The Health Insurance Portability and Accountability Act of 1996 is enforced by the Office for Civil Rights. The Privacy Rule governs use and disclosure, the Security Rule sets eighteen safeguard standards for electronic PHI, and the Breach Notification Rule runs a sixty-day clock.
Your PHI left the clinical system. The rules followed it out.
The copies in analytics, training sets and inference logs are PHI too - and in scope, on the same eighteen standards as everything else.
Our promise
“A policy is paper. The risk analysis is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditHIPAA, in three chapters
Most programmes were scoped around the clinical system, and PHI has not stayed in it. Analytics warehouses, model training sets, support tickets, prompts, inference logs and export files all hold copies - and none appear on the flow diagram drawn when the EHR went in.
OCR asks for the risk analysis first, and it is the deficiency it cites most often. We build the inventory from the systems inwards, test the eighteen standards where they are meant to bite, and hand you a finding trail that is dated, owned and evidenced rather than merely asserted.
Health data that names a person.
Eighteen identifiers, from a name to a date to a device ID - they need only be linked to health information.
- Providers, health plans and clearinghouses
- Business associates, in their own right
- Subcontractors, at every link below them
- Cloud, analytics and model vendors holding PHI
- Before PHI is shared - the BAA comes first
- On discovery, when the sixty days start running
- Whenever the estate changes shape materially
- At every review the risk analysis is meant to get
The duty is yours. So is theirs.
The covered entity at the top
A provider, a health plan or a clearinghouse handling PHI directly. The Privacy Rule, the Security Rule and the Breach Notification Rule all land in full - and choosing a business associate does not move any of them. You stay answerable for having chosen it, and for how it performs long after you have.
The people who hold it for you
A business associate creates, receives, maintains or transmits PHI on your behalf. It owes you a signed agreement - and since the Omnibus Rule it owes the Security Rule and the Breach Notification Rule directly, in its own right, rather than through your contract with it, whatever that contract says.
The chain does not end at one contract
A subcontractor handling PHI for a business associate carries direct liability too, and owes a BAA of its own. Liability follows the data down the supply chain rather than stopping where the paperwork does - which is why the inventory matters more than the contract file does, and why it always will do.
“Our vendor signed a BAA, so that is covered.”
Liability follows the data, not the contract.
It is the first thing we have to correct.
- Who it is for
- Providers & health plans
- Digital health & EHR
- Clinical AI teams
- Billing & RCM
- Cloud & analytics vendors
The Security Rule risk analysis is the most commonly cited deficiency - usually because it was done once and never revisited.
Penalties are assessed per violation, so one bad control repeated right across a large estate is not a single finding at all. It is arithmetic.
Three criminal offences sit above all of it, prosecuted by the Department of Justice on referral. Intent is what separates them.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four clocks, and the first one starts early.
Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.
-
Assess
On discoveryThe four-factor assessment starts the day the breach is known, or would have been with reasonable care.
-
Tell the individuals
Within 60 daysSixty days from discovery, not from the day the investigation closes. It does not pause while you decide.
-
Tell HHS and media
500 individualsAt or above the threshold, both go without unreasonable delay. Below it, HHS gets an annual log instead of that.
-
Revisit the analysis
ContinuouslyA risk analysis run at go-live and never revisited does not describe the estate you have today, or defend it now.
Teams start the sixty days when somebody opens a ticket. The rule starts them on discovery - the first day the breach was known, or would have been known with reasonable diligence. The clock can already be running before anyone has noticed.
What the rules say, what we ship
The Security Rule’s 18 standards, grouped by family, and the Privacy and Breach duties beside them.
- Risk analysis Administrative
- Where ePHI is created, received, maintained and transmitted; the threats to it; the measures in place; and the likelihood, impact and remediation priority of each risk. The first document an investigation asks for.
- Risk management Administrative
- The remediation the analysis called for, prioritised, owned and dated - plus the sanction policy and the review of information system activity that sit in the same standard.
- Assigned responsibility Administrative
- A named security official and a named privacy officer, both designated in writing rather than assumed, and both reachable by someone outside the organisation.
- Workforce security Administrative
- Authorisation, supervision and clearance - and the termination procedure, which is the limb that lapses first and the one an access review finds.
- Information access management Administrative
- Access authorisation, establishment and modification applied per role rather than per request, so a leaver or a mover changes one thing and not twelve.
- Awareness and training Administrative
- Security reminders, malware protection, log-in monitoring and password management - with attendance records, because the training you cannot evidence did not happen.
- Security incident procedures Administrative
- Response to and reporting of security incidents, with the route and the decision-maker defined before one happens rather than named during one.
- Contingency plan Administrative
- Data backup, disaster recovery, emergency mode operation, testing, and a criticality analysis of which applications and data actually have to come back first.
- Evaluation Administrative
- Periodic technical and non-technical evaluation of whether the safeguards still fit the estate - the standard that turns a one-off programme into a live one.
- Physical safeguards Four standards
- Facility access controls, workstation use, workstation security, and device and media controls - including disposal, re-use and what happens before a device moves.
