Skip to content

Support HIPAA readiness with adaptive compliance

For software vendors handling health data, HIPAA arrives through your customers' contracts — and lands on you directly. See how growing teams evidence the Security Rule without a certification to point at.

HIPAA Controls2

HIPAA: Prove you safeguard ePHI, continuously

Unified by design. Built for the AI era.

Iru AI is designed from the ground up to connect a grid of agents behind the scenes—across identity, endpoint, and compliance. Powered by the Iru Context Model, it understands your users, apps, and devices to act safely, intelligently, and in context across your organization.

Iru combines native endpoint and identity telemetry with continuous evidence collection, making it easier to implement the Security Rule's technical safeguards and keep evidencing that they work.

Implement the Security Rule safeguards, don't just document them

Full Iru platform vs standalone compliance tools
Iru
Standalone compliance tools

Automate evidence collection

Automatically pull evidence from connected sources via Iru Compliance Automation — §164.316

Answer customer security reviews

Share your security posture through a public-facing portal via Iru Trust Center — §164.308(b)

Encrypt ePHI on every device

Apply full-disk encryption and maintain a live record of which devices are protected, via Iru Endpoint Management — §164.312(a)(2)(iv)

Control who can access ePHI

Device-bound authentication, separated admin accounts, and access removed when people leave, via Iru Workforce Identity — §164.312(a), (d)

Protect against malicious software

Detect and contain threats on managed devices via Iru Endpoint Detection & Response — §164.308(a)(5)(ii)(B)

Respond to security incidents

Identify, contain, and document incidents and their outcomes via Iru Endpoint Detection & Response — §164.308(a)(6)

Control devices and media

Track hardware carrying ePHI and enforce secure disposal and reuse via Iru Endpoint Management — §164.310(d)

Keep evaluating that safeguards work

Continuous evidence that safeguards are operating, not just that they were configured, via Iru Compliance Automation — §164.308(a)(8)

Customize HIPAA controls for your unique business

Most compliance tools turn frameworks into generic checklists. Iru generates controls that are specific to your organization, in plain language, broken down into sub-tasks.

  • Iru AI generates tailored controls, based on your company context and audit details
  • You can migrate existing controls over from other products, or upload your own custom control set
  • Controls become actions the moment they are created, with suggested owners and due dates
HIPAA actions2

Automate your HIPAA evidence collection

For connected and activated sources, Iru can discover and attach relevant artifacts to the supported control actions, reducing manual uploads. And because you can manage your devices and identity within Iru, that data is pulled natively.

  • Evidence flows in continuously from supported devices, integrations and systems
  • Iru AI helps to identify stale, missing or potentially irrelevant evidence for you to review
  • You're ready when a security review or an OCR inquiry arrives — neither of which has a predictable schedule
HIPAA evidence2

Constantly help to evidence HIPAA year-round

Iru's Adaptive Compliance capabilities watch for changes in your organization, and automatically suggest updates to your controls and actions.

  • Iru AI regularly checks for changes to your sources, artifacts or company profile
  • If a change is detected, a control update recommendation is surfaced for you to review, often within 24 hours
  • No changes are made without your approval, and every change is logged for review
HIPAA adaptive2

Turn HIPAA preparation into an always-on workflow

Iru's AI-powered compliance solution helps IT, security and GRC teams spend less time on manual compliance work and stay audit-ready all year.

Let your team focus 
on what matters

Iru replaces fragmented tools with one AI-powered platform, so IT & security spend less time chasing tickets and more time improving the business.

Frequently asked
questions

Get answers to commonly asked questions

Who writes and enforces HIPAA?

HIPAA is a federal statute. The rules implementing it are written by the Department of Health and Human Services and enforced by its Office for Civil Rights. State attorneys general can also bring HIPAA enforcement actions.

The Security Rule itself lives at 45 CFR Part 160 and Part 164, Subparts A and C.

Does HIPAA apply to us if we're a software vendor, not a healthcare provider?

If you create, receive, maintain, or transmit ePHI on behalf of a covered entity, yes — you're a business associate, and the Security Rule applies to you directly.

 

Before 2013, the Security Rule reached business associates only indirectly, through the contract with their customer. The HITECH Act changed that: the Security Rule's safeguards, policies and procedures, and documentation requirements now apply to business associates in the same manner as they apply to covered entities, and HHS can enforce against you directly. Business associates are civilly and criminally liable for violations.

It also flows downhill. If you use subcontractors who touch ePHI, you're required to get business associate agreements from them.

 

 

What does the Security Rule actually require?

Four things, at the top level: ensure the confidentiality, integrity, and availability of all ePHI you create, receive, maintain, or transmit; protect against reasonably anticipated threats; protect against impermissible uses and disclosures; and ensure your workforce complies.

