Back to Top Icon
HIPAA Security Rule Compliance

HIPAA Compliance for Healthcare Providers

The Security Rule is being rewritten and addressable safeguards are becoming mandatory. Shellproof builds the documented, defensible HIPAA program that holds up under an OCR investigation.

Your gap assessment includes

  • +Control review across administrative, physical, and technical safeguards
  • +Risk analysis maturity scoring against 45 CFR 164.308(a)(1)(ii)(A)
  • +Readiness review against the proposed Security Rule mandates
  • +Prioritized remediation roadmap with owners and sequencing
  • +A written summary you can present to your board or your insurer

Findings are delivered in writing, mapped safeguard by safeguard to the Security Rule standards they satisfy.

$2,190,294

Maximum annual civil monetary penalty per violation category at 2026 rates

60 Days

Deadline to notify HHS of a breach affecting 500 or more individuals

7

Addressable safeguards the proposed Security Rule update would make mandatory

The Problem

Most HIPAA programs are paperwork, not protection

A binder of policies does not satisfy the Security Rule. Federal investigations consistently turn on one question. Can you produce a current, accurate, organization-wide risk analysis, and can you show what you did about what it found.

01

The risk analysis is stale

Conducted once at implementation and never revisited as systems, vendors, locations, and staffing changed. A dated analysis is treated as no analysis.

02

Addressable was treated as optional

Encryption and multi-factor authentication were deferred without documenting a reasonable alternative. The proposed rule removes that discretion entirely.

03

Business associates are unmanaged

Signed agreements exist in a drawer, but no one verifies that vendors handling ePHI maintain the controls those agreements require.

04

Evidence is missing

Controls operate in practice but nothing proves it. Under investigation, an undocumented control is an absent control.

The Risk

The Security Rule is tightening

In January 2025 the Department of Health and Human Services published a proposed rule that would remove the distinction between required and addressable implementation specifications. The comment period has closed and a final rule is anticipated in late 2026.

Organizations treating these controls as discretionary today will be remediating under a federal deadline. The organizations that assess now will be compliant before the clock starts.

  • Multi-factor authentication for remote access and privileged accounts
  • Encryption of ePHI at rest and in transit
  • A documented technology asset inventory covering every ePHI system
  • Network segmentation isolating ePHI systems from general corporate networks
  • Vulnerability scanning and annual penetration testing on a defined schedule
  • Annual testing of the incident response plan
  • An explicit annual security risk analysis

Proposed requirements as published in the January 2025 notice of proposed rulemaking. Not yet final and subject to change.

The Solution

A structured HIPAA compliance program

Shellproof builds the program, produces the evidence, and maintains it. Every deliverable maps to a specific Security Rule standard so you can answer a regulator with a document rather than an explanation.

Security Risk Analysis

An organization-wide analysis mapped to 45 CFR 164.308(a)(1)(ii)(A), covering every system, location, and vendor that creates, receives, maintains, or transmits ePHI.

Policies and Procedures

Administrative, physical, and technical safeguard documentation written against your actual operations rather than pulled from a template library.

Technical Safeguards

Access control, encryption, audit logging, and multi-factor authentication implemented and evidenced against the standards they satisfy.

Business Associate Governance

Vendor inventory, agreement review, and ongoing assurance over every third party that touches protected health information on your behalf.

Workforce Training

Role-based security awareness training with completion records and a sanction policy that is applied consistently and documented.

Incident Response and Breach Determination

A tested response plan, a defensible four-factor breach risk assessment process, and notification workflows that meet federal timelines.

The Engagement

Five phases from unknown risk to audit ready

The sequence is deliberate. Each phase produces an artifact the next phase depends on, and every artifact is something you can hand to an investigator, an insurer, or a health system partner.

01

Scope

Identify every system, location, workforce role, and vendor that touches ePHI. Nothing can be protected until it is inventoried.

02

Assess

Conduct the security risk analysis and score every safeguard against the Security Rule and the proposed mandates. Findings are rated by likelihood and impact.

03

Prioritize

Translate findings into a remediation plan with named owners, sequencing, and target dates. Highest exposure is addressed first.

04

Remediate

Implement controls, write the supporting policy, and capture evidence as the work is completed rather than reconstructing it later.

05

Sustain

Annual reassessment, continuous monitoring, and a maintained evidence library so compliance holds between assessments.

Questions

HIPAA compliance, answered directly

The rules are dense and the guidance is scattered. These are the questions healthcare providers ask before an engagement begins.

Who has to comply with HIPAA?

Covered entities, meaning health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with a covered transaction. Business associates that handle protected health information on a covered entity's behalf are directly liable as well.

Is there an official HIPAA certification?

No. The federal government does not certify or accredit organizations as HIPAA compliant, and no vendor can issue a certification that carries regulatory weight. Compliance is demonstrated through documented safeguards and the evidence that they operate, which is why the risk analysis and its supporting artifacts matter.

How often is a HIPAA risk analysis required?

The Security Rule requires an accurate and thorough assessment of risks to ePHI, updated as conditions warrant. Regulators expect it reviewed at least annually and whenever the environment changes materially, such as a new system, a new location, or an acquisition. The proposed rule would make an annual analysis an explicit requirement.

What is changing in the HIPAA Security Rule?

The Department of Health and Human Services proposed removing the addressable classification and mandating controls including multi-factor authentication, encryption of ePHI at rest and in transit, a technology asset inventory, network segmentation, vulnerability scanning, annual penetration testing, and annual incident response testing. The rule was proposed in January 2025 and has not been finalized.

What are the penalties for a HIPAA violation?

Civil monetary penalties are tiered by culpability. At 2026 rates they begin at $145 per violation where the organization did not know and could not reasonably have known, and reach $2,190,294 for willful neglect that was not corrected, with an annual cap of $2,190,294 per violation category. Criminal penalties apply to knowing misuse of protected health information.

What happens after the gap assessment?

You receive a written findings summary, safeguard-by-safeguard scoring, and a prioritized remediation roadmap sequenced by exposure. Your team can execute that roadmap internally, or Shellproof can deliver the remediation program and maintain the evidence library.

Find Out Where Your HIPAA Program Actually Stands

Request a HIPAA gap assessment. Shellproof reviews your safeguards against the Security Rule and the proposed 2026 mandates, then delivers a prioritized remediation roadmap mapped to the standards it satisfies.

Book a Meeting
Call Us
Let's Schedule a Call

To schedule an introductory call with our Experts please fill out this form.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.