HIPAA Compliance Services for Covered Entities and Business Associates
Security Brigade combines deep technical security testing with HIPAA control mapping to help hospitals, payers, and India-based Business Associates achieve and maintain compliance across the Privacy Rule, Security Rule, and Breach Notification Rule.
Trusted by India's leading enterprises
Which one are you
Almost every Indian organisation on this page is a business associate
HIPAA distinguishes covered entities (health plans, healthcare clearinghouses and most healthcare providers) from business associates, meaning anyone who creates, receives, maintains or transmits protected health information on a covered entity’s behalf. An Indian software company building a telehealth platform, a BPO handling claims, a analytics firm working on clinical data, a hosting provider holding a US hospital’s records: all business associates, and that is the position this page is written for. It matters because the obligation arrives differently. A covered entity is bound directly by the rules; a business associate is bound by a business associate agreement and, since the HITECH Act, directly liable for the Security Rule and for parts of the Privacy Rule as well. The agreement is therefore not a procurement formality to be signed and filed. It is the instrument that defines what you may do with the data, what you must do to protect it, what happens when something goes wrong, and what your client is entitled to verify. And the chain continues: where you engage a sub-contractor who will touch the same data, you need an agreement with them carrying equivalent obligations. The commonest structural failure we find is a business associate agreement signed at the top of the chain and nothing equivalent underneath it, which leaves the signatory carrying an obligation its own suppliers have never been told about.
The Security Rule
Three categories of safeguard, and one word that is widely misread
Administrative safeguards
Risk analysis and risk management, workforce security and clearance, information access management, security awareness training, incident procedures, contingency planning and periodic evaluation. The risk analysis is the keystone: several other requirements are expressed relative to it.
Physical safeguards
Facility access controls, workstation use and security, and device and media controls including disposal and re-use. Frequently the thinnest area in an assessment of a cloud-hosted service, and frequently the one where the answer is a provider attestation, not your own control.
Technical safeguards
Access control including unique user identification, audit controls, integrity controls, person or entity authentication, and transmission security. This is the group our technical assessment evidences directly.
"Addressable" does not mean optional
An addressable implementation specification must be assessed. If it is reasonable and appropriate you implement it; if it is not, you document why and implement an equivalent alternative where one is reasonable. Skipping it silently is the failure mode, and the documentation is what an auditor asks for first.
What an assessment covers
Rule by rule, and what evidences each one
| Rule | What it governs | What evidences it |
|---|---|---|
| Security Rule | Administrative, physical and technical safeguards for electronic protected health information, anchored on a documented risk analysis and the risk management that follows from it. | Risk analysis, technical testing of the safeguards, and the addressable-specification decisions in writing |
| Privacy Rule | Permitted uses and disclosures of protected health information, the minimum necessary standard, and individual rights including access to records. | Policies, access controls that enforce minimum necessary, and a working individual-access path |
| Breach Notification Rule | What counts as a breach, the risk assessment that decides it, and notification to the covered entity, to individuals and where thresholds are met to the regulator and the media. | A rehearsed path with named owners, and the risk-assessment method written down before it is needed |
| Business associate agreements | The contractual chain: your agreement with the covered entity, and equivalent agreements with every sub-contractor that touches the same data. | The agreements themselves, and a vendor inventory that matches them |
Security Rule
- What it governs
- Administrative, physical and technical safeguards for electronic protected health information, anchored on a documented risk analysis and the risk management that follows from it.
- What evidences it
- Risk analysis, technical testing of the safeguards, and the addressable-specification decisions in writing
Privacy Rule
- What it governs
- Permitted uses and disclosures of protected health information, the minimum necessary standard, and individual rights including access to records.
- What evidences it
- Policies, access controls that enforce minimum necessary, and a working individual-access path
Breach Notification Rule
- What it governs
- What counts as a breach, the risk assessment that decides it, and notification to the covered entity, to individuals and where thresholds are met to the regulator and the media.
- What evidences it
- A rehearsed path with named owners, and the risk-assessment method written down before it is needed
Business associate agreements
- What it governs
- The contractual chain: your agreement with the covered entity, and equivalent agreements with every sub-contractor that touches the same data.
