UprootSecurity
Book a demo

HHS · 45 CFR Part 160 & 164 · Security & Privacy Rules

FRAMEWORK

HIPAA safeguardsthat are actually running.

There's no HIPAA certificate only safeguards you can prove or can't. Uproot maps the Security Rule to your stack, tracks every BAA, and makes ePHI access reconstructable.

Start HIPAATalk to a HIPAA lead

Median time to attestation: 45 days

·

BAA tracking & HITRUST mapping included

app.uproot.security · /framework/hipaa
HIPAASEC RULE

acme-health · HIPAA Security Rule

self-attestation · ePHI in scope

90%

safeguarded

46 met6 addressable2 open

Security Rule safeguards

54 specs

308

Administrative

22 specs · 164.308

92%

310

Physical

10 specs · 164.310

80%

312

Technical

9 specs · 164.312

96%

314

Organizational

BAAs · 164.314

88%

316

Documentation · policies

Retention · 6 yrs

100%

ePHI systems

7 mapped

BAAs on file

18 / 18

Open risks

2

ePHI access logged automatically

A new RDS instance entered scope. 164.312(b) audit logging was verified within minutes.

Safeguard categories

3

Administrative, Physical, and Technical — the structure of the HIPAA Security Rule for ePHI.

Implementation specs

54

The discrete requirements across the Security Rule. Uproot ships them pre-mapped to your systems.

Required vs addressable

R / A

Required specs are mandatory; addressable ones you implement or document why an alternative fits.

Authority

HHS OCR

Office for Civil Rights enforces it. No certificate exists — you attest and stand behind it.

Breach notice

60days

Affected individuals and HHS must be notified without unreasonable delay, within 60 days.

The Security Rule

Three safeguard families. Fifty-four specs. Zero screenshots.

The Security Rule governs electronic protected health information. Some specs are required, others addressable — meaning you implement them or document a reasonable alternative. Uproot proves the required ones from your stack and helps you justify the rest.

22 specs
308

Administrative

Security management, workforce access, training, and risk analysis — the family OCR scrutinizes hardest.

(a)(1) Risk analysis · (a)(3) Workforce access · (a)(5) Training · (a)(7) Contingency plan
Controls22 · 164.308
310

Physical

Facility, workstation, and device/media controls — largely inherited from your cloud provider's HIPAA-eligible services.

(a) Facility access · (b) Workstation use · (d) Device & media
Controls10 · 164.310
312

Technical

Access control, audit logging, integrity, and transmission security for ePHI — where you earn your HIPAA posture.

(a) Access control · (b) Audit controls · (c) Integrity · (e) Transmission
Controls9 · 164.312
314

Organizational

BAAs with every vendor that touches ePHI. Uproot tracks each one's status and expiry.

(a)(1) BAA contracts · (a)(2) Required provisions
ControlsBAAs · 164.314
316

Documentation

Written policies and procedures, kept current and retained for six years.

(b)(1) Time limit · (b)(2) Availability · (b)(2)(iii) Updates
Retention6 years · 164.316
One safeguard, end to end

After a breach, OCR asks for your audit logs. 164.312(b) is where you win or lose.

Audit controls is the spec that decides whether you can answer "who touched this record, and when." Here's how Uproot keeps that answer always available.

164.312(b) — Audit controls

Implement hardware, software, and procedural mechanisms that record and examine activity in systems containing or using ePHI. In plain terms: every access to health data must be logged, and the logs must be reviewable.

"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."

— Hiren Hasmukh, Co-Founder & CEO

164.312(b) · AUDIT CONTROLS

Record & examine ePHI activity

Last evidenced 09:14:02 UTC · 7 ePHI systems · sha256 verified

Met
01

The spec

What 164.312(b) asks for

“Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.”
02

Your ePHI scope

What we read from your systems

Uproot identifies which systems actually hold ePHI and confirms logging is on for each — not a policy that says it should be.

aws ·cloudtrail.statusrds ·audit.logs3 ·access.loggingokta ·system.log
03

Evidence collected

Tamper-evident, timestamped, retained

Log configuration, retention, and review cadence are pulled from source, hashed, and stored for the 6-year HIPAA window.

CloudTrail ·all regionsretention ·2,190 daysaccess reviews ·quarterly0 logging gaps
04

For the assessor

Read-only portal, breach-ready

Your assessor — or OCR after an incident — opens 164.312(b) and sees logging coverage, retention, and review history across every ePHI system, already assembled.

Type · Required  ·  Owner· Security  ·  Gaps · 0

SOC 2 CC7.2ISO A.8.15HITRUST 09.aa
Path to attestation

From risk analysis to a defensible HIPAA posture.

HIPAA has no certificate — the goal is a posture you can defend to a customer, a partner, or OCR. Here's the path.

