⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · US healthcare privacy & security

HIPAA compliance, safeguards you can prove.

HIPAA governs how covered entities and business associates in the US protect protected health information (PHI) — the Privacy Rule, Security Rule (administrative, physical, and technical safeguards), and Breach Notification Rule. grComply seeds the real Rule structure, ties technical safeguards to actual scan and log evidence, closes workforce-training requirements with the training module, and offers hybrid or private on-prem deployment for organisations that can't put PHI in shared cloud infrastructure.

5 Rule areas — Privacy, Administrative, Physical, Technical safeguards, and Breach Notification.
Back to all frameworks WhatsApp us
5Rule areas
USJurisdiction
PHIScope
StructuralSeed depth

What is HIPAA? HIPAA (the Health Insurance Portability and Accountability Act) is US federal law governing how covered entities — healthcare providers, health plans, and their business associates — protect protected health information (PHI), enforced through the Privacy Rule, Security Rule, and Breach Notification Rule administered by HHS's Office for Civil Rights.

Why it's different

How grComply benefits your HIPAA programme

Privacy, Security, and Breach Notification Rules in one tree

PRIV/ADMIN/PHYS/TECH/BREACH domains seeded with real Rule structure, not a generic healthcare checklist.

Risk analysis is a live register, not a PDF

HIPAA's required risk analysis documentation is the same configurable risk register used platform-wide, not a static annual report.

Technical safeguards map to real scan and log evidence

Audit controls and access control tie to SIEM log samples and IAM exports already modelled elsewhere in the platform.

Workforce training closes with the training module

HIPAA's workforce security and training requirement becomes a compliance-mapped course with a real completion record.

Breach notification procedure sits with incident evidence

The risk assessment and notification procedure share the same structured evidence model as any other incident-response control.

Deployment flexibility for PHI residency

Hybrid or private on-prem keeps ePHI inside a covered entity's own infrastructure when cloud isn't an option.

Structure

Five Rule areas, seeded with real HIPAA structure

Privacy Rule, the three Security Rule safeguard categories, and Breach Notification — seeded as HIPAA itself is structured, not flattened into one generic list.

Privacy Rule

Notice of privacy practices, minimum-necessary uses and disclosures, and individual rights — access, amendment, and accounting of disclosures.

Security Rule — Administrative safeguards

Security management process, assigned security responsibility, workforce security and training (closed by the training module), information access management, security incident procedures, and contingency planning.

Security Rule — Physical safeguards

Facility access controls and workstation/device controls — the physical boundary around systems holding ePHI.

Security Rule — Technical safeguards

Access control (including unique user identification and emergency access), audit controls, integrity, and transmission security.

Breach Notification Rule

Breach risk assessment and notification — sharing the same structured incident-evidence model as other frameworks' breach requirements.

Evidence, mapped

Evidence grComply already models for HIPAA

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
PRIV-1 — Notice of privacy practicesPolicy documentNotice of Privacy Practices
ADMIN-1 — Risk analysisRisk register exportRisk analysis documentation
ADMIN-6 — Contingency planProcedure documentContingency / disaster recovery plan
TECH-2 — Audit controlsSIEM log sampleePHI access audit log sample
BREACH-1 — NotificationProcedure documentBreach notification procedure and sample workflow

Why this matters: HIPAA's Security Rule was written to be scalable and technology-neutral — grComply's framework-agnostic control model is a natural fit, since a covered entity's actual technical safeguards (IAM, logging, encryption) are evidenced with the same real system data used for ISO 27001 or SOC 2, not a healthcare-specific parallel process.

Product screens

HIPAA, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to HIPAA.

FAQ

HIPAA in grComply

What is HIPAA?

HIPAA is US federal law protecting patient health information, enforced through the Privacy Rule (use and disclosure of PHI), the Security Rule (administrative, physical, and technical safeguards), and the Breach Notification Rule.

Who needs to comply with HIPAA?

Covered entities — healthcare providers, health plans, and healthcare clearinghouses — and their business associates who create, receive, maintain, or transmit PHI on a covered entity's behalf.

Does grComply support the full HIPAA Rule structure?

Yes — Privacy Rule, all three Security Rule safeguard categories (Administrative, Physical, Technical), and the Breach Notification Rule are seeded with real control names as a structural library.

How does the required risk analysis work in grComply?

HIPAA's mandatory risk analysis documentation (ADMIN-1) uses the same configurable risk register the rest of the platform runs — asset, threat, vulnerability, likelihood, impact, and treatment plan — not a separate annual report.

Can workforce training evidence come from the training module?

Yes — a course mapped to ADMIN-3 (workforce security and training) produces a completion record that satisfies this Administrative safeguard directly.

Can HIPAA run on-premise for PHI residency requirements?

Yes — grComply's hybrid or private on-prem deployment options keep ePHI inside a covered entity's own infrastructure, for organisations that can't or won't put PHI in shared cloud infrastructure.

Does HIPAA evidence cross-map to other frameworks?

Where controls are genuinely equivalent, yes — a technical safeguard like TECH-2 audit controls can credit an equivalent ISO 27001 A.8.15 logging control or SOC 2 CC7.1 monitoring criterion.

How does breach notification evidence work?

BREACH-1's risk assessment and notification procedure use the same structured incident-evidence model as breach-notification controls in DORA or ISO 27018, not a HIPAA-only parallel process. See the full catalog on the Compliance Frameworks page.

See HIPAA mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about HIPAA

Tell us where your HIPAA programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring HIPAA into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us