Get started

Compliance Tools

HIPAA Security Rule §164.308(a)(1)(ii)(A) requires a "thorough and accurate assessment of the potential risks and vulnerabilities" to electronic Protected Health Information (ePHI). This is the foundational compliance requirement — every other HIPAA control is meant to address a risk identified in this analysis.

What gets assessed

54 HIPAA safeguards organised into four categories:

CategoryReferenceSafeguardsRequiredAddressable
Administrative§164.308271611
Physical§164.3101266
Technical§164.3121275
Organisational§164.314330

Required means you MUST implement. Addressable means you must assess the safeguard and then (a) implement it, (b) implement an equivalent measure, OR (c) document why neither is reasonable. Addressable is NOT optional.

How to use

Navigate to Compliance Command Center → Privacy Impact tab (HIPAA flow selected).

Auto-population

The §164.312 Technical Safeguards are auto-assessed from your governance data:

SafeguardAuto-detection source
§164.312(a)(1) Access ControlAOCL L1/L3 identity + policy gate events
§164.312(a)(2)(i) Unique User IdentificationAOCL L1 identity resolution
§164.312(b) Audit ControlsAEE envelopes + VOLT event chain
§164.312(c)(1) IntegrityVOLT hash chain
§164.312(c)(2) Mechanism to Authenticate ePHIVOLT chain verification
§164.312(d) Person/Entity AuthenticationAOCL L1 identity
§164.312(e)(1) Transmission SecurityAOCL L3 policy gate

Risk scoring

For each safeguard with an identified risk, score on:

  • Likelihood (1-5): How likely is this to happen?
  • Impact (1-5): How bad if it does?

Score = likelihood × impact:

ScoreLevel
1-5Low
6-15Medium
16-25High

Export

Generate a HIPAA report from the Reports tab. The export includes:

  • BAA Assessment — detects AI providers as potential Business Associates, lists 8 required BAA contract elements per §164.314
  • Addressable Guidance — clarifies that addressable ≠ optional, with decision examples
  • Risk analysis methodology — compatible with NIST SP 800-30
  • Per-safeguard findings with evidence counts and required action

Frequently asked questions

What exactly does the HIPAA Risk Analysis tool assess?

It evaluates 54 HIPAA safeguards across four categories: Administrative, 27 total (16 required, 11 addressable); Physical, 12 total (6 required, 6 addressable); Technical, 12 total (7 required, 5 addressable); and Organisational, 3 total, all required.

What's the difference between "required" and "addressable" safeguards?

Required means you must implement the safeguard. Addressable means you must assess the safeguard and then either implement it, implement an equivalent measure, or document why neither is reasonable.

Does anything get assessed automatically?

Seven technical safeguards auto-assess from governance data, including access control, audit controls, integrity verification, and transmission security monitoring.

What can we export once the analysis is complete?

Exports include a BAA assessment, addressable guidance, risk methodology, and per-safeguard findings documentation.

See also

Glossary

TermDefinition
ePHIElectronic Protected Health Information
BAABusiness Associate Agreement — required under §164.314 with any entity processing ePHI on your behalf
Covered EntityHealth plan, health care clearinghouse, or health care provider that transmits ePHI
Business AssociatePerson/entity that performs functions involving ePHI on behalf of a Covered Entity
AddressableMust assess the safeguard and document the decision. NOT optional.
RequiredMust implement. No exceptions.