Compliance Tools
HIPAA Security Rule §164.308(a)(1)(ii)(A) requires a "thorough and accurate assessment of the potential risks and vulnerabilities" to electronic Protected Health Information (ePHI). This is the foundational compliance requirement — every other HIPAA control is meant to address a risk identified in this analysis.
What gets assessed
54 HIPAA safeguards organised into four categories:
| Category | Reference | Safeguards | Required | Addressable |
|---|---|---|---|---|
| Administrative | §164.308 | 27 | 16 | 11 |
| Physical | §164.310 | 12 | 6 | 6 |
| Technical | §164.312 | 12 | 7 | 5 |
| Organisational | §164.314 | 3 | 3 | 0 |
Required means you MUST implement. Addressable means you must assess the safeguard and then (a) implement it, (b) implement an equivalent measure, OR (c) document why neither is reasonable. Addressable is NOT optional.
How to use
Navigate to Compliance Command Center → Privacy Impact tab (HIPAA flow selected).
Auto-population
The §164.312 Technical Safeguards are auto-assessed from your governance data:
| Safeguard | Auto-detection source |
|---|---|
| §164.312(a)(1) Access Control | AOCL L1/L3 identity + policy gate events |
| §164.312(a)(2)(i) Unique User Identification | AOCL L1 identity resolution |
| §164.312(b) Audit Controls | AEE envelopes + VOLT event chain |
| §164.312(c)(1) Integrity | VOLT hash chain |
| §164.312(c)(2) Mechanism to Authenticate ePHI | VOLT chain verification |
| §164.312(d) Person/Entity Authentication | AOCL L1 identity |
| §164.312(e)(1) Transmission Security | AOCL L3 policy gate |
Risk scoring
For each safeguard with an identified risk, score on:
- Likelihood (1-5): How likely is this to happen?
- Impact (1-5): How bad if it does?
Score = likelihood × impact:
| Score | Level |
|---|---|
| 1-5 | Low |
| 6-15 | Medium |
| 16-25 | High |
Export
Generate a HIPAA report from the Reports tab. The export includes:
- BAA Assessment — detects AI providers as potential Business Associates, lists 8 required BAA contract elements per §164.314
- Addressable Guidance — clarifies that addressable ≠ optional, with decision examples
- Risk analysis methodology — compatible with NIST SP 800-30
- Per-safeguard findings with evidence counts and required action
Frequently asked questions
What exactly does the HIPAA Risk Analysis tool assess?
It evaluates 54 HIPAA safeguards across four categories: Administrative, 27 total (16 required, 11 addressable); Physical, 12 total (6 required, 6 addressable); Technical, 12 total (7 required, 5 addressable); and Organisational, 3 total, all required.
What's the difference between "required" and "addressable" safeguards?
Required means you must implement the safeguard. Addressable means you must assess the safeguard and then either implement it, implement an equivalent measure, or document why neither is reasonable.
Does anything get assessed automatically?
Seven technical safeguards auto-assess from governance data, including access control, audit controls, integrity verification, and transmission security monitoring.
What can we export once the analysis is complete?
Exports include a BAA assessment, addressable guidance, risk methodology, and per-safeguard findings documentation.
See also
- Healthcare AI needs cryptographic proof, not just audit logs — why ePHI-handling agents need tamper-evident evidence, not editable logs.
- For auditors — the read-only auditor view of this same risk analysis and its underlying evidence chain.
Glossary
| Term | Definition |
|---|---|
| ePHI | Electronic Protected Health Information |
| BAA | Business Associate Agreement — required under §164.314 with any entity processing ePHI on your behalf |
| Covered Entity | Health plan, health care clearinghouse, or health care provider that transmits ePHI |
| Business Associate | Person/entity that performs functions involving ePHI on behalf of a Covered Entity |
| Addressable | Must assess the safeguard and document the decision. NOT optional. |
| Required | Must implement. No exceptions. |