Healthcare Cybersecurity: HIPAA, SOC 2 & NIST CSF Compliance Guide for SMBs
Five overlapping frameworks apply to healthcare SMBs and SaaS vendors that handle protected health information: the HIPAA Security Rule (45 CFR §164.308–§164.312), HIPAA Privacy Rule (45 CFR §164.500–§164.534), the HITECH Act breach-notification regime (45 CFR §164.404), state medical-privacy statutes (CA CMIA, TX HB300, IL PIPA, NY SHIELD-adjacent covered-entity duties), and — for healthcare SaaS vendors selling into hospital systems or enterprise payers — SOC 2 Trust Services Criteria (CC6/CC7) wrapped around a NIST CSF 2.0 GOVERN+PROTECT operating program. Patient records sell for 10–40x the value of credit card data on the dark web, making clinics, dental practices, specialty providers, behavioral-health practices, and digital-health SaaS companies prime ransomware targets. Healthcare SMBs face the highest breach costs of any sector while operating under HIPAA's administrative, physical, and technical safeguards with limited IT budgets. This guide covers which regulations apply to your organization, what controls BAA-covered vendors and covered entities must implement, and how to close the gaps before OCR, state attorneys general, or attackers surface them.
Build your healthcare evidence packet
Use this compact, printable worksheet to organize the evidence a healthcare compliance review may request.
Open the printable evidence worksheetEvidence categories
- Policies
- Technical safeguards
- Access reviews
- Audit records
Healthcare evidence-readiness checklist
Use these five checkpoints to organize the policies, controls, response plans, risk work, and dated evidence a healthcare compliance review may sample.
0 of 15 items checked. Readiness: Not started
Access controls
Related resources
Incident response
Related resources
Risk assessments
Related resources
Audit evidence
Related resources
Top Cyber Risks for Healthcare Businesses
Regulations and Frameworks for Healthcare Organizations
Several overlapping frameworks may apply to your healthcare organization depending on contract role, data handled, customer requirements, and jurisdiction. Not all apply to every organization — use this guide to identify which are relevant to you.
HIPAA Security Rule (45 CFR §164.308–§164.312)
Applies to: All covered entities (healthcare providers, health plans, healthcare clearinghouses) and their Business Associates — clinics, dental practices, specialty providers, billing companies, EHR/PM SaaS vendors, and any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
- Annual HIPAA risk analysis under §164.308(a)(1)(ii)(A) — the most-cited OCR enforcement gap; not a point-in-time checklist
- BAAs with every Business Associate that touches PHI (§164.308(b)(1)) — including cloud hosting, transcription, AI summarization, and analytics vendors
- Workforce security training and sanctions policy (§164.308(a)(3) and §164.530(b)) — annual training plus documented sanctions for violations
- Audit controls (§164.312(b)) and encryption of PHI at rest and in transit (§164.312(a)(2)(iv) and §164.312(e)(2)(ii)) — both are addressable specifications but OCR treats absence as a deficiency
- Access control with unique user IDs, emergency-access procedures, and automatic logoff (§164.312(a)(1)–(a)(2)(iii)) — break-glass procedures must be logged and reviewed
- 60-day individual breach notification to affected individuals and 60-day media notice for breaches affecting 500+ residents of a state or jurisdiction (§164.404)
- 72-hour breach notification to HHS Secretary for breaches affecting 500+ individuals; annual summary of smaller breaches within 60 days of year-end
- Contingency planning: data backup, disaster recovery, and emergency mode operations (§164.308(a)(7)) — tested annually
HIPAA Privacy Rule (45 CFR §164.500–§164.534)
Applies to: All covered entities and — through Business Associate Agreements — Business Associates that handle PHI. Sets the permitted uses and disclosures framework that the Security Rule operationalizes.
