UprootSecurity
Book a demo

HHS · 45 CFR Part 160 & 164 · Security & Privacy Rules

FRAMEWORK

HIPAA compliance,explained and automated.

There's no HIPAA certificate only safeguards you can prove or can't. Uproot maps the Security Rule to your stack, tracks every BAA, and makes ePHI access reconstructable.

Start HIPAATalk to a HIPAA lead

Median time to attestation: 45 days

·

BAA tracking & HITRUST mapping included

app.uproot.security · /framework/hipaa
HIPAASEC RULE

acme-health · HIPAA Security Rule

self-attestation · ePHI in scope

90%

safeguarded

46 met6 addressable2 open

Security Rule safeguards

54 specs

308

Administrative

22 specs · 164.308

92%

310

Physical

10 specs · 164.310

80%

312

Technical

9 specs · 164.312

96%

314

Organizational

BAAs · 164.314

88%

316

Documentation · policies

Retention · 6 yrs

100%

ePHI systems

7 mapped

BAAs on file

18 / 18

Open risks

2

ePHI access logged automatically

A new RDS instance entered scope. 164.312(b) audit logging was verified within minutes.

HIPAA & Healthcare

Who counts as a business associate?

A business associate is any vendor that creates, receives, maintains, or transmits protected health information on your behalf hosting, analytics, billing, support tooling. Each one needs a signed BAA before it touches PHI, and their breach becomes your breach.

Last reviewed

Safeguard categories

3

Administrative, Physical, and Technical — the structure of the HIPAA Security Rule for ePHI.

Implementation specs

54

The discrete requirements across the Security Rule. Uproot ships them pre-mapped to your systems.

Required vs addressable

R / A

Required specs are mandatory; addressable ones you implement or document why an alternative fits.

Authority

HHS OCR

Office for Civil Rights enforces it. No certificate exists — you attest and stand behind it.

Breach notice

60days

Affected individuals and HHS must be notified without unreasonable delay, within 60 days.

The Security Rule

Three safeguard families. Fifty-four specs. Zero screenshots.

The Security Rule governs electronic protected health information. Some specs are required, others addressable — meaning you implement them or document a reasonable alternative. Uproot proves the required ones from your stack and helps you justify the rest.

22 specs
308

Administrative

Security management, workforce access, training, and risk analysis — the family OCR scrutinizes hardest.

(a)(1) Risk analysis · (a)(3) Workforce access · (a)(5) Training · (a)(7) Contingency plan
Controls22 · 164.308
310

Physical

Facility, workstation, and device/media controls — largely inherited from your cloud provider's HIPAA-eligible services.

(a) Facility access · (b) Workstation use · (d) Device & media
Controls10 · 164.310
312

Technical

Access control, audit logging, integrity, and transmission security for ePHI — where you earn your HIPAA posture.

(a) Access control · (b) Audit controls · (c) Integrity · (e) Transmission
Controls9 · 164.312
314

Organizational

BAAs with every vendor that touches ePHI. Uproot tracks each one's status and expiry.

(a)(1) BAA contracts · (a)(2) Required provisions
ControlsBAAs · 164.314
316

Documentation

Written policies and procedures, kept current and retained for six years.

(b)(1) Time limit · (b)(2) Availability · (b)(2)(iii) Updates
Retention6 years · 164.316
Path to attestation

From risk analysis to a defensible HIPAA posture.

HIPAA has no certificate — the goal is a posture you can defend to a customer, a partner, or OCR. Here's the path.

Day 0

Map ePHI

Identify every system that stores, processes, or transmits ePHI. Uproot discovers them from your cloud and data inventory.

Day 1–3

Risk analysis

The 164.308(a)(1) risk analysis — the spec OCR cites most — generated from your real environment, not a template.

Day 4–20

Close & document

Required specs remediated as tickets; addressable specs implemented or justified. BAAs collected and tracked.

Day 21–45

Attestation-ready

Safeguards proven, policies retained, risk analysis signed. Ready for a customer security review or third-party assessment.

5

Ongoing

Stay defensible

Posture recomputes continuously. A new ePHI system or expired BAA pages the owner before it becomes a finding.

