The rule

What does the HIPAA Security Rule ask of engineering?

The Security Rule (45 CFR 164.302 to 164.318) makes covered entities and business associates ensure the confidentiality, integrity and availability of ePHI with administrative, physical and technical safeguards, written policies and documentation kept for six years. Engineering carries most of the technical safeguards and part of the administrative ones. Which measures are enough is set by your risk analysis, not by this page.

Each standard has implementation specifications marked Required or Addressable. Addressable does not mean optional: §164.306(d)(3) requires you to assess whether the specification is reasonable and appropriate, then implement it, or document why not and implement an equivalent alternative if one is reasonable.

The rule leaves the method to you. §164.306(b) tells you to weigh your size and complexity, your technical infrastructure, the cost of the measures, and the probability and criticality of the risks to ePHI.

If your company is itself a covered entity, a health plan, a clearinghouse or a provider that transmits health information electronically, we are your business associate directly. If you are a vendor to one, we are your subcontractor.

The BAA

Do we sign a HIPAA business associate agreement?

Yes. Clouditive signs a HIPAA business associate agreement (BAA) when an engagement touches PHI. The Security Rule lets a covered entity, or a business associate, give ePHI to a business associate only after satisfactory assurances, documented in a written contract (§164.308(b)). That contract must make the business associate comply with the rule, bind its own subcontractors the same way, and report security incidents, including breaches of unsecured PHI (§164.314(a)).

Ask for the BAA on the first call, so that it is signed before an engineer has access to PHI. A business associate must notify the covered entity of a breach without unreasonable delay and in no case later than 60 calendar days after discovery (§164.410).

A BAA does not make a system compliant. The safeguards do that work, and your risk analysis decides which ones are enough.

What we do not claim

What do we not claim?

HIPAA has no certification, so we hold none, issue none and claim none. We are not an auditor, an assessor or a law firm, and we have no published healthcare case.

  • The Security Rule requires a periodic evaluation (§164.308(a)(8)), not a certificate. When HHS adopted the rule in 2003 it said it did not intend to create certification criteria (68 FR 8334, at 8352).
  • We have no published healthcare case. The cases linked below show the same controls in other sectors, and they are not proof of experience with a covered entity.
  • We do not perform or sign your risk analysis, write your policies, train your workforce or act as your security official. Those stay with your organization (§164.308(a)(1), (a)(2) and (a)(5)).
  • We guarantee no outcome of an audit, an investigation or a customer's security review, and we give no legal advice.
  • We claim no HITRUST certification and no partnership with any compliance-automation (GRC) platform.
  • HHS published a proposal to amend the Security Rule on 6 January 2025 (90 FR 898). We found no final rule in the Federal Register on 2026-10-09, so this page describes the rule in force.

The safeguards

Which safeguards does the engineering team build?

Six areas of the Security Rule land on engineering: access control and authentication, audit controls, integrity and transmission security, the contingency plan, the technical side of risk management, and the business associate chain. For each: what the rule asks, the engineering work, and where we have done it in a published case.

Access control and authentication

What it asks of engineeringDoes every person and program that reaches ePHI have its own identity, and can you cut access quickly?

§164.312(a) makes unique user identification and an emergency access procedure required, and automatic logoff and encryption addressable. §164.312(d) separately requires procedures to verify that a person or entity seeking access is the one claimed, and §164.308(a)(3) and (a)(4) add authorization, supervision and termination procedures. The engineering: identities on your SSO, MFA, least privilege, session timeouts, logged break-glass access, secrets in a managed store and workload identity for services.

Where we have done it

No fixed package covers access control on its own. We scope it in Discovery or with engineers by the hour.

Audit controls and activity review

What it asks of engineeringWhat do your systems record about who touched ePHI, and does anyone review it?

§164.312(b) requires mechanisms that record and examine activity in systems that contain or use ePHI. §164.308(a)(1)(ii)(D) requires procedures to regularly review audit logs, access reports and security incident tracking reports. The engineering: application and infrastructure logs designed so that ePHI does not land in log lines, alerts on the events your review defines, and a runbook. The review itself is your team's.

Where we have done it

Delivered by

Integrity and transmission security

What it asks of engineeringCan ePHI be altered without notice, and is it protected in transit?

§164.312(c) asks for protection from improper alteration or destruction, with a mechanism to authenticate ePHI as an addressable specification. §164.312(e) asks for technical measures against unauthorized access in transit, with integrity controls and encryption addressable. The engineering: TLS on every path, signed and digest-pinned release artifacts, so that what runs is what was tested, and a web application firewall at the edge.

Where we have done it

Delivered by

Contingency plan

What it asks of engineeringAre there retrievable exact copies of ePHI, and has anyone restored one?

§164.308(a)(7) requires a data backup plan, a disaster recovery plan and an emergency mode operation plan. Periodic testing and revision of the plan, and an analysis of which applications and data are critical, are addressable. The engineering: encrypted, scheduled backups, restore drills, and a rollback that is rehearsed rather than assumed.

Where we have done it

No fixed package covers backups and recovery on their own. We scope them in Discovery or with engineers by the hour.

