Back to Industries
Healthcare

HIPAA + SOC 2 + HITRUST readiness as one program. Real vCISO included. Priced for Series A.

For health-tech companies closing their first enterprise-hospital deal. Countersign the BAA on Wednesday, file the risk analysis on Friday, project HITRUST readiness from the same evidence pool, and hand your cyber-insurance carrier a FAIR-quantified renewal packet the next quarter. $299–$1,499/mo, where Vanta plus a partner consultancy runs $60–150K/yr.

BAA request on your desk right now? See the workflow →

  1. 2013HITECH Act takes effectrule / policy shiftExtends HIPAA to business associates directly; adds subprocessor BAA duty; four-tier penalty structure up to $1.5M per violation category per year.
  2. 2019Anthem Insurancesettlement / event$16M OCR settlement. 78.8M individuals exposed. Still the largest HIPAA settlement on record.
  3. 2023Banner Healthsettlement / event$1.25M OCR settlement for not having a Security Risk Analysis on file for the period under review.
  4. 2024Change Healthcare ransomwaresettlement / eventFeb 2024. One vendor outage disrupted claims processing for months. 80% of practices lost revenue; ~2/3 dipped into personal funds (AMA). Post-breach, health systems and PE sponsors now filter for "Change Healthcare-type" concentration risk.
  5. 2024FTC Health Breach Notification Rule (amended)rule / policy shiftExtends breach-notification duty to non-HIPAA health apps, wearables, and AI wellness tools. FTC's domain, parallel to OCR. Vendors touching health data outside HIPAA are now covered.
  6. 2025OCR Security Rule NPRMrule / policy shiftProposes removing the "addressable" designation from implementation specifications. Every technical safeguard becomes mandatory. Adds annual expert-certified written attestation of vendor safeguards. Cyber insurance carriers already asking for this.
  7. 2025Kaiser Permanente vendor AI requirementsrule / policy shiftSept 2025. Kaiser publishes formal AI Requirements for Vendors, Contractors and Suppliers. HTI-1 FAVES source attributes, CHAI model cards, closed-tenant inference now table-stakes for any AI vendor selling into Kaiser's ecosystem.
  8. 2026Joint Commission RUAIH launchesrule / policy shiftJune 2026. Responsible Use of AI in Healthcare certification opens. 5 areas: governance, data management, risk/bias, monitoring, transparency + training. Hospital procurement is reshaping around this now.
  9. 2026Your row is nextnextThe next hospital-customer procurement conversation on your desk will ask about at least three of these. What you attest to will be measured against them for the life of the retainer.

§ The three moments

Three clocks a health-tech company lives with. Same program covers all three.

The BAA request that lands on a Tuesday. The annual HIPAA risk analysis. The cyber-insurance renewal. Different moments, same evidence pool, one program to run them from.

T+00:00 · First BAA request
urgent

The enterprise customer's BAA lands.

The hospital-system procurement team wants the Business Associate Agreement countersigned in 48 hours, with your Security Rule attestation attached, subprocessors named, and evidence that your controls actually run. Miss the clock and the deal slips a quarter.

What ships
  • BAA as a first-class contract type in the platform: categorized, tracked, renewal-aware
  • HIPAA Business Associate Contracts policy template (rego-backed)
  • PHI as a first-class vendor risk dimension on every subprocessor row
T+Annual · Risk analysis cycle
routine

The HIPAA risk analysis is due.

HIPAA Security Rule §164.308(a)(1) requires a documented risk analysis at least once every 12 months. Banner Health's $1.25M settlement was for not having one on file. Yours needs to exist, be current, and be findable by an investigator on the day they ask. So does the readiness projection your hospital customer might ask for.

What ships
  • HIPAA framework assessment (eCFR-verbatim controls, OCR audit-protocol testing procedures)
  • HITRUST readiness projection: e1 / i1 / r2 tier scoring from existing evidence
  • SCF cross-map: same evidence pool answers HIPAA + SOC 2 + ISO 27001 + HITRUST readiness
T+Renewal · Cyber insurance
critical

Cyber insurance renewal is due. Carriers deny 41% first submission.

The carrier questionnaire is the second regulator. MFA on privileged access, EDR on workstations + servers, restore-tested backups, tabletop drill records, IR plan. Carriers named for healthcare: Coalition, At-Bay, Corvus, Chubb, Travelers, Beazley. Get the packet wrong and the premium doubles, or the policy denies.