- Notice of Privacy Practices (NPP) provided to all patients at first delivery of service (§164.520)
- Minimum necessary standard: limit PHI use, disclosure, and requests to the minimum needed (§164.502(b))
- Patient rights: access (§164.524), amendment (§164.526), accounting of disclosures (§164.528), and restriction requests (§164.522)
- Authorization for any use or disclosure of PHI outside treatment, payment, and healthcare operations (§164.508)
- Business Associate Contracts ensuring downstream PHI handling (§164.504(e)) — the contractual foundation for vendor risk management
- De-identification standards (§164.514) — Safe Harbor or Expert Determination paths for using PHI in analytics and AI without authorization
- Marketing and fundraising use rules with opt-out provisions (§164.508 and §164.514)
HITECH Act breach notification (45 CFR §164.404)
Applies to: All covered entities and Business Associates following discovery of a breach of unsecured PHI. Triggered by unauthorized acquisition, access, use, or disclosure that compromises PHI security or privacy.
- Notification to affected individuals without unreasonable delay and no later than 60 days from discovery (§164.404(b))
- Notification to HHS Secretary within 60 days; for breaches affecting 500+ individuals, notify HHS contemporaneously and HHS posts to the public "Wall of Shame"
- Media notice for breaches affecting 500+ residents of a state or jurisdiction (§164.406) — prominent media outlet serving the affected area
- Notification by a Business Associate to the covered entity without unreasonable delay (§164.410) — typically 30–60 days under BAA terms
- Subcontractor BAA breach notification obligations flowing down to every downstream PHI handler
- Documentation of the risk assessment showing low probability of PHI compromise (the breach-presumption defense — must meet four §164.402(2) factors)
- Substitute notice permitted when 10+ individuals are affected and contact information is insufficient: website notice, email, or mail
State medical privacy laws (CA CMIA, NY SHIELD-adjacent covered-entity duties, TX HB300, IL PIPA for health)
Applies to: All healthcare SMBs and SaaS vendors handling PHI of residents in the named states — regardless of where the organization is headquartered. State laws layer additional requirements on top of HIPAA.
- California CMIA (Cal. Civ. Code §§ 56–56.37): broader than HIPAA — covers any provider of healthcare services and any Business Associate; consent required for most disclosures beyond direct patient care
- Texas HB300: applies to "covered entities" handling PHI of Texas residents — requires training, audit logs, and breach notification within 60 days; explicit prohibition on selling PHI
- Illinois PIPA (Personal Information Protection Act, 815 ILCS 530): healthcare-specific data destruction and notification rules layered on top of BIPA biometric requirements
- NY SHIELD Act + NY Public Health Law §18: covered-entity duties for hospitals and health plans; state AG enforcement; private right of action under certain circumstances
- State breach notification clocks often running in parallel with HIPAA — the shortest applicable clock controls (typically 30–60 days)
- Sector-specific duties for hospitals, clinical labs, and behavioral health providers (state licensing regimes beyond HIPAA)
- BAA-equivalent state contract requirements that can exceed HIPAA minimums (e.g. CMIA medical-information release requiring patient authorization)
SOC 2 for healthcare SaaS (contractually required by enterprise buyers and hospital systems)
Applies to: Healthcare SaaS vendors selling B2B into health systems, payers, or enterprise providers; HIPAA-as-a-Service vendors; clinical-trial platforms; telehealth infrastructure providers; any vendor storing, processing, or transmitting PHI on behalf of a covered-entity buyer. Not legally mandated but contractually required by virtually all enterprise healthcare prospects.
- Trust Services Criteria mapped to HIPAA administrative, physical, and technical safeguards — Security (required), Availability, Confidentiality common for healthcare SaaS
- Common Criteria CC1–CC9 + Availability — with CC6 (Logical and Physical Access) and CC7 (System Operations) carrying the heaviest evidence burden for PHI environments
- Continuous monitoring of access to PHI systems; quarterly access reviews for privileged roles
- BAA-gated access controls, MFA on every PHI system, encryption of PHI at rest with AES-256 and in transit with TLS 1.2+
- Vendor risk management evidence under CC9.2 — makes HIPAA §164.308(b)(1) BAAs and §164.314(a) Organizational Requirements audit-ready
- 12-month look-back SOC 2 Type II report from an independent CPA firm covering the full BAA-in-scope period
- Evidence retention for every control test, every access review, and every BAA — auditors expect sampled evidence on demand
- Bridge letter for the gap between the most recent audit period and the present, provided to enterprise prospects
Required Controls at a Glance
These controls provide a practical baseline for sector-specific compliance and cybersecurity gap assessments.