Underneath that sit three categories of safeguard:

  • Administrative — risk analysis and risk management, an assigned security official, workforce security, access management, training, incident procedures, contingency planning, and periodic evaluation
  • Physical — facility access controls, workstation use and security, and device and media controls
  • Technical — access control, audit controls, integrity, authentication, and transmission security

Everything starts with the risk analysis. HHS is explicit that it "affects the implementation of all of the safeguards" — what's reasonable and appropriate for you depends on what your risk analysis found.

What's the difference between "required" and "addressable"?

Addressable does not mean optional. This is the most common and most expensive misconception in HIPAA.

Every Security Rule standard is mandatory. Within those standards, individual implementation specifications are marked required or addressable. Where an addressable specification is reasonable and appropriate for you, you must implement it. Where it isn't, you must adopt an alternative measure that achieves the same purpose — and document why the original wasn't reasonable and appropriate.

Encryption of ePHI at rest is currently addressable, which is why some organizations skip it. Skipping it without a documented, defensible rationale is not compliance; it's an unwritten decision waiting to be found.

 

Can we get "HIPAA certified"?

No. There is no HIPAA certification, and no body — government or private — that can confer one.

You will see vendors and consultancies selling "HIPAA certification." What they're selling is their own assessment against their own interpretation. While it may be useful preparation, it is not a credential a regulator or a sophisticated customer will treat as dispositive.

What actually holds up is documented evidence: a current risk analysis, implemented safeguards, and records showing they operate.

What are the penalties?

Civil monetary penalties are tiered by culpability — running from violations the entity did not know about and could not reasonably have known about, through reasonable cause, up to willful neglect. The maximum penalties apply to willful neglect that goes uncorrected. Criminal penalties are also available for knowing misuse of PHI.

Penalty amounts are adjusted annually for inflation, so check the current figures rather than relying on a number from an article.

Beyond penalties, OCR resolution agreements typically impose multi-year corrective action plans with ongoing reporting obligations — which in practice cost more than the settlement.

 

Do we have to report a breach, and how fast?

Yes, and as a business associate your obligation runs to your customer, not directly to individuals.

Under the Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI. The covered entity then handles notification to affected individuals, to HHS, and in some cases to the media. Your business associate agreement will also require you to report security incidents to the covered entity — a broader category than breaches.

Two important points: your BAA may impose a tighter deadline than the regulation does, so read it. And the clock runs from discovery, which means detection capability determines whether you can meet it.


 

What is a BAA, and do we need one?

A business associate agreement is the written contract a covered entity must have in place before letting you create, receive, maintain, or transmit ePHI on its behalf.

It has to document satisfactory assurances that you'll safeguard the information, commit you to complying with the Security Rule, require you to get equivalent agreements from any subcontractors who touch ePHI, and obligate you to report security incidents — including breaches — to the covered entity.

Signing one doesn't create your obligations; the Security Rule already applies to you directly. What the BAA does is make those obligations contractual as well as regulatory, which means a customer can act on them without waiting for OCR.

Is the Security Rule changing?

A significant update has been proposed, but it is not in force.

 

In December 2024, OCR issued a Notice of Proposed Rulemaking that would substantially modernize the Security Rule. Among the proposals: removing the required/addressable distinction and making nearly all specifications mandatory; requiring encryption of ePHI at rest and in transit; requiring multi-factor authentication; requiring a technology asset inventory and network map reviewed at least every 12 months; requiring vulnerability scanning at least every six months and penetration testing annually; requiring anti-malware deployment and removal of extraneous software; and requiring business associates to verify their technical safeguards annually through a written analysis and certification to their customers.

HHS has been explicit throughout: "while the Department is undertaking this rule-making, the current Security Rule remains in effect."

The direction of travel is clear, and most of what's proposed is what a mature security program does anyway.

Does SOC 2 or ISO 27001 make us HIPAA compliant?

No — but they overlap substantially with the Security Rule, and the evidence is largely reusable.

Access control, encryption, vulnerability management, incident response, and workforce training appear in all three. What SOC 2 and ISO 27001 don't cover is anything HIPAA-specific: the risk analysis in the form HHS expects, business associate agreements, the Privacy Rule, and breach notification obligations.

Most customers asking for HIPAA assurance will accept a SOC 2 report as supporting evidence. None of them will accept it as a substitute for a BAA.

Can Iru make us HIPAA compliant?

No, and treat anyone who says they can with suspicion. HIPAA compliance depends on your risk analysis, your policies, your contracts, your workforce, and decisions no platform makes for you.

What Iru's entire platform does is the technical safeguards side of the Security Rule. The platform enforces encryption and access control on the devices and identities that touch ePHI, detects and contains security incidents, and produces the documented evidence that those safeguards are operating — which is what a customer's security review, or OCR after an incident, will ask you to produce.

If you'd like to see how that works, book a demo. Existing customers can reach out to their rep.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.