What ships
  • FAIR-quantified renewal packet with Loss Exceedance Curve
  • Vendor incident register with HHI concentration math (Change Healthcare-type filter)
  • Board dashboard with FAIR risk analysis in dollars

§ Solutions

Four moments healthcare compliance actually breaks. Four fixes on your side.

Four moments every health-tech founder hits. At each, someone with the authority to break the deal (the hospital’s compliance officer, an OCR investigator, a cyber-insurance carrier) asks for a specific artifact you either have on the shelf or you don’t.

Without vCISO Lite
With vCISO Lite

The hospital-customer BAA lands. You have 48 hours.

First-enterprise-BAA · $0 deal risk vs. a full quarter's revenue

You've never signed a BAA. No template pack, no Security Rule attestation ready, no named subprocessor list. Ops director opens Google Docs.

01 BAA as a first-class contract type

Countersign package assembled from the platform's live state.

BAA categorized, tracked, renewal-aware in the vendor register. Security Rule attestation attached. Subprocessor list exported from the same register. Ready for hospital procurement in hours.

The annual HIPAA risk analysis is due.

§164.308(a)(1) · Banner Health settled $1.25M for not having one

Last risk analysis is a Word doc from 18 months ago. Half the safeguards named there don't reflect what your stack actually runs today.

02 Risk analysis auto-populates from live stack

eCFR-verbatim controls, OCR audit-protocol testing procedures.

52 shipped integrations (AWS · Okta · CrowdStrike · GitHub · Google Workspace + the rest) pull continuously. What the framework claims lives in your live stack, verified. Refreshed on every integration change.

Engineering adds a new subprocessor mid-quarter.

Missing-BAA OCR finding · #1 category of enforcement action

No one tells compliance. New vendor touches PHI. OCR investigator asks six months later. The BAA that should have existed never got signed.

03 Vendor register PHI-access-flagged

New subprocessor added → BAA capture kicks off automatically.

Every subprocessor is a governed row with PHI-access as a first-class risk dimension. When a new vendor lands, the register surfaces it and the BAA workflow starts. Subprocessor chain visible on one export when the hospital's DPO asks.

Cyber-insurance renewal survey lands.

41% denial rate on first submission · premium doubles or policy lapses

15-question carrier survey. Six blank fields the ops director can't answer without pulling MFA reports from Okta, encryption evidence from AWS, tabletop drill records from the shared drive.

04 FAIR-quantified renewal packet

Mapped to what Coalition / At-Bay / Corvus / Chubb actually ask.

Loss Exceedance Curve, control attestation, FAIR-quantified breach scenarios in dollars. Board dashboard shows the same numbers the underwriter sees. When it happens to a peer this month, the carrier renews yours.

§ The working state

When the hospital’s DPO asks for your subprocessor list. This is what they get.

Every third party with PHI access is a governed row in the register: category, BAA status tracked, breach-notification window on file, cross-border transfer mechanism named. The three red rows below are what a Tuesday-morning gap surfacing looks like, caught before the OCR investigator does.

Aurora Health Systems · subprocessor register
Illustrative composite · 10 subprocessors · auto-updated from vendor integrations
As of2026-08-23 · 09:14 PT
Subprocessor
Category
PHI
BAA status
Breach clock
Transfer mech
AWS RDS + S3
Cloud infra
PHI
SIGNED · 2026-01-14
24h
N/A · US
Redox
HL7/FHIR gateway
PHI
SIGNED · 2025-09-08
24h
N/A · US
Postmark
Transactional email
PHI
SIGNED · 2026-03-20
48h
DPF-covered
Vireo Bio (data aggregator)
PHI aggregator
PHI
SIGNED · 2026-05-15
48h
DPF-covered
Datadog
Observability
PHI
REDLINE V2 · 47d
72h *
DPF-covered
OpenAI API
AI inference
PHI
MISSING
—
none
Meridian Clinical (freelance)
Contract clinician
PHI
MISSING
—
none
BambooHR
HRIS
—
N/A · no PHI
—
N/A
GitHub
Source control
config
N/A · code only
—
N/A
Okta
Identity
—
N/A · identity only
—
N/A
BAA currentPending / expiringMissing on a PHI-accessing sub · the OCR-finding pattern
Illustrative composite · the live register auto-updates as your vendor list changes.

§ The rhythm

Fifteen hours a week, back on your calendar. That’s what shifts to the platform, and what stays with you.

