HIPAA responsibility extends across the healthcare ecosystem
HIPAA obligations depend on an organisation's role and its relationship with protected health information. A secure environment requires visibility across covered entities, business associates, subcontractors, systems, and data exchanges.
Covered entities
For applicable healthcare providers, health plans, and healthcare clearinghouses that create, receive, maintain, or transmit protected health information.
Hospitals, clinics, health plans, laboratories, pharmacies, and other applicable providers.
Business associates
For organisations that handle protected health information while delivering services to covered entities.
Cloud providers, billing services, managed service providers, consultants, analytics firms, and software platforms.
Subcontractors and connected services
For downstream organisations that may create, receive, maintain, or transmit protected health information on behalf of a business associate.
Hosting providers, support vendors, data processors, and specialised technology partners.
Your compliance scope begins with knowing where PHI and ePHI enter, move, and leave the organisation.
PHI and ePHI require different levels of control visibility
Protected health information
Protected health information, or PHI, is individually identifiable health information held or transmitted by a covered entity or business associate. It may exist in electronic, paper, or oral form.
Electronic protected health information
Electronic protected health information, or ePHI, is PHI created, received, maintained, or transmitted electronically.
The HIPAA Security Rule specifically addresses the confidentiality, integrity, and availability of ePHI.
HIPAA brings privacy, security, breach response, and accountability together
Control how protected health information is used and disclosed
The Privacy Rule establishes standards for protecting PHI in electronic, paper, and oral forms. It addresses permitted uses and disclosures, individual rights, privacy practices, authorisations, and safeguards around health information.
Three safeguard areas shape ePHI protection
Administrative safeguards
Define how security responsibilities are governed and managed.
Physical safeguards
Control physical access to facilities, devices, systems, and media containing ePHI.
Technical safeguards
Control access to ePHI and protect it during use and transmission.
A risk assessment must follow the information
A system list alone does not show how ePHI is exposed. The assessment must examine how information moves between people, devices, applications, locations, and external services.
Patient demographics, clinical notes, referral data, lab orders
Clinicians, registration staff, EHR intake modules
Unauthorised entry, incomplete consent, data accuracy errors
Access controls, intake validation, consent workflows
Every identified risk should connect to an asset, a data flow, an owner, and a treatment decision.
Core areas we assess
Enterprise wide HIPAA risk analysis
Assess potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of ePHI across the defined environment.
Identity and access management
Review user access, privileged accounts, authentication, provisioning, termination, and periodic access reviews.
Security monitoring and audit controls
Evaluate logging, monitoring, alerting, investigation, and the review of system activity.
Cloud and application security
Examine platforms, configurations, data locations, integrations, encryption, and shared responsibility arrangements.
Endpoint and medical device exposure
Assess workstations, mobile devices, connected technology, media controls, and remote access.
Backup and contingency readiness
Review backups, restoration procedures, emergency operations, recovery priorities, and testing records.
Business associate oversight
Assess due diligence, Business Associate Agreements, access boundaries, incident responsibilities, and subcontractor governance.
Incident and breach readiness
Examine detection, escalation, investigation, risk assessment, documentation, and notification workflows.
Our HIPAA services
HIPAA security risk assessment
Assess the organisation's ePHI environment, identify potential risks and vulnerabilities, evaluate safeguards, and document prioritised findings.
- —Scope and ePHI environment review
- —Risk register
- —Safeguard observations
- —Prioritised remediation roadmap
HIPAA privacy and security gap assessment
Review current practices against applicable HIPAA Privacy, Security, and Breach Notification requirements.
- —Requirement mapping
- —Policy and procedure review
- —Control gap analysis
- —Readiness summary
Business associate and vendor assessment
Evaluate how external parties access, maintain, transmit, and protect PHI or ePHI.
- —Vendor scope review
- —BAA control assessment
- —Security evidence review
- —Third party findings
HIPAA remediation and advisory support
Help internal teams plan corrective actions, strengthen safeguards, improve documentation, and track progress.
- —Remediation planning
- —Control recommendations
- —Ownership and timeline mapping
- —Evidence review
Need help defining the right assessment scope?
Discuss your HIPAA environmentEvidence behind HIPAA readiness
How risks are identified, evaluated, and treated
Risk analysis, risk register, treatment plans
How access is approved, changed, and removed
Access records, role definitions, termination procedures
How the workforce understands security responsibilities
Training materials, completion records, reminders
How physical assets and media are controlled
Access procedures, device inventory, disposal records
How users and systems access ePHI
Account records, authentication settings, access reviews
How important activity is logged and reviewed
Audit logs, alerts, review records, investigations
How ePHI access and operations are restored
Backup reports, recovery plans, test results
How suspected incidents are escalated and assessed
Response plans, case records, breach assessment documentation
How business associate risks are managed
Agreements, assessments, review records, corrective actions
How the assessment works
Define
Confirm the organisation's role, assessment scope, locations, systems, business units, and relevant third parties.
Discover
Collect documentation, interview stakeholders, identify ePHI, and trace important data flows.
Analyse
Identify threats, vulnerabilities, current safeguards, likelihood, and potential impact.
Validate
Examine policies, configurations, processes, records, and other evidence supporting control operation.
Prioritise
Rank findings based on risk, regulatory relevance, operational impact, and remediation effort.
Report
Provide leadership and control owners with clear findings, recommended actions, ownership, and sequencing.
Outcome: A defensible assessment with findings that teams can act on.
When organisations engage Digisecuritas
Building or refreshing a HIPAA programme
The organisation needs a structured view of its current safeguards, gaps, documentation, and security priorities.
After a technology change
A cloud migration, EHR implementation, acquisition, integration, or infrastructure change has altered how ePHI is handled.
Before a customer review
A covered entity, partner, insurer, or enterprise customer has requested evidence of HIPAA security practices.
After an incident or material control finding
The organisation needs to understand the underlying weaknesses, track corrective actions, and strengthen its security programme.
Healthcare security demands evidence, context, and careful judgement
Our assessments connect HIPAA requirements with the organisation's technology, workforce, vendors, and operating environment. Findings are written for the people who must approve, implement, and oversee the response.
Receive an objective assessment without software or implementation bias.
Examine the systems, workflows, and external relationships that shape ePHI exposure.
Connect regulatory expectations with practical cybersecurity controls.
Present material risks and priorities in language leadership can use.
Give control owners clear actions, priorities, and evidence expectations.
Common questions about HIPAA assessments
Strengthen the controls protecting ePHI
Gain a clear view of your HIPAA security risks, safeguard gaps, and practical remediation priorities.
