HIPAA compliance

Safeguards, agreements, access records and what happens when something is disclosed.

HIPAA compliance in SigmaPointPi
/verticals/healthcare/compliance

Protected health information carries administrative, physical and technical safeguard requirements, plus a risk analysis that has to be current rather than performed once.

Access to records is logged. Reviewing those logs is itself a required activity, not an optional one.

Where everything sits

HIPAA Compliance
HIPAA Compliance
Overall Score
Overall Score
Compliant Items
Compliant Items
Overdue Deadlines
Overdue Deadlines
Audit Readiness
Audit Readiness
Documents Current
Documents Current

How to work this page

Keep the risk analysis current

It underpins every other safeguard decision and it is the first document requested in an investigation. Out of date is close to not having one.

Hold agreements with every vendor touching this data

A business associate agreement is required before the data reaches them. Any subcontractor of theirs needs one too.

Review access logs on a schedule

Logging without reviewing satisfies nothing. Reviews are recorded as performed.

Know the breach clock

Notification deadlines run from discovery. The assessment of whether an incident is a reportable breach is itself documented.

On a phone

HIPAA compliance on iPhone 15 Pro Max

Every figure from the desktop appears here, stacked rather than reduced. Tables scroll inside themselves so the page never moves sideways, and figures keep their separators and their alignment at every width.

Questions people actually ask

What counts as a breach?

Impermissible use or disclosure is presumed a breach unless a risk assessment across the specified factors shows low probability of compromise. The assessment must be documented either way.

How long do we keep records?

Six years for required documentation, from creation or from last effective date, whichever is later. State law may require longer.