Every hour the platform pulls evidence, drafts questionnaire responses, and keeps the vendor register current is an hour your ops director isn’t. Roughly fifteen a week, spent on your compliance program without adding to your headcount.

Platform hours

Integrations pull continuously: Okta, AWS, GitHub, CrowdStrike, Google Workspace, the rest. Vendor-incident detection scans eight sources every hour, auto-declaring matching incidents in the register. New subprocessors get flagged the day engineering adds them. Framework attestations re-project on evidence drift. The cyber-insurance renewal packet assembles the quarter before your renewal date. The HIPAA risk analysis fires on its §164.308(a)(1) twelve-month clock. The statute sets the calendar.

Your hours

Sign the customer BAA when it lands. Read and publish drafted policies before they go live. Vet the Evaluator-flagged questionnaire responses before they go to the hospital’s procurement team. Show up to the vCISO advisory call. The compliance moments that actually need your judgment, and only those.

On Enterprise

Want more of your hours to shift over? On Enterprise, Trustworthy Autonomy™ turns the queue into a scoped-authority agent. You pre-trust the low-risk categories, it acts inside those lines, and every action lands with its reasoning and a sealed record in your approval log. Human in the loop on everything consequential; scoped autonomy only where you opened the lane.

§ Intake

Check every one that applies. Any two = we should talk.

Health-tech founders and covered entities don’t three-way shop compliance vendors. Either you’re carrying enough enterprise-customer pressure that the program is straining what you can do manually, or you’re about to be.

If your hospital customer requires HITRUST i1 or r2 certification specifically and is unwilling to accept readiness plus SOC 2 in lieu, go direct to a HITRUST Assessor Organization. We ship readiness, not certification. If your primary buying criterion is AI-in-healthcare vendor governance (HTI-1 FAVES, CHAI model cards, HITRUST ai1/ai2), a CHAI-aligned tool is a better fit today. Otherwise this is us.

§ Contents of the chart

Eight weeks in: the artifacts that live in your compliance chart.

Every deliverable maps to a moment in the health-tech buying cycle. Each is exportable in the format the hospital procurement team asks for. Each is linked back to the feature that keeps it current after it ships.

HIPAA risk analysis
Framework assessment against eCFR-verbatim controls with OCR audit-protocol testing procedures. 12-month recurrence tracked. Populated from your live stack, not filled from a template.
Compliance
HIPAA policy set · 18 templates
Administrative, Physical, and Technical safeguard policies generated from your live stack, not template-filled. Includes a dedicated Business Associate Contracts template.
Policy management
HITRUST readiness report
e1 / i1 / r2 tier scoring projected from your HIPAA + SOC 2 + ISO 27001 evidence via the SCF cross-map. Bring the report to a HITRUST Assessor Organization to certify. We ship readiness, they issue the certification.
Business Associate Agreement · countersign package
BAA as a first-class contract type, categorized and renewal-aware. Security Rule attestation attached. Subprocessor list from the register. Ready for hospital procurement.
Security questionnaires
Subprocessor + vendor register
Every subprocessor with PHI-access flagged, BAA capture status, category, risk tier. When the hospital's DPO asks for the list, it's one export.
Vendor register
HIPAA + SOC 2 + ISO 27001 cross-mapped evidence pack
Same evidence pool exports as three attestations via the SCF corpus. When the hospital procurement team asks for both HIPAA and SOC 2, they come from one source of truth.
Framework coverage
Vendor incident register + FAIR scenarios
BREACH as first-class incident type. Dependency graph, HHI concentration math (the Change Healthcare filter), auto-declare, FAIR-quantified impact in dollars.
Vendor risk
Cyber-insurance renewal packet
FAIR-quantified breach scenarios with Loss Exceedance Curve, control attestation for the underwriter, mapped to what Coalition / At-Bay / Corvus / Chubb / Travelers actually ask.
Executive reporting
Board dashboard with FAIR risk analysis
Loss exceedance in dollars, portfolio benchmark against healthcare industry baselines, 15 report types available including AUDIT_PREP.
Executive intelligence
Auditor / brand-DPO client portal
Magic-link workspace with seven tabs (Overview, Controls & Evidence, Coverage, Q&A, Verifier, Packs, Evidence Graph). Same portal your SOC 2 auditor uses; extends to an OCR inquiry.
Client portal

Advisory hours · higher tiers

A real vCISO. Not “book time with our partner network.”

