Skip to main content

The Art of CTO HIPAA Compliance tool evaluates healthcare organizations against a subset of the HIPAA Security Rule administrative, physical and technical safeguards for electronic protected health information (ePHI), covering risk analysis, workforce training, information access management, incident procedures, contingency planning, access control, audit controls, encryption and business associate agreements.

Do our safeguards meet HIPAA?

Administrative, physical and technical safeguard scores with the gaps and the penalty context.

About 15 min · Assessment · Free

About this toolWhy it matters, common mistakes, FAQ

Would Your Safeguards Survive A HIPAA Review?

HIPAA penalties are tiered by culpability, and 'we did not know' is the most expensive tier. For most engineering orgs the real exposure is a subprocessor holding PHI without a BAA, or a logging pipeline quietly carrying identifiers into a third-party tool.

Encryption gets treated as the whole of the Security Rule. The administrative safeguards — risk analysis, workforce training, access management, incident procedures — are where reviews actually find gaps, and they are the ones no engineer owns by default.

Questions CTOs ask

What are the three HIPAA safeguard categories?
HIPAA requires three categories of safeguards: administrative (policies, training, risk assessments, and workforce security), physical (facility access controls, workstation security, and device disposal), and technical (access controls, audit logs, encryption, and transmission security). All three must be implemented to protect electronic protected health information (ePHI). Most technology companies focus on technical safeguards but underinvest in administrative policies and physical security.
Does HIPAA apply to SaaS companies handling health data?
Yes, any SaaS company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity (hospitals, insurers, providers) is classified as a Business Associate under HIPAA and must comply. This requires signing Business Associate Agreements (BAAs), implementing all required safeguards, and reporting breaches. Cloud providers like AWS and GCP offer BAAs, but the SaaS company remains responsible for proper configuration and data handling.

Related Reading