Risk analysis, risk management and evaluation

What it asks of engineeringWhere is ePHI, what could go wrong with it, and what did you do about it?

§164.308(a)(1)(ii)(A) and (B) require an accurate and thorough risk analysis and security measures that reduce risk to a reasonable and appropriate level, and §164.308(a)(8) a periodic evaluation. Your organization performs and signs them. The engineering supplies the facts: an inventory of systems and data flows, scans on every change, tested alerts, and a backlog of fixes ranked by the risk you assessed.

Where we have done it

Delivered by

We do not perform or sign your risk analysis.

Business associates and incident reporting

What it asks of engineeringWhich vendors touch ePHI, is there a BAA with each, and who reports an incident to whom?

§164.308(b) and §164.314(a) require a written contract with every business associate and subcontractor that handles ePHI, and §164.308(a)(6) requires procedures to identify, respond to, mitigate and document security incidents. The engineering: a map of the services and vendors the data flows through, so that you know which BAAs you need, and the detection and runbook that let you learn of an incident as early as the system can show it.

No published case shows this row on its own. The audit controls row shows the detection work.

How we deliver

How do our packages and engineers deliver it?

Start with a fixed-price package, or hire engineers by the hour. The CI/CD & IaC package builds the pipeline and the infrastructure as code. SRE / Observability Foundations wires the monitoring. QA Automation Foundations puts tests in your CI. Discovery turns your risk analysis, or a covered entity's security questionnaire, into a roadmap with a backlog.

Pipeline and infrastructure as code

A 2-week build or re-architecture of your CI/CD pipelines and your infrastructure as code. The gates that go into the pipeline, such as a vulnerability scan, are agreed in the SOW.

Delivered by

Logging and monitoring

Metrics, logs and traces wired, 3 SLOs defined, alerts tested until they fire, and a runbook.

Delivered by

Tests on every change

A Playwright suite for your 5 critical flows, running in your CI, with accessibility checks.

Delivered by

From the requirement list to a backlog

Discovery understands your product and its configuration end to end and delivers a roadmap with a backlog, roles, critical changes and needs. Bring your risk analysis, a covered entity's security questionnaire or a gap list from your consultant, and we turn it into engineering work.

Delivered by

Engineers by the hour

For the work that continues after a package: Senior USD 45–⁠50 an hour, Lead or Architect USD 55–⁠60, with a 6-month minimum, billed per hour worked. You interview the engineer who will do the work.

Sources

Which texts did we read?

Primary texts, read on 2026-10-09.

  • 45 CFR Part 164, Subpart C (§§164.302 to 164.318), eCFR text in force on 2026-10-01.
  • 45 CFR 160.103, definition of business associate, and 45 CFR 164.410, notification by a business associate, same eCFR date.
  • Health Insurance Reform: Security Standards, 68 FR 8334 (20 February 2003), the final rule and its preamble.
  • HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, 90 FR 898 (6 January 2025), a proposed rule.

Frequently asked questions

Is Clouditive HIPAA certified?

No. The Security Rule creates no HIPAA certification: it requires a periodic evaluation (§164.308(a)(8)), and in 2003 HHS said it did not intend to create certification criteria. We claim no certification for Clouditive or for any client.

Do you sign a HIPAA business associate agreement?

Yes. Clouditive signs a HIPAA BAA when an engagement touches PHI. Ask for it on the first call, so that it is signed before an engineer has access to PHI.

Do you have healthcare clients?

We have no published healthcare case. The cases linked on this page show the same controls in fintech analytics, govtech, proptech, AI, gaming and transportation work.

Does addressable mean optional?

No. For an addressable specification, §164.306(d)(3) requires you to assess whether it is reasonable and appropriate, then implement it, or document why not and implement an equivalent alternative if one is reasonable.

Will our app be HIPAA compliant after you build it?

We build the technical safeguards and leave evidence a reviewer can read. Compliance also covers your risk analysis, policies, training, vendors and operations, so no outside vendor can promise it, and we guarantee no outcome of an audit or an investigation.

Has the Security Rule changed?

HHS published a proposal to amend it on 6 January 2025 (90 FR 898). On 2026-10-09 we found no final rule in the Federal Register, so this page describes the rule in force.

What do you need from us to start?

A BAA if PHI is in scope, access through your own accounts, and your risk analysis or a covered entity's questionnaire if you have one. Discovery covers the rest.

How does this relate to SOC 2 and the other frameworks?

The engineering overlaps a lot: gated releases, access you can prove, tested alerts and drilled recovery serve several frameworks at once. The compliance engineering page shows which clause of each framework asks for which control.

How do your engineers get access to our systems?

Through your own accounts and identities, with your SSO, your MFA and least-privilege access, revoked when the engagement ends. Every engineer passes a background check before assignment.

Who does the work?

Mat Caniglia leads every project end to end, and the engineers are in LATAM and share your working day. We present candidates within 1 week, and you interview the engineer who will do the work.

Tell us your case.

We reply to every request within 1 business day. We sign an NDA before the call if you ask.