Kuulo
← Trust Centre
HIPAA mark

Health assurance

HIPAA Privacy, Security and Breach Notification Rules

The obligations depend on the organisation's role, the data and the service relationship. A useful delivery review therefore covers the data path, access model, safeguards, incident handling and any required Business Associate Agreement.

Requirements addressed in delivery contextHHS Security Rule

The framework

What HIPAA is for.

HIPAA is a US framework that includes privacy, security and breach-notification requirements for covered entities and business associates handling protected health information. The Security Rule focuses on appropriate administrative, physical and technical safeguards for electronic protected health information.

How we work with it

Make the obligation usable.

  • Clarify whether the organisation and engagement involve a covered entity or business associate relationship.
  • Map protected health information, access, safeguards, logging, incident response and retention.
  • Prepare the technical and contractual evidence needed for the client's review, including BAA input where applicable.

What we can leave behind

Evidence a reviewer can follow.

  • HIPAA control mapping
  • Security questionnaire support
  • BAA review input where applicable
Request documentation →

Concrete delivery evidence

How this showed up in client work.

HIPAA requirements formed part of the delivery context for the regulated health platform. The work combined the patient and clinician service with security, privacy, clinical-safety evidence, a DPIA and client questionnaires. The public material does not turn that engagement into a universal HIPAA certification claim.

Keep the map connected

Need this mapped to your system?

Start with the evidence your review needs.

Talk to us →