Administrative safeguards
The mandated risk analysis and risk management process, assigned security responsibility, workforce training and access management, contingency planning and periodic evaluation.
Governance, Risk & Compliance
HIPAA does not require you to be American. An Indian IT firm, BPO or health-tech vendor that creates, receives, maintains or transmits ePHI on behalf of a US covered entity is a Business Associate under the law — and that status attaches to what you do, not to whether anyone remembered to send you a contract.
If you process, host, transcribe, code, support or build against US patient data — medical billing, claims processing, EHR support, telehealth infrastructure, health-app backends — you are almost certainly a Business Associate rather than a bystander. Your US client, the covered entity, is legally required to have a signed Business Associate Agreement in place before sharing ePHI with you. If they have not asked for one, that is a problem for both of you, and the Office for Civil Rights has repeatedly held Business Associates directly liable rather than treating the covered entity as the only responsible party.
There is no HIPAA certification. HHS and OCR do not certify, accredit or approve organisations, and no third party can issue a certificate that carries statutory weight. Firms selling "HIPAA certified" status in India are selling a training completion record or a self-assessment with a logo on it. What is real is a documented risk analysis, implemented safeguards and a defensible compliance posture — which is what an OCR investigation or a covered entity’s vendor audit actually examines.
One item is worth watching rather than acting on as settled law: a Notice of Proposed Rulemaking published in the Federal Register in January 2025 proposes significant Security Rule changes, including mandatory encryption and multi-factor authentication and the removal of the "addressable" distinction. As of August 2026 that remains proposed rather than final. We flag it because the direction of travel is a sensible target regardless of the final compliance date — not because it binds you today.
Coverage
The Security Rule is where most technical work lands, but the Privacy Rule and Breach Notification Rule both apply to Business Associates directly, not only through contract.
The mandated risk analysis and risk management process, assigned security responsibility, workforce training and access management, contingency planning and periodic evaluation.
Facility access controls, workstation use and security, and device and media controls including disposal and re-use. Applies to cloud-first teams too — a home-working laptop with ePHI on it is in scope.
Access control and unique user identification, audit controls, integrity controls, authentication and transmission security. This is where testing evidence replaces assertion.
A signed, current BAA with every covered entity you serve, and downstream BAAs with your own subcontractors who touch ePHI. Reviewed for the clauses OCR actually enforces on.
Discovery, assessment against the four-factor risk analysis, and notification to the covered entity without unreasonable delay and per the terms of your BAA.
Permitted uses and disclosures, the minimum necessary standard, and the restrictions your BAA imposes on what you may do with ePHI.
Approach
Status determination comes first, because the obligations follow from it and because a surprising number of Indian vendors have never had it established in writing.
A written assessment of whether, where and how your systems touch ePHI on behalf of a covered entity — and whether any of your subcontractors do too.
Current state against the Privacy, Security and Breach Notification Rules, prioritised by real exposure rather than by rule order.
The mandated risk analysis, done properly and specific to your environment. This is the single most cited failure in OCR enforcement, and templates do not survive scrutiny.
Your existing agreements and your subcontractor agreements, checked for the clauses that matter and the ones that are quietly missing.
Access control hardening, encryption and audit-logging review, and penetration testing of every system in the ePHI path.
Breach process rehearsed, training delivered, and continuous monitoring so posture does not decay between client audits.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Where your systems sit in the ePHI path, and what that makes you under the law — the document your covered entity will ask for.
The mandated analysis, environment-specific and defensible, with risk management decisions recorded and owned.
Gaps in your existing agreements and your subcontractor agreements, with the specific clauses that need to change.
Administrative, physical and technical safeguards with owners and dates, prioritised by exposure.
The four-factor assessment, notification path to the covered entity and BAA-specific timelines, rehearsed rather than filed.
Penetration test and access-control findings mapped to Security Rule technical safeguards, so the controls are demonstrated rather than described.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
If you create, receive, maintain or transmit ePHI on behalf of a US covered entity, you are functioning as a Business Associate regardless of where you are located. HIPAA reaches you through the covered-entity relationship and through your Business Associate Agreement, and OCR has held Business Associates directly liable. Geography changes the practicalities of enforcement, not the obligations.
No. HHS and the Office for Civil Rights do not certify, accredit or endorse organisations, products or training under HIPAA, and no third party can issue a certificate with statutory standing. Anything sold as HIPAA certification is a training record or a self-assessment. What holds up is a documented risk analysis, implemented safeguards and evidence they operate — which is what we build.
That is a compliance gap on both sides, and it is more common than it should be. A covered entity is required to have a signed BAA in place before disclosing ePHI to you. We identify where ePHI is already flowing without an agreement behind it, and help you raise it with the client — which is a considerably better conversation to have proactively than after an incident.
No. As of August 2026 the Notice of Proposed Rulemaking published in January 2025 remains proposed rather than final. We flag its direction — mandatory encryption, multi-factor authentication and removal of the "addressable" distinction — because those are reasonable targets to build toward now, and because organisations that adopt them early will not face a compressed remediation window if and when a final rule lands. We do not present it as a current obligation.
OCR applies civil monetary penalties across four culpability tiers, from genuine lack of knowledge through to uncorrected wilful neglect, with per-violation amounts and annual caps that are adjusted for inflation each year (as of August 2026). Rather than quote figures that move annually, the practical point is this: for an Indian Business Associate, the commercial consequence usually arrives first. A breach traced to your systems ends the covered-entity relationship, and the references that came with it, well before a regulator does anything.
Yes. The Security Rule requires technical safeguards — access control, audit controls, integrity, authentication and transmission security — and a periodic evaluation of whether they meet the rule’s requirements. Documentation alone does not demonstrate that. Our engagements test every system in the ePHI path and map the findings to the specific safeguard they evidence.
HIPAA is a legal obligation that attaches because you handle ePHI. SOC 2 is a voluntary attestation many US buyers request alongside it as evidence of general security control. They overlap in substance — access control, logging, incident response — but not in status: you cannot satisfy HIPAA by holding a SOC 2 report, and a SOC 2 report is not evidence of HIPAA compliance unless it was scoped to say so.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.