- What evidences it
- The agreements themselves, and a vendor inventory that matches them
Where engagements find problems
Four states, in the order we usually meet them
| State | What it means | What follows |
|---|---|---|
| Risk analysis current and acted on | A documented risk analysis covering every system that touches protected health information, with the risk management decisions traceable to it. | The position everything else is measured against. Where it exists, an assessment becomes a verification exercise. |
| Risk analysis done once | An analysis performed for an onboarding or an audit and not revisited as the platform, the vendors and the data footprint changed. | The single most common finding. Because so much of the Security Rule is expressed relative to the risk analysis, a stale one weakens every requirement that refers to it. |
| Addressable specifications skipped | Encryption at rest, automatic logoff or integrity controls treated as optional because the word addressable was read as discretionary. | Expensive, and easy for an auditor to find, because what is missing is not the control but the written reasoning that would have justified its absence. |
| The chain stops at the top | A business associate agreement with the covered entity, and no equivalent agreement with the sub-contractors handling the same data. | You carry an obligation your own suppliers have never been told about, and discover it during your client’s vendor review, not your own. |
- Assessment becomes verification
- Weakens everything built on it
- Found by your client, not by you
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade's HIPAA compliance methodology is designed to be thorough, practical, and evidence-driven. Each phase builds on the previous one, and Lemon manages the entire workflow from initial scoping through final closure validation. The engagement typically spans 6 to 12 weeks depending on organisation size and complexity, with the option for ongoing managed compliance support.
Scoping and Applicability Assessment
Determine entity type (Covered Entity or Business Associate), identify all systems and processes that create, receive, maintain, or transmit PHI, and define the compliance assessment boundary. Duration: 1 to 2 weeks.
PHI Data Flow Mapping
Document all PHI flows across applications, APIs, databases, cloud infrastructure, third-party processors, backups, logs, and communication channels. Identify where PHI is stored, processed, and transmitted.
HIPAA Risk Assessment
Conduct the risk assessment required under 164.308(a)(1). Identify threats and vulnerabilities to ePHI, assess likelihood and impact, and document risk levels for every identified gap. This becomes the foundation of your compliance programme.
Technical Security Validation
Security Brigade performs VAPT, network security audit, application security testing, and code review against systems handling PHI. Findings are mapped directly to Security Rule technical safeguard requirements. This is where SB differs from policy-only consultants.
Gap Analysis and Remediation Roadmap
Comprehensive gap analysis across Privacy Rule, Security Rule, and Breach Notification Rule. Each gap is risk-rated with specific remediation guidance, assigned owners, and target closure dates tracked in Lemon.
Remediation Support
Security Brigade provides hands-on support for policy development, technical control implementation, vendor management frameworks, BAA review, incident response planning, and workforce training programme design.
Closure Validation and Reporting
After remediation, Security Brigade validates that all gaps are addressed through evidence review and retesting. The final HIPAA compliance assessment report and evidence pack are delivered for customer due diligence, BAA obligations, or OCR audit readiness.
"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
CART · Continuous Automated Red-Teaming
Automated vulnerability detection and validation on your live attack surface — exploit context delivered, not just scanner noise.
Annual audits prove a moment. CART proves resilience continuously.
Explore on ShadowMapThreat Intelligence
1,000+ threat actor profiles, CVE tracking against your stack, IOC monitoring, and geographic threat analysis.
Know which threats are coming for you specifically.
Explore on ShadowMapFAQ
HIPAA for Indian service providers, answered
Scope, safeguards and the contractual chain. Talk to our team about your data flows.
Contact usWe are an Indian company. Can HIPAA apply to us?
What does "addressable" mean in the Security Rule?
Do we need business associate agreements with our own vendors?
Where does the risk analysis fit?
Does penetration testing form part of HIPAA compliance?
Ready to Achieve HIPAA Compliance?
Whether you are a US Covered Entity or an India-based Business Associate handling PHI, Security Brigade combines technical security validation with HIPAA control mapping to get you compliant faster.
Typically responds within 1 business day · No commitment required