| Control Area | Required Control |
|---|---|
| BAA Inventory | Maintain a current inventory of every Business Associate with PHI access, with signed BAAs reviewed annually and re-signed on scope change (§164.308(b)(1)) |
| Annual Risk Analysis | Documented, dated annual HIPAA risk analysis under §164.308(a)(1)(ii)(A) covering all PHI assets, threats, vulnerabilities, likelihood, and impact |
| PHI Encryption | AES-256 encryption of PHI at rest, TLS 1.2+ in transit, and key management with documented rotation (§164.312(a)(2)(iv) and §164.312(e)(2)(ii)) |
| MFA on PHI Systems | Multi-factor authentication on every system that stores, processes, or transmits PHI — including EHR, PM systems, cloud storage, and admin consoles |
| Audit Logging | Audit controls (§164.312(b)) with ≥90-day retention; log review for break-glass access, admin actions, and anomalous PHI export events |
| Workforce Training | Annual HIPAA training for all workforce members with PHI access, plus documented sanctions policy (§164.308(a)(3) and §164.530(b)) |
| Vendor Risk Tiering | Tier every PHI processor by volume, sensitivity, and access depth; require SOC 2 / HITRUST evidence for high-tier vendors and renew BAAs annually |
| Breach Notification | Documented 60-day individual / 72-hour HHS runbook with named owners, decision matrices, and pre-drafted HIPAA + state notification templates |
HIPAA ↔ SOC 2 Crossover Controls Matrix
For healthcare SMBs and healthcare SaaS vendors, this is an illustrative overlap map between selected HIPAA safeguards and relevant SOC 2 Trust Services Criteria areas. It is not a HIPAA certification, does not mean SOC 2 is required for every organization, and cannot guarantee that an auditor will accept a particular artifact. The evidence column lists examples to prepare and retain; applicability, control design, testing, and evidence expectations depend on your role, systems, risks, contracts, and engagement scope.
| HIPAA safeguard and citation | Relevant SOC 2 Trust Services Criteria area | Practical evidence examples |
|---|---|---|
| Risk analysis and risk management — §164.308(a)(1)(ii)(A)–(B) | CC3 Risk Assessment; CC9 Risk Mitigation | Dated ePHI risk assessment, risk register, treatment decisions, assigned owners, and documented updates after material changes. |
| Access control and authentication — §§164.308(a)(4), 164.312(a), and 164.312(d) | CC6 Logical and Physical Access Controls | System and role inventory, access approvals, joiner/mover/leaver tickets, periodic access reviews, and documented exceptions. |
| Audit controls and activity review — §§164.308(a)(1)(ii)(D) and 164.312(b) | CC4 Monitoring Activities; CC7 System Operations | Log-source inventory, review procedure, dated log-review records, alert investigations, and sampled remediation tickets. |
| Security incident procedures and breach response — §164.308(a)(6); §164.404 where applicable | CC7 System Operations; CC9 Risk Mitigation | Incident-response plan, exercise or tabletop records, incident tickets, decision logs, and notification assessment records. |
| Contingency and availability safeguards — §164.308(a)(7) | Availability (A1); CC7 System Operations | Contingency plan, backup scope, restore-test results, emergency-mode procedures, and follow-up tickets from failed tests. |
| Business Associate and vendor oversight — §§164.308(b)(1) and 164.314(a) | CC9.2 Risk Mitigation for Vendors and Business Partners | BAA/vendor inventory, signed agreements, due-diligence reviews, risk tiers, subcontractor checks, and sampled remediation tickets. |
- NIST CSF PR.AA can provide shared vocabulary for identity, authentication, and access-control discussions alongside HIPAA §164.312.
- NIST CSF DE.CM can add context to monitoring and activity-review discussions alongside HIPAA §§164.308(a)(1)(ii)(D) and 164.312(b).
