Skip to main content

Secure Minds System

HIPAA Compliance Consulting

HIPAA Compliance Consulting

Secure Minds runs HIPAA compliance engagements for covered entities and business associates — Security Rule risk analysis, Privacy Rule policy alignment, safeguards implementation, and Business Associate Agreement (BAA) review. This is practitioner-led work, delivered by consultants with 15+ years of hands-on GRC implementation experience supporting US healthcare clients and their offshore business associates.

Current Rule vs. the Proposed 2025 Update — Don’t Confuse the Two

The Security Rule in force today is the 45 CFR Part 164, Subpart C framework last substantively revised in 2013 (the HIPAA Omnibus Rule). A Notice of Proposed Rulemaking to overhaul the Security Rule was published in the Federal Register on 6 January 2025, with the public comment period closing 7 March 2025. As of today, HHS/OCR has not issued a final rule — OMB’s Unified Agenda now targets July 2027 for final action, pushed back from an earlier spring-2026 target, and that date is not binding and could shift again. Everything below distinguishes clearly between what’s mandatory now and what’s proposed.

The Security Rule: Three Safeguard Categories (Currently in Force)

Category 45 CFR Reference Covers
Administrative Safeguards § 164.308 Security management process, assigned security responsibility, workforce security, information access management, training, incident procedures, contingency planning, business associate contracts
Physical Safeguards § 164.310 Facility access controls, workstation use and security, device and media controls
Technical Safeguards § 164.312 Access control, audit controls, integrity controls, person/entity authentication, transmission security
Policies, Procedures & Documentation § 164.316 Written policy requirements and documentation retention supporting all three safeguard categories

Under the current rule, most implementation specifications are labeled “required” or “addressable.” Addressable does not mean optional — it means the entity must assess whether the specification is reasonable and appropriate and, if not implementing it as-is, document an equivalent alternative or a justified reason not to. Auditors treat undocumented addressable-specification decisions as findings.

Privacy Rule vs. Security Rule — Not the Same Obligation

The Privacy Rule (45 CFR Part 164, Subpart E) governs how Protected Health Information (PHI) in any form may be used and disclosed, patient rights of access and amendment, and minimum-necessary standards. The Security Rule (Subpart C) governs only electronic PHI (ePHI) and the administrative, physical, and technical safeguards protecting it. A compliance program addressing only one of the two has a real gap — we scope engagements to cover both where the client handles PHI in non-electronic form (paper records, verbal disclosures) as well as ePHI.

What the Proposed Rule Would Change (Not Yet in Force)

If finalized as proposed, the update would eliminate the addressable/required distinction entirely — nearly all specifications become mandatory and auditable, with narrow, documented exceptions only. Key proposed changes include mandatory multi-factor authentication, encryption of ePHI at rest and in transit, network segmentation, defined system-restoration timelines after an incident, and annual written verification (certification) from business associates confirming their technical safeguards. HHS’s own impact analysis projected roughly $9 billion in year-one industry compliance costs, which has drawn opposition from hospital associations requesting withdrawal. We track this rulemaking as part of every HIPAA engagement so clients aren’t caught flat-footed if and when it finalizes.

Our Methodology

Phase What We Deliver
Applicability & Scoping Covered entity vs. business associate determination, ePHI data flow mapping, BAA inventory review
Risk Analysis § 164.308(a)(1) risk analysis — the single most cited OCR audit finding when absent or outdated
Safeguards Implementation Administrative, physical, and technical safeguard gap remediation mapped to §§ 164.308/310/312
Privacy Rule Alignment Notice of Privacy Practices, minimum-necessary procedures, patient access/amendment workflows
Business Associate Readiness BAA review and negotiation support, subcontractor flow-down obligations, breach notification procedure (§ 164.410)

Typical Engagement Timeline

For a mid-market covered entity or business associate: risk analysis and gap assessment (3–5 weeks), safeguards and policy remediation (6–10 weeks), and BAA/documentation cleanup (2–3 weeks, run in parallel). Organizations already certified to ISO/IEC 27001:2022 or pursuing SOC 2 can reuse a substantial share of risk assessment, access control, and incident response evidence against the current Security Rule — we scope combined engagements to avoid collecting the same evidence three times.

Frequently Asked Questions

Is the new HIPAA Security Rule already in effect?
No. It remains a proposed rule as of today. The current 2013 Omnibus Rule framework (§§ 164.308, 164.310, 164.312, 164.316) is what’s enforceable and what OCR audits against right now.

Does “addressable” mean we can skip a specification?
No. You must assess and document either implementation or a justified, reasonable alternative. Undocumented gaps on addressable specifications are a standard audit finding.

We’re an Indian business associate serving US healthcare clients — does HIPAA apply to us?
Yes, if you create, receive, maintain, or transmit PHI on behalf of a US covered entity, HIPAA’s Security and Privacy Rule obligations flow down to you contractually through the Business Associate Agreement, regardless of where you’re located.

How does HIPAA relate to our ISO 27001 or SOC 2 program?
Meaningful overlap on risk assessment, access control, and incident response, but HIPAA has US-specific requirements — the risk analysis under § 164.308(a)(1), breach notification timelines under § 164.410, and BAA flow-down obligations — that neither ISO 27001 nor SOC 2 fully covers on their own.

Discuss Today to scope your HIPAA compliance engagement.