Vantage Point Group, LLC
HIPAA Compliance

HIPAA compliance, without the confusion.

Who it applies to, what it requires, and where to start.

HIPAA compliance means putting in place the administrative, physical, and technical safeguards the HIPAA Security Rule requires to protect electronic protected health information (ePHI), along with meeting the Privacy Rule and Breach Notification Rule. It applies to covered entities (healthcare providers, health plans, and clearinghouses) and to their business associates, which includes many vendors that handle health information on their behalf. There is no official HIPAA certification.

Who has to comply

HIPAA applies to covered entities, meaning healthcare providers, health plans, and healthcare clearinghouses, and to their business associates. A business associate is a vendor or contractor that creates, receives, maintains, or transmits protected health information (PHI) on a covered entity's behalf, such as billing companies, IT providers, software vendors, and consultants.

If you are a business associate, you generally need a signed Business Associate Agreement (BAA) with each covered entity you serve, and you are directly responsible for the Security Rule.

The three rules that matter

The Privacy Rule

Sets limits on how PHI can be used and disclosed, and gives individuals rights over their own health information.

The Security Rule

Requires administrative, physical, and technical safeguards to protect electronic PHI. This is where most of the practical work is: a documented risk analysis, access controls, workforce training, audit controls, and a contingency plan.

The Breach Notification Rule

Requires notifying affected individuals, and in many cases HHS, after a breach of unsecured PHI.

What a HIPAA risk assessment involves

A documented risk analysis is a core Security Rule requirement, and a missing or out-of-date one is frequently cited in enforcement. A sound one follows a clear sequence:

  • Find everywhere ePHI lives: systems, devices, cloud services, backups, and vendors
  • Identify the realistic threats and vulnerabilities for each
  • Evaluate the safeguards you already have
  • Rate the likelihood and impact of each risk
  • Document the results and prioritize what to fix first
  • Revisit it regularly, and whenever your systems or operations change significantly

Common gaps in smaller organizations

  • No documented risk analysis
  • Policies that are missing, outdated, or never read by staff
  • No signed BAAs with vendors that touch PHI
  • No record of workforce training
  • No tested backup, recovery, or incident response plan
  • Unencrypted laptops and phones that hold ePHI
  • Shared logins

How we help

We help you understand where you stand and close the gaps: a HIPAA gap assessment, support with your risk analysis, the policies and procedures the Security Rule calls for, workforce training materials, vendor and BAA review, and an incident response plan. We provide security and compliance guidance, not legal advice, so for questions of legal interpretation, work with your attorney.

Related guides

HIPAA questions, answered.

Is there a HIPAA certification?

No. HHS does not certify products, people, or organizations as HIPAA compliant. Compliance is something you demonstrate through your safeguards, documentation, and day-to-day practices, so be cautious of anyone selling a HIPAA certification as proof.

Do software and IT vendors need to comply with HIPAA?

If you create, receive, maintain, or transmit protected health information for a covered entity, you are likely a business associate, which means complying with the Security Rule and signing a Business Associate Agreement. Whether that applies to you depends on your specific services, so it is worth confirming with your attorney.

How often should we do a HIPAA risk analysis?

HIPAA expects risk analysis to be ongoing rather than a one-time exercise. A common practice is to review it at least annually, and any time you make a significant change to your systems, vendors, or operations.

How do HIPAA, HITRUST, and SOC 2 relate?

HIPAA is a law. HITRUST and SOC 2 are a framework and a report type that customers may ask for as evidence of good security. They overlap in many controls, but meeting one does not automatically satisfy the others.

Not sure where you stand on HIPAA?

Start with a free conversation, or a quick self-check. No pressure, no jargon.