • Remediation plan with owners and dates
  • Reviewed business associate agreement template
  • Incident and breach response procedure
  • Evidence pack for customer security reviews

Who needs this

Indian technology and BPO companies serving US healthcare clients, and any organisation that has signed a business associate agreement.

How long it takes

Three to five weeks for assessment and risk analysis.

Standards this satisfies

  • HIPAA Security Rule
  • HIPAA Breach Notification Rule
  • HITRUST
  • ISO 27001

Why it matters

Almost nobody starts a certification because they want one. It starts because a customer will not sign without it, a regulator has asked, or a deal is sitting still while procurement waits for evidence. The commercial driver is real and it is worth being honest that it, rather than security, is usually what pays for the programme.

The security benefit is real too, but it comes from a specific place: the discipline of having to evidence that a control operated over a period, rather than that it was configured once. That is the part that changes behaviour, and it is also the part organisations consistently underestimate.

Choose how you want this delivered

Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.

Gap assessment, then we work alongside your team through remediation, internal audit and the certification audit itself. Your people do the work and own the outcome, which is what makes the management system survive after we leave. This is what most organisations should choose.

Choose this when

  • You have a team who can absorb the work alongside their day job
  • You want the capability to remain in-house afterwards
  • First certification where documentation is the main gap

Effort and cost

Moderate. The calendar is longer than a managed programme because the work competes with everyone's existing responsibilities.

Scope it yourself, before you call anyone

Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.

1/5

Which framework are you going for?

What we look for, and keep finding

These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.

  • Controls that exist on paper only

    The policy says quarterly access reviews. The evidence shows one, eighteen months ago, and it was not completed. This is the single most common audit finding across every framework.

  • Scope drawn too narrowly

    A certificate covering a subset of the business that customers assume covers all of it. Auditors check the boundary; buyers rarely do. Getting scope right is the most consequential early decision.

  • Evidence that cannot be reproduced

    A screenshot proves a control was configured on the day someone took it. A framework wants proof it operated throughout the period. Those are very different, and the gap only appears at the audit.

  • Exceptions with no expiry

    Risk accepted once, recorded, and never revisited. Over a few years these accumulate into an undocumented second control framework nobody is managing.

  • Third parties outside the boundary

    Processing carried out by a supplier who was assessed at onboarding and never since, while your obligation for their handling of your data continues regardless.

Who runs your engagement

A lead assessor who has sat on the other side of the table

Compliance work is led by an assessor who has taken organisations through certification, not by a consultant reading the standard for the first time with you. They know which findings a certification body will actually raise, which is a different list from what the standard technically says.

Questions we get asked

What does addressable actually mean?

It means you must implement it, or document why it is not reasonable and appropriate for you and implement an equivalent alternative. Skipping it with no documented reasoning is a finding. Most organisations we assess have treated addressable as optional.

Is there a HIPAA certification we can get?

No. There is no official HIPAA certification and anyone selling you one is selling their own opinion. What exists is an assessment against the Rules and the evidence to support it. HITRUST is the closest thing to a recognised certification and it is a separate, heavier programme.

We only process de-identified data. Are we out of scope?

Possibly, but de-identification has a specific meaning under the Privacy Rule and most datasets people describe as de-identified do not meet it. It is worth establishing that properly, because if you are right your obligations reduce dramatically.

How does this interact with our ISO 27001 certificate?

ISO 27001 gives you most of the administrative and technical machinery, so it is a strong head start. It does not cover the HIPAA specific requirements around business associate agreements, minimum necessary, or breach notification timing. We map what your ISMS already satisfies rather than repeating it.

Ready to scope your hipaa & hitrust compliance?

Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.