Skip to main content
CERT-In Empanelled — Empanelled by CERT-In since 2008, and listed in its public register

HIPAA Compliance Services for Covered Entities and Business Associates

Security Brigade combines deep technical security testing with HIPAA control mapping to help hospitals, payers, and India-based Business Associates achieve and maintain compliance across the Privacy Rule, Security Rule, and Breach Notification Rule.

Privacy + Security
Rule Coverage
65+
Healthcare Clients
PHI
Protected Data Focus
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Which one are you

Almost every Indian organisation on this page is a business associate

HIPAA distinguishes covered entities (health plans, healthcare clearinghouses and most healthcare providers) from business associates, meaning anyone who creates, receives, maintains or transmits protected health information on a covered entity’s behalf. An Indian software company building a telehealth platform, a BPO handling claims, a analytics firm working on clinical data, a hosting provider holding a US hospital’s records: all business associates, and that is the position this page is written for. It matters because the obligation arrives differently. A covered entity is bound directly by the rules; a business associate is bound by a business associate agreement and, since the HITECH Act, directly liable for the Security Rule and for parts of the Privacy Rule as well. The agreement is therefore not a procurement formality to be signed and filed. It is the instrument that defines what you may do with the data, what you must do to protect it, what happens when something goes wrong, and what your client is entitled to verify. And the chain continues: where you engage a sub-contractor who will touch the same data, you need an agreement with them carrying equivalent obligations. The commonest structural failure we find is a business associate agreement signed at the top of the chain and nothing equivalent underneath it, which leaves the signatory carrying an obligation its own suppliers have never been told about.

The Security Rule

Three categories of safeguard, and one word that is widely misread

The largest group

Administrative safeguards

Risk analysis and risk management, workforce security and clearance, information access management, security awareness training, incident procedures, contingency planning and periodic evaluation. The risk analysis is the keystone: several other requirements are expressed relative to it.

Facilities and devices

Physical safeguards

Facility access controls, workstation use and security, and device and media controls including disposal and re-use. Frequently the thinnest area in an assessment of a cloud-hosted service, and frequently the one where the answer is a provider attestation, not your own control.

Where testing lands

Technical safeguards

Access control including unique user identification, audit controls, integrity controls, person or entity authentication, and transmission security. This is the group our technical assessment evidences directly.

The misreading

"Addressable" does not mean optional

An addressable implementation specification must be assessed. If it is reasonable and appropriate you implement it; if it is not, you document why and implement an equivalent alternative where one is reasonable. Skipping it silently is the failure mode, and the documentation is what an auditor asks for first.

What an assessment covers

Rule by rule, and what evidences each one

RuleWhat it governsWhat evidences it
Security Rule Administrative, physical and technical safeguards for electronic protected health information, anchored on a documented risk analysis and the risk management that follows from it. Risk analysis, technical testing of the safeguards, and the addressable-specification decisions in writing
Privacy Rule Permitted uses and disclosures of protected health information, the minimum necessary standard, and individual rights including access to records. Policies, access controls that enforce minimum necessary, and a working individual-access path
Breach Notification Rule What counts as a breach, the risk assessment that decides it, and notification to the covered entity, to individuals and where thresholds are met to the regulator and the media. A rehearsed path with named owners, and the risk-assessment method written down before it is needed
Business associate agreements The contractual chain: your agreement with the covered entity, and equivalent agreements with every sub-contractor that touches the same data. The agreements themselves, and a vendor inventory that matches them

Security Rule

What it governs
Administrative, physical and technical safeguards for electronic protected health information, anchored on a documented risk analysis and the risk management that follows from it.
What evidences it
Risk analysis, technical testing of the safeguards, and the addressable-specification decisions in writing

Privacy Rule

What it governs
Permitted uses and disclosures of protected health information, the minimum necessary standard, and individual rights including access to records.
What evidences it
Policies, access controls that enforce minimum necessary, and a working individual-access path

Breach Notification Rule

What it governs
What counts as a breach, the risk assessment that decides it, and notification to the covered entity, to individuals and where thresholds are met to the regulator and the media.
What evidences it
A rehearsed path with named owners, and the risk-assessment method written down before it is needed

Business associate agreements

What it governs
The contractual chain: your agreement with the covered entity, and equivalent agreements with every sub-contractor that touches the same data.

