HIPAA that survives contact with a health system's diligence.
The Security Rule safeguards, the annual risk analysis regulators actually ask for, and the business associate chain behind you - implemented and evidenced, not asserted in a PDF.
- A real risk analysis under Section 164.308(a)(1)(ii)(A), refreshed - the first thing OCR requests
- Every addressable specification implemented or documented as to why not
- BAAs tracked in both directions, upstream and down to your subcontractors















Nobody certifies HIPAA. You have to be able to show your work.
There is no HIPAA certificate, and any vendor implying otherwise is selling you a logo. What exists is a documented program you can put in front of a health system's diligence team or a regulator - so that is what we build.
The risk analysis, done properly
The most-cited failure in OCR enforcement is a risk analysis that is missing, stale, or scoped to a fraction of where PHI lives. We map the PHI, run the analysis, and keep it current.
Addressable is not optional
Addressable specifications - encryption, automatic logoff, integrity controls - are implemented, or the reasoning and the alternative are documented. Silence is the finding.
The BAA chain, both directions
Agreements with the covered entities above you and every subcontractor below you, tracked with dates - because your customers will ask about your vendors.
Breach notification you can actually execute
A documented process with the 60-day clock, the risk assessment for whether an incident is a breach at all, and our incident response team already on the hook.
What HIPAA actually requires of you.
Three rules do the work. Which apply depends on whether you are a covered entity or a business associate - most software companies are the latter, and the obligations still land directly on you.
Administrative safeguards
Section 164.308Risk analysis and management, workforce access and sanctions, training, contingency planning, and periodic evaluation. The largest bucket by far.
Physical safeguards
Section 164.310Facility access, workstation use and security, and device and media controls including disposal and reuse.
Technical safeguards
Section 164.312Access control, audit controls, integrity, authentication, and transmission security across systems holding ePHI.
Privacy Rule
Section 164.500+Permitted uses and disclosures, minimum necessary, individual rights of access, and notice obligations.
Breach Notification Rule
Section 164.400+The four-factor assessment, individual and HHS notification, and the 60-day outer limit for notice.
Business associate agreements
Section 164.314Contracts flowing obligations from covered entities through you and on to every subcontractor that touches PHI.
There is no such thing as HIPAA certification - no government body issues one. What you can hold is a documented, evidenced program plus an independent assessment, and that is what health-system diligence teams actually evaluate.
From scoping call to defensible program.
Two phases are gated - PHI scoping and the risk analysis. Everything downstream is only as good as knowing where PHI actually lives, and that is the question most programs answer wrong.
Map where PHI lives
Systems, vendors, backups, logs, support tooling, and the places PHI ends up that nobody documented. Scope is the whole game and this is where programs quietly fail.
Run the risk analysis
A real analysis against the mapped environment, producing ranked risks and a risk management plan - the artifact OCR asks for first and the one most companies cannot produce.
Implement the safeguards
Administrative, physical, and technical safeguards implemented and evidenced. Every addressable specification either in place or documented with its alternative.
Operate, train, and stay ready
Workforce training, periodic evaluation, BAA renewals, and a breach process that has been walked through before you need it. Diligence questionnaires answered by us.
HIPAA is $3,000 a year.
The security department is the rest.
Every other vendor in this category makes you book a demo to learn what HIPAA costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.
The people who already handed it over.
"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Real engagements. Real outcomes.
The same programme, run for teams who had no security function when they started.
A four-person team with payment data, no security function, and a Series A closing.
Read the case studyechowinHIPAA attestation held and SOC 2 underway, with the whole department owned by us.
Read the case studyThe Academy of Charter SchoolsA penetration test their IT team rode along on, plus a roadmap of what to harden.
Read the case studyHIPAA, honestly answered.
The questions that come up on every HIPAA scoping call, answered before you have to ask them.
- Can we get HIPAA certified?
- No. No government body certifies HIPAA compliance, and a vendor selling you a certificate is selling a logo. What holds up in diligence is a documented program - current risk analysis, implemented safeguards, executed BAAs - plus an independent assessment.
- We are a business associate, not a covered entity. Does HIPAA apply to us?
- Yes. Since the HITECH Act, business associates are directly liable for the Security Rule and parts of the Privacy Rule, and can be enforced against directly. Most software companies serving healthcare are business associates.
- What does OCR ask for first in an investigation?
- The risk analysis, essentially every time. A missing, stale, or narrowly scoped risk analysis is the most frequently cited failure in enforcement actions, which is why we gate on it.
- Do we need SOC 2 as well?
- Often, yes - health systems frequently ask for both, because HIPAA has no report to hand over and SOC 2 does. The control sets overlap heavily, so the second framework costs far less than the first.
- What does the $3,000 cover?
- Our work running the HIPAA program: PHI scoping, the risk analysis, safeguard implementation and evidence, BAA tracking, workforce training, and answering the diligence questionnaires your customers send.
Answer the diligence questionnaire with evidence, not adjectives.
A 30-minute call. We will tell you where your PHI actually is, what your risk analysis is missing, and what a defensible program costs - whether or not you hire us.