Day 0

Map ePHI

Identify every system that stores, processes, or transmits ePHI. Uproot discovers them from your cloud and data inventory.

Day 1–3

Risk analysis

The 164.308(a)(1) risk analysis — the spec OCR cites most — generated from your real environment, not a template.

Day 4–20

Close & document

Required specs remediated as tickets; addressable specs implemented or justified. BAAs collected and tracked.

Day 21–45

Attestation-ready

Safeguards proven, policies retained, risk analysis signed. Ready for a customer security review or third-party assessment.

5

Ongoing

Stay defensible

Posture recomputes continuously. A new ePHI system or expired BAA pages the owner before it becomes a finding.

The checklist way
  • ×

    A risk analysis from a template that never mentions your actual systems — the #1 OCR enforcement finding

  • ×

    BAAs in someone’s inbox, expiry unknown, until a vendor breach makes it everyone’s problem

  • ×

    “We log everything” — with no way to prove it the day a device goes missing

  • ×

    Policies written once, never operated, retained in a folder no one opens

With Uproot
  • A risk analysis built from your real ePHI systems, updated as they change

  • Every BAA tracked with status and expiry, owners paged before lapse

  • Audit logging verified continuously on every system in scope — breach-ready by default

  • Policies tied to operating evidence, retained for the full six years automatically

Evidence map

Where the Security Rule actually lives. Uproot reads it there.

A partial map of the Technical and Administrative safeguards — pulled from the systems that protect ePHI, hashed and timestamped.

312

Access & auth

  • Okta · unique IDs + MFA

    312

  • AWS · IAM ePHI scope

    least-priv

  • RDS · auto-logoff

    on

  • Okta · emergency access

    break-glass

312

Audit & integrity

  • CloudTrail · multi-region

    on

  • RDS · audit logging

    enabled

  • S3 · object lock

    WORM

  • KMS · encryption at rest

    all

308

Administrative

  • Uproot · risk analysis

    live

  • Rippling · workforce access

    312

  • KnowBe4 · HIPAA training

    98%

  • AWS · backup + DR plan

    tested

314

BAAs & vendors

  • AWS · BAA signed

    on file

  • Twilio · BAA signed

    on file

  • Datadog · BAA signed

    on file

  • Vendor inventory

    18 / 18

Assessment partners

No certificate exists. A credible assessment does.

HIPAA can't be "certified" — but a third-party assessment (or a HITRUST certification built on it) is what most partners actually accept. Uproot gives your assessor a read-only portal scoped to your ePHI environment.

Coalfire

assessor

Clearwater

hipaa specialist

Schellman

hitrust

A-LIGN

hitrust

KirkpatrickPrice

assessor

Intraprise Health

hipaa specialist

Sensiba

assessor

Prescient

hitrust

BARR Advisory

assessor

Tevora

assessor

Sword GRC

assessor

+ 16 more

on request

HIPAA, plainly

Questions we get every week. Answered the way an engineer would.

Can I get "HIPAA certified"?+

No. There is no official HIPAA certification — HHS doesn't issue one. You attest to compliance and stand behind it. Many companies layer a HITRUST certification or a third-party assessment on top to give partners something concrete.

What's "required" vs "addressable"?+

Required specs must be implemented as written. Addressable specs give you flexibility: implement them, or document why a reasonable alternative is appropriate for your environment. Addressable does not mean optional.

What's a BAA and why does it matter?+

A Business Associate Agreement is the contract required with any vendor that handles ePHI on your behalf. Without one, sharing ePHI is itself a violation. Uproot tracks every BAA’s status and expiry so none lapse silently.

Does AWS / GCP make me HIPAA compliant?+

No — they make it possible. You sign their BAA and use only HIPAA-eligible services, but the safeguards on top are yours. Uproot proves that those safeguards are actually configured and operating.

How does HIPAA relate to SOC 2?+

They share a lot of technical ground — access control, logging, encryption, risk management. If you run SOC 2 with Uproot, you've already evidenced most of the HIPAA Security Rule's technical safeguards.

What's the risk analysis everyone mentions?+

164.308(a)(1) requires an accurate, thorough risk analysis of ePHI. It's the single most-cited finding in OCR enforcement. Uproot generates it from your real systems and keeps it current, instead of a one-time template.

Prove the safeguards. Skip the theater.

Map your ePHI in minutes, generate a real risk analysis by lunch, and keep every BAA and audit log provable. When a partner or OCR asks, the answer is already assembled.

Start HIPAATalk to a HIPAA lead
$uproot init --framework hipaa
discovering ePHI systems7
generating 164.308 risk analysisok
46 of 54 specs met · 18 BAAs tracked90%
posture ready in 4m 51slive