HIPAA compliance, explained end to end. What it is, who it applies to, the rules and safeguards it requires, and how a lean team actually achieves and maintains it. This is the overview that ties the whole picture together.
TL;DR
HIPAA compliance means meeting the US law that protects health information: following the Privacy, Security, and Breach Notification Rules, implementing administrative, physical, and technical safeguards, and keeping evidence that it all works. It applies to covered entities and their business associates.
It is not a one-time certificate but an ongoing program anchored by a risk analysis. For a lean team, the practical route is one platform that provides the controls and the evidence together, mapped to HIPAA.
On this page
What HIPAA compliance is
HIPAA, the Health Insurance Portability and Accountability Act, is the US law that governs how protected health information is used and protected. Compliance means meeting its requirements: following its rules, putting safeguards in place around health data, and being able to demonstrate that you do. It applies to organisations that handle PHI and is enforced by the HHS Office for Civil Rights. Importantly, HIPAA compliance is a continuous state, not a certificate you earn once and file away.
Who must comply with HIPAA
HIPAA divides the world into two groups. Covered entities are healthcare providers, health plans, and healthcare clearinghouses, the organisations at the centre of care and payment. Business associates are the vendors and partners that handle PHI on a covered entity’s behalf, which includes most healthtech and SaaS companies serving healthcare. If you are either, HIPAA applies to you, and business associates carry direct compliance obligations, not just contractual ones.
The core rules of HIPAA
HIPAA compliance is built on three central rules, each governing a different aspect of protecting health information.
| Rule | What it governs |
|---|---|
| Privacy Rule | How PHI may be used and disclosed, and patients’ rights over it |
| Security Rule | Safeguards for electronic PHI: administrative, physical, technical |
| Breach Notification Rule | What to do and whom to notify when PHI is breached |
The Privacy Rule sets the boundaries on using health data, the Security Rule mandates how electronic PHI must be protected, and the Breach Notification Rule defines your obligations when something goes wrong. Together they form the backbone of compliance.
The safeguards HIPAA requires
The Security Rule organises its protections into three categories of safeguards, and a compliant program needs all three.
Administrative safeguards are the policies, procedures, and workforce controls that manage security. Physical safeguards protect facilities, devices, and media. Technical safeguards, access control, encryption, audit logging, and transmission security, protect ePHI in your systems. A gap in any category is a gap in compliance.
How to achieve HIPAA compliance
Achieving compliance follows a logical sequence. It starts with a risk analysis, the foundational, most-scrutinised requirement, which identifies risks to your PHI. From there you implement safeguards to address those risks, document policies and procedures, sign BAAs with vendors, train your workforce, and collect the evidence that proves each control operates. The order matters: the risk analysis tells you what the rest of the program needs to be.
Staying compliant over time
Because compliance is a continuous state, the work does not end at implementation. You maintain it by keeping evidence current, reviewing and updating your risk analysis as you grow, monitoring controls, retraining your workforce, and keeping BAAs and policies up to date. HIPAA compliance that was real a year ago can lapse quietly if nothing maintains it, which is why continuous monitoring and evidence matter as much as the initial build.
The lean-team path to HIPAA compliance
Seen whole, HIPAA compliance is a lot of connected parts, rules, safeguards, evidence, and ongoing upkeep, and most of the technical load is repeatable work that a small team should not hand-assemble across disconnected tools. Consolidation is what makes the whole program achievable without a dedicated security function.
Achieve and maintain HIPAA compliance, end to end.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Put the safeguards, evidence, training, and monitoring of a full HIPAA program on one platform. No security team required.
Frequently asked questions
What is HIPAA compliance?
Meeting the US law that protects health information: following the Privacy, Security, and Breach Notification Rules, implementing administrative, physical, and technical safeguards for PHI, and keeping evidence that it all works. It is an ongoing state, not a one-time certificate.
Who has to comply with HIPAA?
Covered entities, healthcare providers, health plans, and clearinghouses, and their business associates, the vendors and partners that handle PHI on their behalf. Most healthtech and SaaS companies serving healthcare are business associates with direct obligations.
What are the main HIPAA rules?
The Privacy Rule, governing how PHI is used and disclosed and patients’ rights; the Security Rule, requiring safeguards for electronic PHI; and the Breach Notification Rule, defining what to do when PHI is breached. Together they form the core of compliance.
How do you become HIPAA compliant?
Start with a risk analysis, then implement safeguards to address the risks, document policies, sign BAAs with vendors, train your workforce, and collect evidence that each control operates. The risk analysis anchors and directs the rest of the program.
Is HIPAA compliance a one-time thing?
No. It is a continuous state. You must maintain evidence, review your risk analysis, monitor controls, retrain staff, and keep BAAs and policies current. Compliance can lapse quietly if nothing maintains it, so ongoing monitoring is essential.
Is there a HIPAA certificate?
No official HIPAA certification exists. Compliance is a state you maintain and can demonstrate through your controls and evidence, not a certificate issued by the government. Beware any claim to sell you an official HIPAA certification.