Hospital-system MSA cyber-addendum negotiation. HITRUST External Assessor Organization selection + pre-engagement scoping. OCR-inquiry response readiness with dated artifact chain. Right-of-access request escalation. Breach coordination inside the 60/60/72-day clocks. Ultra tier includes 4 hours/month of vCISO consulting; Fractional CISO SKU adds a dedicated 8-hour-per-week engagement. Real people, real hours, priced by engagement.

§ Common questions on HIPAA scope, HITRUST readiness, and AI

What health-tech founders and covered entities ask us

  • Do we need HITRUST if we have HIPAA?

    Depends on which hospital is asking. Some hospital systems (particularly large integrated delivery networks, academic medical centers, payers, and PBMs) require HITRUST i1 or r2 certification specifically as a purchasing condition. Others accept SOC 2 Type II + HIPAA attestation. Ask your customer which they'll accept before choosing a path. vCISO Lite ships HITRUST readiness: we project your existing HIPAA + SOC 2 + ISO 27001 evidence against the HITRUST control catalog and tell you where you stand across e1 / i1 / r2. When you're ready to certify, bring the readiness report to a HITRUST Assessor Organization. They issue the certification, not us. That's a deliberate boundary.

  • We use AWS / GCP / Azure. Do we need our own BAA with them?

    Yes. AWS, GCP, and Azure all sign BAAs, but the BAA is not on by default. It has to be requested and countersigned per your account. There's also a specific subset of each cloud's services that are BAA-eligible (AWS calls this the HIPAA Eligible Services List); running PHI on a non-eligible service is a violation even under a signed BAA. Our vendor register tracks BAA capture per subprocessor with PHI-access flagged so you can see the chain.

  • Our AI feature analyzes patient records. Different HIPAA rules?

    Same rules, higher scrutiny, and this is a boundary we're honest about. If PHI reaches the model as an input or as training data, the model provider is a subprocessor and needs a BAA. Under the FTC's amended 2024 Health Breach Notification Rule, AI wellness / AI health features outside HIPAA carry their own breach-notification duty parallel to OCR. Hospitals are actively reshaping AI vendor procurement. Kaiser Permanente published formal AI Requirements for Vendors in Sept 2025, and Joint Commission RUAIH certification launched June 2026. What vCISO Lite ships today: your AI subprocessors go in the vendor register with PHI-access flagged, and ISO 42001 controls are loaded in the SCF corpus. What we do NOT ship today: HTI-1 FAVES source-attribute tracking, CHAI model card generation, HITRUST ai1/ai2 workflow, FDA PCCP tracking. If your buyer is asking for those specifically, we can help you draft the procurement conversation but we're not the CHAI-aligned tool of record.

  • We're not a covered entity. Do we still need HIPAA?

    If you receive, create, maintain, or transmit PHI on behalf of a covered entity, you're a business associate and you inherit the HIPAA Security Rule directly. That includes many SaaS vendors serving healthcare, RCM providers, medical billing platforms, patient-communication tools, analytics vendors, and AI features running on patient data. The HITECH Act extended HIPAA to business associates directly in 2013; this is not a covered-entity-only regime.

  • What actually happens in an OCR investigation?

    OCR opens most investigations from three triggers: a self-reported breach (500+ affected individuals), a patient complaint (right-of-access is the fastest-growing category), or a random compliance review. The investigator requests: the risk analysis and the date it was last conducted, the workforce training log, the list of BAAs in place, encryption evidence for PHI at rest and in transit, the incident-response plan, and the sanction policy with any recent disciplinary actions. The investigator does not want a marketing deck; they want the artifacts, dated, findable.

  • We already use Vanta or Drata or Sprinto. Why not just add HIPAA there?

    You can. You're here because that's obviously not working. Generic compliance-automation platforms handle HIPAA as a checkbox with reasonable Security Rule mapping, good enough for many SMB scenarios. Where they run out of runway: when the hospital's procurement team asks for HITRUST readiness alongside HIPAA + SOC 2, when the subprocessor BAA chain needs to be a governed register (not a spreadsheet), or when the cyber-insurance renewal packet needs FAIR-quantified LEC. Our differentiator vs Vanta/Drata is (a) HITRUST readiness projection via SCF cross-map, (b) BAA + PHI as first-class data model, (c) real fractional CISO included at Ultra tier, not a partner-referral network.

Ready to safeguard PHI on a subscription that fits the stage?

Countersign the BAA on Wednesday. File the risk analysis on Friday. Show up quarterly with the readiness report already sent.