The checklist way
  • ×

    A risk analysis from a template that never mentions your actual systems — the #1 OCR enforcement finding

  • ×

    BAAs in someone’s inbox, expiry unknown, until a vendor breach makes it everyone’s problem

  • ×

    “We log everything” — with no way to prove it the day a device goes missing

  • ×

    Policies written once, never operated, retained in a folder no one opens

With Uproot
  • A risk analysis built from your real ePHI systems, updated as they change

  • Every BAA tracked with status and expiry, owners paged before lapse

  • Audit logging verified continuously on every system in scope — breach-ready by default

  • Policies tied to operating evidence, retained for the full six years automatically

Evidence map

Where Security Rule evidence actually lives in your stack.

A partial map of the Technical and Administrative safeguards — pulled from the systems that protect ePHI, hashed and timestamped.

312

Access & auth

  • Okta · unique IDs + MFA

    312

  • AWS · IAM ePHI scope

    least-priv

  • RDS · auto-logoff

    on

  • Okta · emergency access

    break-glass

312

Audit & integrity

  • CloudTrail · multi-region

    on

  • RDS · audit logging

    enabled

  • S3 · object lock

    WORM

  • KMS · encryption at rest

    all

308

Administrative

  • Uproot · risk analysis

    live

  • KnowBe4 · HIPAA training

    98%

  • AWS · backup + DR plan

    tested

314

BAAs & vendors

  • AWS · BAA signed

    on file

  • Twilio · BAA signed

    on file

  • Datadog · BAA signed

    on file

  • Vendor inventory

    18 / 18

Assessment partners

No certificate exists. A credible assessment does.

HIPAA can't be "certified" — but a third-party assessment (or a HITRUST certification built on it) is what most partners actually accept. Uproot gives your assessor a read-only portal scoped to your ePHI environment.

Auro Security

CPA FIRM

Atom Audit

CPA FIRM

Cert Pro

CPA FIRM

Johanson Group

CPA FIRM

Prescient Security

CPA FIRM

Tempo audits

CPA FIRM

A-lign

CPA FIRM

MJD Advisors

CPA FIRM

Attinkom

CPA FIRM

Darata

CPA FIRM

Glocert

CPA FIRM

+ 23 more

on request

Everything on HIPAA & Healthcare

12 articles

HIPAA Security Rule, covered entities, PHI handling and healthcare compliance.

What HIPAA covers

The law, who it applies to, and what counts as protected health information.

  • What is HIPAA Compliance? A Complete Guide for Healthcare Tech

PHI, PII and adjacent regimes

Where health data ends and other regulated data begins.

Tooling and help

Software and consultants, if you would rather not run it alone.

HIPAA, plainly

Questions we get every week. Answered the way an engineer would.

Can I get "HIPAA certified"?+

No. There is no official HIPAA certification — HHS doesn't issue one. You attest to compliance and stand behind it. Many companies layer a HITRUST certification or a third-party assessment on top to give partners something concrete.

What's "required" vs "addressable"?+

Required specs must be implemented as written. Addressable specs give you flexibility: implement them, or document why a reasonable alternative is appropriate for your environment. Addressable does not mean optional.

What's a BAA and why does it matter?+

A Business Associate Agreement is the contract required with any vendor that handles ePHI on your behalf. Without one, sharing ePHI is itself a violation. Uproot tracks every BAA’s status and expiry so none lapse silently.

Does AWS / GCP make me HIPAA compliant?+

No — they make it possible. You sign their BAA and use only HIPAA-eligible services, but the safeguards on top are yours. Uproot proves that those safeguards are actually configured and operating.

How does HIPAA relate to SOC 2?+

They share a lot of technical ground — access control, logging, encryption, risk management. If you run SOC 2 with Uproot, you've already evidenced most of the HIPAA Security Rule's technical safeguards.

What's the risk analysis everyone mentions?+

164.308(a)(1) requires an accurate, thorough risk analysis of ePHI. It's the single most-cited finding in OCR enforcement. Uproot generates it from your real systems and keeps it current, instead of a one-time template.

Prove the safeguards. Skip the theater.

Map your ePHI in minutes, generate a real risk analysis by lunch, and keep every BAA and audit log provable. When a partner or OCR asks, the answer is already assembled.

Start HIPAATalk to a HIPAA lead
$uproot init --framework hipaa
discovering ePHI systems7
generating 164.308 risk analysisok
46 of 54 specs met · 18 BAAs tracked90%
posture ready in 4m 51slive