Health data protection
HIPAA: the Privacy, Security and Breach Notification rules
In short
HIPAA — the US Health Insurance Portability and Accountability Act of 1996 — sets national standards for protecting sensitive patient health information (PHI). It applies to healthcare organizations and the vendors that handle their data, and is enforced by the HHS Office for Civil Rights through the Privacy Rule, Security Rule, Breach Notification Rule and Enforcement Rule (45 CFR Parts 160, 162 and 164).
Last reviewed: August 2026
Who it applies to
HIPAA applies to “covered entities” — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically — and to their “business associates”: any vendor (including SaaS and cloud providers) that creates, receives, maintains or transmits PHI on their behalf. If your product handles US health data for a covered entity, you are almost certainly a business associate and must sign a Business Associate Agreement (BAA).
The core rules
- Privacy Rule — how PHI may be used and disclosed, and patients’ rights over their data
- Security Rule — administrative, physical and technical safeguards for electronic PHI (ePHI), including a required risk analysis
- Breach Notification Rule — notify affected individuals (and HHS, sometimes the media) without unreasonable delay and no later than 60 days
- Enforcement Rule — investigations and civil money penalties
Typical compliance challenges
- Mapping where ePHI actually flows across systems and vendors
- Completing and maintaining the required Security Rule risk analysis
- Signing and tracking Business Associate Agreements across the vendor chain
- Evidencing that safeguards operate continuously, not once
- Meeting the 60-day breach-notification window under pressure
What can reasonably be automated
- Continuous monitoring of technical safeguards (access control, audit logging, encryption)
- Time-stamped evidence instead of manual collection
- A vendor/BAA register with status and reminders
- A breach workflow with the notification clock built in
- Mapping HIPAA safeguards onto ISO 27001 and SOC 2 controls to reuse evidence
Evidence auditors and regulators expect
- Security Rule risk analysis and risk management plan
- Privacy and security policies and procedures
- Workforce security training records
- Access controls and audit logs for ePHI
- Business Associate Agreements with vendors
- Breach register and notification records
Relationship to ISO 27001 and SOC 2
HIPAA is US law, not a certification — there is no official “HIPAA certificate.” Its Security Rule safeguards overlap heavily with ISO 27001 and SOC 2, so a strong information-security program covers much of the work. Treating them as overlapping frameworks — one control mapped to HIPAA, ISO 27001 and SOC 2 — avoids collecting the same evidence three times.
How Isodora supports HIPAA
Isodora keeps HIPAA safeguards operating and evidenced on the same engine as your other frameworks.
Safeguard monitoring
Continuously verify technical safeguards for ePHI — access control, logging, encryption — against live system state.
BAA & vendor register
Track Business Associate Agreements and vendor risk across the chain with token-based questionnaires.
Breach workflow
A register and workflow for breaches with the 60-day notification clock built in.
Shared controls
Reuse ISO 27001 and SOC 2 evidence for HIPAA’s Security Rule safeguards.
Isodora helps you operationalize HIPAA safeguards. It is not legal advice, and there is no official HIPAA certification — compliance is your organization’s responsibility, assessed by regulators (HHS OCR).
Frequently asked questions
- Who has to comply with HIPAA?
- Covered entities — health plans, healthcare clearinghouses and providers that transmit health data electronically — and their business associates, meaning any vendor that handles protected health information on their behalf.
- Is there a HIPAA certification?
- No. HIPAA is US federal law enforced by the HHS Office for Civil Rights; there is no official certificate. Organizations demonstrate compliance through their safeguards, risk analysis, policies and evidence — often alongside SOC 2 or ISO 27001.
- How quickly must a HIPAA breach be reported?
- Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI. HHS must also be notified, and the media in larger breaches.
- How does HIPAA relate to ISO 27001 and SOC 2?
- HIPAA’s Security Rule safeguards overlap heavily with ISO 27001 and SOC 2 controls. Many organizations run all three together and reuse the same underlying evidence, which is how Isodora treats them.