Compliance/03 - HIPAA

HIPAA that survives contact with a health system's diligence.

The Security Rule safeguards, the annual risk analysis regulators actually ask for, and the business associate chain behind you - implemented and evidenced, not asserted in a PDF.

  • A real risk analysis under Section 164.308(a)(1)(ii)(A), refreshed - the first thing OCR requests
  • Every addressable specification implemented or documented as to why not
  • BAAs tracked in both directions, upstream and down to your subcontractors
Trusted by teams shipping in regulated markets
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess

Nobody certifies HIPAA. You have to be able to show your work.

There is no HIPAA certificate, and any vendor implying otherwise is selling you a logo. What exists is a documented program you can put in front of a health system's diligence team or a regulator - so that is what we build.

The risk analysis, done properly

The most-cited failure in OCR enforcement is a risk analysis that is missing, stale, or scoped to a fraction of where PHI lives. We map the PHI, run the analysis, and keep it current.

- Section 164.308(a)(1)(ii)(A)

Addressable is not optional

Addressable specifications - encryption, automatic logoff, integrity controls - are implemented, or the reasoning and the alternative are documented. Silence is the finding.

- implemented or justified

The BAA chain, both directions

Agreements with the covered entities above you and every subcontractor below you, tracked with dates - because your customers will ask about your vendors.

- upstream + downstream

Breach notification you can actually execute

A documented process with the 60-day clock, the risk assessment for whether an incident is a breach at all, and our incident response team already on the hook.

- 60-day clock - IR included

What HIPAA actually requires of you.

Three rules do the work. Which apply depends on whether you are a covered entity or a business associate - most software companies are the latter, and the obligations still land directly on you.

Administrative safeguards

Section 164.308

Risk analysis and management, workforce access and sanctions, training, contingency planning, and periodic evaluation. The largest bucket by far.

Physical safeguards

Section 164.310

Facility access, workstation use and security, and device and media controls including disposal and reuse.

Technical safeguards

Section 164.312

Access control, audit controls, integrity, authentication, and transmission security across systems holding ePHI.

Privacy Rule

Section 164.500+

Permitted uses and disclosures, minimum necessary, individual rights of access, and notice obligations.

Breach Notification Rule

Section 164.400+

The four-factor assessment, individual and HHS notification, and the 60-day outer limit for notice.

Business associate agreements

Section 164.314

Contracts flowing obligations from covered entities through you and on to every subcontractor that touches PHI.

There is no such thing as HIPAA certification - no government body issues one. What you can hold is a documented, evidenced program plus an independent assessment, and that is what health-system diligence teams actually evaluate.

From scoping call to defensible program.

Two phases are gated - PHI scoping and the risk analysis. Everything downstream is only as good as knowing where PHI actually lives, and that is the question most programs answer wrong.

Phase 01 - gated

Map where PHI lives

Systems, vendors, backups, logs, support tooling, and the places PHI ends up that nobody documented. Scope is the whole game and this is where programs quietly fail.

PHI inventory - flows mapped
Phase 02 - gated

Run the risk analysis

A real analysis against the mapped environment, producing ranked risks and a risk management plan - the artifact OCR asks for first and the one most companies cannot produce.

Analysis on file - risks ranked
Phase 03

Implement the safeguards

Administrative, physical, and technical safeguards implemented and evidenced. Every addressable specification either in place or documented with its alternative.

Safeguards evidenced
Phase 04

Operate, train, and stay ready

Workforce training, periodic evaluation, BAA renewals, and a breach process that has been walked through before you need it. Diligence questionnaires answered by us.

Program operating - diligence handled
Pricing

HIPAA is $3,000 a year.
The security department is the rest.

Every other vendor in this category makes you book a demo to learn what HIPAA costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.

Startup plan + HIPAA
$20,000 / year

For companies under $5M revenue or 50 staff. The whole department, included.

  • Penetration testing
  • Vulnerability management
  • Monitoring & detection 24/7
  • Incident response
  • Compliance & GRC support
  • A named human on call
  • The Sythe Labs platform, run by us
+ $3,000 / yr for HIPAA - scoping, evidence, gap closure, and the path to a defensible compliance program. Add other frameworks at the same rate, only when you need them.
Book a call
Enterprise
Custom

Over $5M revenue or 50 staff. Negotiated to your scale and obligations.

  • Everything in Startup
  • Dedicated security lead
  • Custom SLAs & response times
  • Audit & board reporting
  • Scaled to your headcount
  • Procurement & MSA support
Talk to us
IncludedHealth-system diligence almost always asks for a current penetration test alongside the risk analysis. Yours is already in the flat plan.
Compliance billed per framework - no per-seat fees, ever. Auditor and certification-body fees are billed by them, not by us.

The people who already handed it over.

"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
EchoWin
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
Maru AI
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Naked Denver

HIPAA, honestly answered.

The questions that come up on every HIPAA scoping call, answered before you have to ask them.

Can we get HIPAA certified?
No. No government body certifies HIPAA compliance, and a vendor selling you a certificate is selling a logo. What holds up in diligence is a documented program - current risk analysis, implemented safeguards, executed BAAs - plus an independent assessment.
We are a business associate, not a covered entity. Does HIPAA apply to us?
Yes. Since the HITECH Act, business associates are directly liable for the Security Rule and parts of the Privacy Rule, and can be enforced against directly. Most software companies serving healthcare are business associates.
What does OCR ask for first in an investigation?
The risk analysis, essentially every time. A missing, stale, or narrowly scoped risk analysis is the most frequently cited failure in enforcement actions, which is why we gate on it.
Do we need SOC 2 as well?
Often, yes - health systems frequently ask for both, because HIPAA has no report to hand over and SOC 2 does. The control sets overlap heavily, so the second framework costs far less than the first.
What does the $3,000 cover?
Our work running the HIPAA program: PHI scoping, the risk analysis, safeguard implementation and evidence, BAA tracking, workforce training, and answering the diligence questionnaires your customers send.

Answer the diligence questionnaire with evidence, not adjectives.

A 30-minute call. We will tell you where your PHI actually is, what your risk analysis is missing, and what a defensible program costs - whether or not you hire us.