HHS · 45 CFR Part 160 & 164 · Security & Privacy Rules
FRAMEWORKThere's no HIPAA certificate only safeguards you can prove or can't. Uproot maps the Security Rule to your stack, tracks every BAA, and makes ePHI access reconstructable.
Median time to attestation: 45 days
BAA tracking & HITRUST mapping included
acme-health · HIPAA Security Rule
self-attestation · ePHI in scope
90%
safeguarded
Security Rule safeguards
54 specs
Administrative
22 specs · 164.308
92%
Physical
10 specs · 164.310
80%
Technical
9 specs · 164.312
96%
Organizational
BAAs · 164.314
88%
Documentation · policies
Retention · 6 yrs
100%
ePHI systems
7 mapped
BAAs on file
18 / 18
Open risks
2
ePHI access logged automatically
A new RDS instance entered scope. 164.312(b) audit logging was verified within minutes.
Safeguard categories
3Administrative, Physical, and Technical — the structure of the HIPAA Security Rule for ePHI.
Implementation specs
54The discrete requirements across the Security Rule. Uproot ships them pre-mapped to your systems.
Required vs addressable
R / ARequired specs are mandatory; addressable ones you implement or document why an alternative fits.
Authority
HHS OCROffice for Civil Rights enforces it. No certificate exists — you attest and stand behind it.
Breach notice
60daysAffected individuals and HHS must be notified without unreasonable delay, within 60 days.
The Security Rule governs electronic protected health information. Some specs are required, others addressable — meaning you implement them or document a reasonable alternative. Uproot proves the required ones from your stack and helps you justify the rest.
Administrative
Security management, workforce access, training, and risk analysis — the family OCR scrutinizes hardest.
Physical
Facility, workstation, and device/media controls — largely inherited from your cloud provider's HIPAA-eligible services.
Technical
Access control, audit logging, integrity, and transmission security for ePHI — where you earn your HIPAA posture.
Organizational
BAAs with every vendor that touches ePHI. Uproot tracks each one's status and expiry.
Documentation
Written policies and procedures, kept current and retained for six years.
Audit controls is the spec that decides whether you can answer "who touched this record, and when." Here's how Uproot keeps that answer always available.
Implement hardware, software, and procedural mechanisms that record and examine activity in systems containing or using ePHI. In plain terms: every access to health data must be logged, and the logs must be reviewable.
"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."
164.312(b) · AUDIT CONTROLS
Record & examine ePHI activity
Last evidenced 09:14:02 UTC · 7 ePHI systems · sha256 verified
The spec
What 164.312(b) asks for
Your ePHI scope
What we read from your systems
Uproot identifies which systems actually hold ePHI and confirms logging is on for each — not a policy that says it should be.
Evidence collected
Tamper-evident, timestamped, retained
Log configuration, retention, and review cadence are pulled from source, hashed, and stored for the 6-year HIPAA window.
For the assessor
Read-only portal, breach-ready
Your assessor — or OCR after an incident — opens 164.312(b) and sees logging coverage, retention, and review history across every ePHI system, already assembled.
Type · Required · Owner· Security · Gaps · 0
HIPAA has no certificate — the goal is a posture you can defend to a customer, a partner, or OCR. Here's the path.
Day 0
Map ePHI
Identify every system that stores, processes, or transmits ePHI. Uproot discovers them from your cloud and data inventory.
Day 1–3
Risk analysis
The 164.308(a)(1) risk analysis — the spec OCR cites most — generated from your real environment, not a template.
Day 4–20
Close & document
Required specs remediated as tickets; addressable specs implemented or justified. BAAs collected and tracked.
Day 21–45
Attestation-ready
Safeguards proven, policies retained, risk analysis signed. Ready for a customer security review or third-party assessment.
Ongoing
Stay defensible
Posture recomputes continuously. A new ePHI system or expired BAA pages the owner before it becomes a finding.
A risk analysis from a template that never mentions your actual systems — the #1 OCR enforcement finding
BAAs in someone’s inbox, expiry unknown, until a vendor breach makes it everyone’s problem
“We log everything” — with no way to prove it the day a device goes missing
Policies written once, never operated, retained in a folder no one opens
A risk analysis built from your real ePHI systems, updated as they change
Every BAA tracked with status and expiry, owners paged before lapse
Audit logging verified continuously on every system in scope — breach-ready by default
Policies tied to operating evidence, retained for the full six years automatically
A partial map of the Technical and Administrative safeguards — pulled from the systems that protect ePHI, hashed and timestamped.
Access & auth
Okta · unique IDs + MFA
312
AWS · IAM ePHI scope
least-priv
RDS · auto-logoff
on
Okta · emergency access
break-glass
Audit & integrity
CloudTrail · multi-region
on
RDS · audit logging
enabled
S3 · object lock
WORM
KMS · encryption at rest
all
Administrative
Uproot · risk analysis
live
Rippling · workforce access
312
KnowBe4 · HIPAA training
98%
AWS · backup + DR plan
tested
BAAs & vendors
AWS · BAA signed
on file
Twilio · BAA signed
on file
Datadog · BAA signed
on file
Vendor inventory
18 / 18
HIPAA can't be "certified" — but a third-party assessment (or a HITRUST certification built on it) is what most partners actually accept. Uproot gives your assessor a read-only portal scoped to your ePHI environment.
Coalfire
assessor
Clearwater
hipaa specialist
Schellman
hitrust
A-LIGN
hitrust
KirkpatrickPrice
assessor
Intraprise Health
hipaa specialist
Sensiba
assessor
Prescient
hitrust
BARR Advisory
assessor
Tevora
assessor
Sword GRC
assessor
+ 16 more
on request
No. There is no official HIPAA certification — HHS doesn't issue one. You attest to compliance and stand behind it. Many companies layer a HITRUST certification or a third-party assessment on top to give partners something concrete.
Required specs must be implemented as written. Addressable specs give you flexibility: implement them, or document why a reasonable alternative is appropriate for your environment. Addressable does not mean optional.
A Business Associate Agreement is the contract required with any vendor that handles ePHI on your behalf. Without one, sharing ePHI is itself a violation. Uproot tracks every BAA’s status and expiry so none lapse silently.
No — they make it possible. You sign their BAA and use only HIPAA-eligible services, but the safeguards on top are yours. Uproot proves that those safeguards are actually configured and operating.
They share a lot of technical ground — access control, logging, encryption, risk management. If you run SOC 2 with Uproot, you've already evidenced most of the HIPAA Security Rule's technical safeguards.
164.308(a)(1) requires an accurate, thorough risk analysis of ePHI. It's the single most-cited finding in OCR enforcement. Uproot generates it from your real systems and keeps it current, instead of a one-time template.
Map your ePHI in minutes, generate a real risk analysis by lunch, and keep every BAA and audit log provable. When a partner or OCR asks, the answer is already assembled.