Where engagements find problems

Four states, in the order we usually meet them

Four states, in the order we usually meet them
StateWhat it meansWhat follows
Risk analysis current and acted on A documented risk analysis covering every system that touches protected health information, with the risk management decisions traceable to it. The position everything else is measured against. Where it exists, an assessment becomes a verification exercise.
Risk analysis done once An analysis performed for an onboarding or an audit and not revisited as the platform, the vendors and the data footprint changed. The single most common finding. Because so much of the Security Rule is expressed relative to the risk analysis, a stale one weakens every requirement that refers to it.
Addressable specifications skipped Encryption at rest, automatic logoff or integrity controls treated as optional because the word addressable was read as discretionary. Expensive, and easy for an auditor to find, because what is missing is not the control but the written reasoning that would have justified its absence.
The chain stops at the top A business associate agreement with the covered entity, and no equivalent agreement with the sub-contractors handling the same data. You carry an obligation your own suppliers have never been told about, and discover it during your client’s vendor review, not your own.
Key
  • Assessment becomes verification
  • Weakens everything built on it
  • Found by your client, not by you

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade's HIPAA compliance methodology is designed to be thorough, practical, and evidence-driven. Each phase builds on the previous one, and Lemon manages the entire workflow from initial scoping through final closure validation. The engagement typically spans 6 to 12 weeks depending on organisation size and complexity, with the option for ongoing managed compliance support.

Discovery
01

Scoping and Applicability Assessment

Determine entity type (Covered Entity or Business Associate), identify all systems and processes that create, receive, maintain, or transmit PHI, and define the compliance assessment boundary. Duration: 1 to 2 weeks.

02

PHI Data Flow Mapping

Document all PHI flows across applications, APIs, databases, cloud infrastructure, third-party processors, backups, logs, and communication channels. Identify where PHI is stored, processed, and transmitted.

03

HIPAA Risk Assessment

Conduct the risk assessment required under 164.308(a)(1). Identify threats and vulnerabilities to ePHI, assess likelihood and impact, and document risk levels for every identified gap. This becomes the foundation of your compliance programme.

Testing
04

Technical Security Validation

Security Brigade performs VAPT, network security audit, application security testing, and code review against systems handling PHI. Findings are mapped directly to Security Rule technical safeguard requirements. This is where SB differs from policy-only consultants.

05

Gap Analysis and Remediation Roadmap

Comprehensive gap analysis across Privacy Rule, Security Rule, and Breach Notification Rule. Each gap is risk-rated with specific remediation guidance, assigned owners, and target closure dates tracked in Lemon.

Delivery
06

Remediation Support

Security Brigade provides hands-on support for policy development, technical control implementation, vendor management frameworks, BAA review, incident response planning, and workforce training programme design.

07

Closure Validation and Reporting

After remediation, Security Brigade validates that all gaps are addressed through evidence review and retesting. The final HIPAA compliance assessment report and evidence pack are delivered for customer due diligence, BAA obligations, or OCR audit readiness.

"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Head of Platform Engineering, Fintech Unicorn
Head of Platform Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

HIPAA for Indian service providers, answered

Scope, safeguards and the contractual chain. Talk to our team about your data flows.

Contact us
We are an Indian company. Can HIPAA apply to us?+
Yes, through the contract. If you create, receive, maintain or transmit protected health information on behalf of a covered entity, you are a business associate, and the obligation reaches you through the business associate agreement and — since the HITECH Act — directly for the Security Rule and parts of the Privacy Rule. Location is not the test; the relationship to the data is.
What does "addressable" mean in the Security Rule?+
That the specification must be assessed, not that it may be ignored. Where implementing it is reasonable and appropriate for your environment, you implement it. Where it is not, you document that assessment and implement an equivalent alternative measure if one is reasonable and appropriate. What an auditor looks for is the written reasoning, which is precisely what is missing when the word has been read as optional.
Do we need business associate agreements with our own vendors?+
Where a sub-contractor creates, receives, maintains or transmits the same protected health information, yes: the chain carries downstream and the agreements need to impose equivalent obligations. The failure we find most often is an agreement signed with the covered entity and nothing underneath it, which leaves you accountable for suppliers who were never told what they are handling.
Where does the risk analysis fit?+
At the centre. It is an administrative safeguard in its own right, and several other Security Rule requirements are expressed relative to it, so a stale risk analysis quietly weakens everything that refers back to it. It should cover every system that touches protected health information, including backups, logs, analytics and third-party services, and be revisited when the estate changes, not annually by habit.
Does penetration testing form part of HIPAA compliance?+
The technical safeguards (access control, audit controls, integrity, authentication and transmission security) are what testing evidences directly, and the Security Rule also calls for periodic technical and non-technical evaluation of your environment. In practice covered entities increasingly require testing evidence from their business associates as a condition of the relationship, so it is as often a commercial requirement as a regulatory one.

Ready to Achieve HIPAA Compliance?

Whether you are a US Covered Entity or an India-based Business Associate handling PHI, Security Brigade combines technical security validation with HIPAA control mapping to get you compliant faster.

Typically responds within 1 business day · No commitment required

Request a Scoping Call