- NIST CSF RS.RP and GV.SC can add context to incident-response and supplier discussions alongside HIPAA §§164.308(a)(6) and 164.308(b)(1).
Common Healthcare Compliance Gaps: BAA, PHI Handling, and Vendor Access
OCR enforcement actions and HHS breach-report data both cluster around the same four gaps for healthcare SMBs. The first is unsigned or out-of-date Business Associate Agreements with cloud and analytics vendors — the average healthcare SMB uses 30–50 SaaS tools and rarely has signed BAAs on more than a handful. The second is PHI leaving covered scope through screenshots pasted into ticketing systems, AI chatbots, transcription tools, and screen-share recordings — every pasted patient name, DOB, or diagnostic code is a breach the moment it touches a non-covered system. The third is legacy medical-device flat networks — infusion pumps, imaging modalities, and IoMT devices that run Windows XP or unpatched firmware on the same VLAN as the EHR. The fourth is break-glass admin accounts that skip the audit trail — emergency-access procedures without logging are an automatic §164.312(b) audit-control deficiency.
- Vendor-entry-time BAA checklist — require signed BAA before provisioning any PHI-touching vendor; review annually; document substitutions
- Screenshot / PHI-leak policy — explicit prohibition on pasting identifiable patient data into non-covered tools, including AI assistants and ticketing
- Medical-device segmentation rule — IoMT and imaging modalities behind a dedicated VLAN with controlled east-west traffic; no EHR-facing lateral path
- Break-glass logging rule — emergency-access procedures must (a) generate explicit alerts to security, (b) require post-access justification within 24 hours, (c) be reviewed quarterly
- Workforce offboarding checklist — revoke PHI access for departing employees within one business day; rotate shared credentials; reissue MFA tokens
- AI-tool evaluation framework — any vendor using patient data for model training or summarization requires explicit BAA + Opt-Out clause on training use
Frequently Asked Questions
Q: What does HIPAA readiness mean, and what is the annual risk analysis?
Q: How does SOC 2 overlap with HIPAA, and does it replace it?
Q: What evidence should healthcare organizations collect for compliance readiness?
Q: What does the healthcare compliance assessment cover, and what does it not cover?
Take Action
Your next steps — all free, no account required to start.
Start Your HIPAA + SOC 2 + NIST CSF Gap Analysis →
Map your current controls against HIPAA Security/Privacy Rule, SOC 2 CC6/CC7, and NIST CSF 2.0 GV.SC — get a prioritized gap report in minutes.Run a HIPAA-Specific Gap Analysis →
Dedicated HIPAA Security Rule assessment: administrative, physical, and technical safeguards mapped to §164.308–§164.312 with section-level remediation guidance.Score Your BAA + Healthcare Vendor Risk →
Healthcare SMB breaches frequently originate with a Business Associate. Tier every PHI processor and document SOC 2 / HITRUST evidence requirements.Generate Your HIPAA §164.308(a)(6) IRP →
HIPAA requires a documented incident response procedure. Generate an IRP aligned to the 60-day individual / 72-hour HHS notification clocks.See Your Free Healthcare Security Score (0–100) →
Get a quick 0–100 baseline for a PHI-handling clinic, practice, or healthcare SaaS environment before prioritizing remediation.Take the Free 47-Control Healthcare Security Assessment →
Review authentication, patching, network, and access controls across the systems that handle PHI — free, no account required.Download Your Healthcare Security Posture Report →
Get a detailed, actionable report on your PHI environment — HIPAA findings, BAA inventory gaps, and audit-readiness priorities.Read the HIPAA + SOC 2 Framework Comparison →
How HIPAA maps to SOC 2 CC6/CC7 and NIST CSF 2.0 — the architectural model healthcare SaaS vendors use to satisfy both enterprise buyers and OCR.CyberStackHub Tools for Healthcare
These tools are most relevant for healthcare businesses based on your sector's specific risk profile and compliance requirements.
Healthcare Cybersecurity Statistics
Data from public sources including Verizon DBIR, IBM Cost of Data Breach, FBI IC3, and industry-specific research.