- Technical safeguards Five standards
- Access control, audit controls, integrity, person or entity authentication, and transmission security - with the encryption decision documented either way.
- Privacy and breach duties The other two rules
- Minimum necessary, individual rights, the notice of privacy practices and the workforce sanctions behind them - plus the breach path from discovery to notification.
Health data, independently reviewed
From the EHR to the model training set.
-
Intake
Where PHI is created, received, maintained and transmitted.
-
Test
The eighteen standards against the estate, and the BAAs behind them.
-
Sign off and evidence
You see the draft first. Then the analysis, policies and drills - dated.
Why teams choose iDharma for their HIPAA review
The analysis, done right
The risk analysis OCR asks for first, scoped to the estate you have rather than to a questionnaire.
Evidence, not attestation
Every safeguard tested where it is meant to bite, and every finding dated, owned and tracked.
The whole chain covered
Business associates and their subcontractors, with agreement status and current risk.
PHI in the AI estate
Training sets, prompts and inference logs read as PHI, because that is what they hold.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
HIPAA review report
The full review: what PHI you hold, on what footing, under which rule - and where each obligation is evidenced or is not. Findings land on the Security Rule’s own eighteen standards plus the Privacy and Breach duties, ranked by consequence to patients rather than by ease of fixing, with the business associate chain stated separately.
Security Rule risk analysis
Threats and vulnerabilities to the confidentiality, integrity and availability of ePHI, with likelihood, impact and a remediation plan attached.
PHI inventory and flow map
Every system that creates, receives, maintains or transmits PHI, traced to a flow map - analytics, training sets and inference logs included.
Safeguards evidence pack
The eighteen standards tested where they are meant to bite - access control, encryption decisions, audit logging and the integrity controls.
Breach runbook and drill
Discovery to notification with the four-factor assessment written down: who decides, who drafts to OCR, and when the media threshold trips.
Business associate register
Every associate and subcontractor with agreement status, risk position and review date - the oversight both rules require and few keep current.
Policy template pack
The Privacy Rule set, the Security Rule set and the breach and compliance set - mapped across to SOC 2 and ISO 27001 so one set answers both.
Real numbers, upfront.
- Scope
- Set by the rules
- Inputs
- Your systems and your BAAs
- Re-review
- Every twelve months - $10,500 against your known baseline
The rules fixed the standards, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- The Security Rule risk analysis
- PHI inventory and flow map
- Breach runbook and one drill
- 31 policy templates, tailored
Four things you have to be able to produce
HIPAA is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The analysis,
current
A risk analysis that describes the estate you have now. It is the most commonly cited deficiency in enforcement, and it is the first thing an investigation asks to see.
The map,
complete
Every system that creates, receives, maintains or transmits PHI - the analytics tables, training sets, prompts and inference logs included, because they hold it too.
The BAA,
signed
A BAA with every party that touches PHI on your behalf, and one at every link below them. No compliant agreement means the sharing itself was not lawful.
The clock,
rehearsed
The path from discovery to notification, with the four-factor assessment written before you need it. Sixty days is not long once the first week goes on deciding.
Four cards, and the date on each one is part of the card.
Plain answers
What counts as PHI, which side of the line you are on, and where AI touches scope. Answered straight.
Request this reviewWhat counts as protected health information?
Individually identifiable health information held or transmitted by a covered entity or business associate, in any form - electronic, paper or spoken. It turns on eighteen identifiers, from names and dates to biometric identifiers, once they are linked to health information.
What is the difference between a covered entity and a business associate?
Covered entities are healthcare providers, health plans and clearinghouses that handle PHI directly. Business associates are third parties performing services involving PHI on their behalf - and since the Omnibus Rule of 2013 they carry direct HIPAA liability of their own.
What does the Security Rule risk analysis have to cover?
Where ePHI is created, received, maintained and transmitted; the threats to it; the measures currently in place; and the likelihood, impact and remediation priority of each risk. It is the single most commonly cited deficiency in enforcement - usually because it was done once and never revisited.
Where does AI touch HIPAA scope?
In three places, and they matter more here because the identifiers are so broad. PHI copied into a training set is maintained PHI. A prompt carrying patient detail is PHI in transmission, and the model vendor receiving it is a business associate. Inference logs kept for debugging are a copy of both.
What does an iDharma HIPAA review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the Security Rule risk analysis, the PHI inventory and flow map, the safeguards evidence pack, the breach runbook and drill, the business associate register and the policy template pack.
Request your HIPAA review
Tell us where PHI lives and we come back with a scoping call in one business day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your clinical and security teams, and we tell you which extracts we need before you commit.
- Which systems create, receive, maintain or transmit PHI
- Whether you are a covered entity, an associate, or both
- Your current risk analysis, if one exists
- The business associate list, with agreement status
- Whether PHI has reached analytics or model pipelines
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The HIPAA rules and HHS guidance
- The Office for Civil Rights, on enforcement
- Enacted
- 1996
- Omnibus Rule
- 2013
What it means
- General information about what the rules require — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- No penalty amount appears on this page. OCR adjusts the civil money penalty figures for inflation every year, and the current schedule is published by HHS — go there rather than to a page like this one for a number.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom