Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

HIPAA: the risk analysis is not optional.

A HIPAA compliance consultant in India is almost always working for a business associate rather than a covered entity: an Indian software, analytics, billing or support company handling protected health information for a US healthcare client. The obligations reach you through a business associate agreement, and since the HITECH Act they also reach you directly.

The single most cited failure in HIPAA enforcement is the absence of an accurate, thorough, organisation-wide risk analysis. It is an explicit requirement of the Security Rule, it is the first thing regulators ask for, and it is the foundation on which every other safeguard decision rests, because the Rule deliberately lets you choose safeguards proportionate to your assessed risk.

We run that analysis properly, implement the administrative, physical and technical safeguards it justifies, get the business associate agreements right in both directions, and build the breach notification process the Rule requires. Where the same environment needs broader assurance, SOC 2 and ISO 27001:2022 reuse most of the evidence.

Why you need it

01 / 06

Why business associates are in scope.

01

The obligation reaches you directly.

Since the HITECH Act and the Omnibus Rule, business associates are directly liable for Security Rule compliance and for breach notification, not merely contractually bound to their covered entity. Enforcement can be brought against you regardless of where you are established.

02

The agreement is signed before the controls exist.

Business associate agreements are executed early in a commercial relationship and commit you to safeguards, breach reporting timelines, subcontractor flow-down and, frequently, audit rights. Signing one you cannot yet honour is a common and avoidable exposure.

03

Health data has a long tail of value.

Medical records combine identity, financial and clinical information and cannot be reissued the way a card number can. That makes healthcare a persistent target and makes the consequences of a breach durable.

04

Subcontractors inherit everything.

Any subcontractor of a business associate that creates, receives, maintains or transmits PHI is itself a business associate and needs its own agreement. Cloud providers, support vendors and offshore development partners are all in this chain.

Instrument

02 / 06

Where HIPAA safeguards overlap what you have.

Access control, encryption, logging and incident response are asked for by several regimes at once. The overlap is work you only do once.

What we deliver

03 / 06

What we deliver.

01

Security Rule risk analysis

The accurate and thorough assessment the Rule requires: where PHI is created, received, maintained and transmitted; the threats and vulnerabilities to it; the likelihood and impact of each; and the current controls. Documented to withstand regulatory scrutiny, and the basis for everything that follows.

02

Administrative safeguards

Security management process and risk management, assigned security responsibility, workforce security and authorisation, security awareness and training, incident procedures, contingency planning, and periodic evaluation.

03

Physical safeguards

Facility access controls, workstation use and security, and device and media controls, including the disposal and re-use procedures that catch out organisations with distributed or home-based staff.

04

Technical safeguards

Access control with unique user identification and emergency access, audit controls, integrity controls, person or entity authentication, and transmission security. Addressable specifications are implemented or the alternative documented, never simply skipped.

05

Business associate agreements

Reviewing what you have signed with covered entities, and putting agreements in place with every subcontractor that touches PHI. Includes an inventory of where PHI actually flows, which is usually wider than the contract assumes.

06

Breach notification readiness

The four-factor risk assessment for determining whether an impermissible use or disclosure is a reportable breach, notification procedures and timelines, documentation, and the contractual reporting obligations you owe your covered entity, which are typically far shorter than the regulatory deadline.

How we run it

04 / 06

Six steps.

  1. 01

    Risk assessment

    The Security Rule risk analysis: PHI inventory and flows, threats and vulnerabilities, current safeguards, and residual risk rated and documented. Everything else derives from this, and regulators ask for it first.

    Weeks 1-4
  2. 02

    Implement safeguards

    Administrative, physical and technical safeguards proportionate to the assessed risk, with each addressable specification either implemented or its documented alternative recorded.

    Months 1-4
  3. 03

    Document policies

    The policy and procedure set the Rule requires, written to describe what you actually do, with the six-year retention obligation for documentation built into how they are kept.

    Months 2-4
  4. 04

    Workforce training

    Security awareness and training for everyone who can reach PHI, with completion recorded. The records are themselves required evidence, and they are frequently what is missing.

    Month 4, then periodically
  5. 05

    Breach notification process

    The four-factor assessment, notification procedures and timelines to your covered entity and, where you are the covered entity, to individuals and the regulator. Rehearsed rather than merely written.

    Month 4
  6. 06

    Regular audits

    Periodic evaluation as the Rule requires, with the risk analysis refreshed on any material change to systems, data flows or the environment.

    Annually, and on change

Key benefits

05 / 06

What changes after.

The document regulators ask for exists

A current, documented, organisation-wide risk analysis, the single most commonly missing artefact in HIPAA enforcement actions.

Your BAAs are honourable

The safeguards, subcontractor agreements and reporting timelines you have committed to are actually in place, in both directions along the chain.

Healthcare clients can proceed

Documented safeguards, training records and breach procedures answer the diligence a covered entity is obliged to perform before sending you PHI.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Regulation

  • HIPAA Security Rule (45 CFR Part 164 Subpart C)
  • HIPAA Privacy Rule
  • Breach Notification Rule
  • HITECH Act

Risk analysis

  • NIST SP 800-66
  • NIST SP 800-30
  • PHI inventory and data-flow mapping

Technical safeguards

  • Encryption at rest and in transit
  • Audit log collection and review
  • Unique user identification and access review

Documentation

  • Policy set with six-year retention
  • Training completion records
  • Business associate agreement register

Mapping

  • ISO 27001:2022 Annex A
  • SOC 2 Trust Services Criteria

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about HIPAA.

We are an Indian company. Does HIPAA really apply to us?
If you create, receive, maintain or transmit protected health information on behalf of a US covered entity, you are a business associate, and since HITECH you are directly liable for Security Rule compliance and breach notification. Location does not exempt you. You will also be bound contractually through a business associate agreement, which typically imposes tighter timelines than the regulation itself.
Is there a HIPAA certification?
No. There is no government-issued HIPAA certification and any vendor offering one is selling something the regulation does not recognise. What exists is demonstrable compliance: a current risk analysis, implemented safeguards, documented policies, training records and a working breach process. Third-party attestations such as SOC 2 or HITRUST are frequently used as evidence alongside that, and they are not the same as certification.
What does "addressable" mean in the Security Rule?
It does not mean optional. For an addressable implementation specification you must assess whether it is reasonable and appropriate in your environment; if it is, you implement it. If it is not, you must document why and implement an equivalent alternative measure where reasonable. Skipping an addressable specification without that documented analysis is exactly the finding enforcement actions cite. Encryption is the most common example.
How quickly must we report a breach?
Two clocks, and the contractual one usually runs faster. As a business associate you must notify your covered entity without unreasonable delay and no later than 60 days from discovery, but most business associate agreements specify considerably shorter, often 24 to 72 hours, so read yours. Covered entities notify individuals without unreasonable delay and within 60 days, with regulator and, for larger breaches, media notification obligations on top.
Can our HIPAA work count toward SOC 2 or ISO 27001?
Substantially. Access control, encryption, audit logging, incident response, workforce training, contingency planning and vendor management are common to all three, and we map the control set so one implementation serves each. What does not transfer is the HIPAA-specific machinery: the risk analysis in its required form, business associate agreements, and the four-factor breach assessment, which has no equivalent in the other frameworks.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.