- Home
- Compliance
- HIPAA
HIPAA
HIPAA Security & Privacy Rules
Health Insurance Portability and Accountability Act
The baseline for Protected Health Information (PHI) privacy and security in healthcare organizations.
$1.9M
Maximum HIPAA penalty per violation category, per year
60 days
Notification window for breaches affecting 500+ individuals
6 years
Required audit log and documentation retention
$10.93M
Average healthcare breach cost in 2024 (IBM)
"PHI Protection That Never Sleeps"
$1.9M
Maximum HIPAA penalty per violation category, per year
60 days
Notification window for breaches affecting 500+ individuals
6 years
Required audit log and documentation retention
$10.93M
Average healthcare breach cost in 2024 (IBM)
Sources: HIPAA Security Rule, 45 CFR Part 164 Subpart C; HHS Office for Civil Rights enforcement reports; IBM Cost of a Data Breach Report 2024 (healthcare segment)
What HIPAA requires
The core obligations at a glance.
Every HIPAA program AdVran builds is sized against these requirements. Use this as a quick orientation before reading the deeper analysis below.
Required
Technical safeguards including encryption, access controls, audit logs, integrity controls (45 CFR 164.312)
Required
Administrative safeguards including risk analysis, workforce training, sanction policies (45 CFR 164.308)
Required
Physical safeguards including facility access, workstation security, device disposal (45 CFR 164.310)
Required
Business Associate Agreements with every vendor that touches PHI
How AdVran handles HIPAA
From gap analysis to audit-ready, in 3 to 6 months.
Risk analysis baseline
We document every system that creates, receives, maintains, or transmits PHI. Output is a written risk analysis required by 45 CFR 164.308(a)(1)(ii)(A). The single most-cited gap in HIPAA enforcement actions.
Safeguard implementation
Technical (encryption, access controls, audit logs), administrative (workforce policies, training, BAAs), and physical (facility, device) safeguards deployed and documented.
Continuous monitoring
Audit logs collected and retained for six years. Access reviewed monthly. AdVran's SOC watches PHI systems 24/7 for anomalous access patterns.
Audit readiness
Evidence packages organized for OCR audit. Incident response plan tested annually. Breach notification timelines (60 days for individuals and HHS) built into runbooks.
Self-assessment
HIPAA Security Rule readiness snapshot
This checks whether nineteen basic practices from the current HIPAA Security Rule and Breach Notification Rule are in place at your practice, using the text of 45 CFR 164 as it stands today. The questions say electronic patient information throughout, which is what the rule calls electronic protected health information, or ePHI. It is a self-assessment and not the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), and a strong score is not a compliance opinion and would not serve as a defense in an OCR investigation.
What this means
Gaps to close
This is a self-assessment, not an audit or a compliance opinion. Nothing you entered was sent anywhere or saved.
Talk through these gaps with an engineerSources
- 45 CFR 164 Subpart C, Security Standards for the Protection of Electronic Protected Health Information
- 45 CFR 164.306, General rules, including what required and addressable mean
- 45 CFR 164 Subpart D, Notification in the Case of Breach of Unsecured Protected Health Information
- HHS OCR, Final Guidance on Risk Analysis
- HHS OCR, The Security Rule
- HHS OCR, Breach Notification Rule
- HHS OCR, Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable
- Proposed only, not in effect: HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, 90 FR 898 (6 January 2025)
Common questions
HIPAA compliance.
Don't see yours? Call (714) 694-4573 or email contact@advran.com.
What is HIPAA and who needs to comply? +
The baseline for Protected Health Information (PHI) privacy and security in healthcare organizations.
How does AdVran help with HIPAA compliance? +
AdVran provides end-to-end HIPAA compliance management, including gap assessment, control implementation, continuous monitoring, evidence collection, and audit coordination. Our team handles the technical complexity so you can focus on your business.
How long does it take to achieve HIPAA compliance? +
Timeline depends on your current security posture and the scope of required controls. Most organizations achieve initial compliance within 3-6 months with AdVran's guidance. We provide a detailed timeline during our initial assessment.
What happens if we fail a compliance audit? +
AdVran conducts pre-audit readiness assessments to identify and resolve gaps before the official audit. If issues are found during an audit, we provide immediate remediation support and work with auditors to address findings.
Related frameworks
More in Healthcare & Life Sciences
21 CFR Part 11
FDA Electronic Records and Electronic Signatures
FDA requirement for electronic records and signatures in clinical trials, R&D, and pharmaceutical manufacturing environments.
HITECH Act
Health Information Technology for Economic and Clinical Health Act
Mandates strict breach notifications, increases penalties for HIPAA non-compliance, and extends requirements to business associates.