United States · 9 controls evidenced

    Continuous evidence for HIPAA Security Rule

    Technical safeguards for US-regulated electronic protected health information.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    See your HIPAA Security Rule readiness in 60 seconds. Free, no signup.

    Sample evidence
    acme-corp.com · HIPAA Security Rule
    Live
    §164.312(e)(1) Transmission security
    Encrypted transport (TLS 1.2+)
    §164.312(e)(2)(ii) Encryption (addressable)
    Encrypted transport (TLS 1.2+)
    §164.308(a)(5)(ii)(B) Protection from malicious software
    Email authentication (SPF / DKIM / DMARC)
    §164.308(a)(6) Security incident procedures
    Credential exposure monitoring
    Updated continuously+ 5 more controls
    Why it matters

    HIPAA Security Rule in 30 seconds

    The HIPAA Security Rule (45 CFR §164.302–318) requires covered entities and business associates to implement technical, physical and administrative safeguards for ePHI. The HHS Office for Civil Rights actively enforces — multi-million dollar settlements for inadequate technical safeguards are routine. The proposed 2025 NPRM strengthens encryption, vulnerability management and incident detection requirements.

    Scope

    US healthcare providers, health plans, healthcare clearinghouses (covered entities) and any business associate processing ePHI on their behalf.

    Exposure

    Tiered civil penalties up to USD 2.1M per violation category per year, plus state AG actions and breach-notification costs.

    Clause-by-clause mapping

    How Security Monitor evidences HIPAA Security Rule

    Each row links a HIPAA Security Rule clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.

    HIPAA Security Rule clauseWhat it requiresHow we evidence it
    TLS-1
    §164.312(e)(1) Transmission security
    Implement technical security measures to guard against unauthorised access to ePHI being transmitted over an electronic communications network.
    Encrypted transport (TLS 1.2+)
    We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname.
    TLS-1
    §164.312(e)(2)(ii) Encryption (addressable)
    Implement a mechanism to encrypt ePHI whenever deemed appropriate. NIST SP 800-52 references modern TLS.
    Encrypted transport (TLS 1.2+)
    We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname.
    EMAIL-1
    §164.308(a)(5)(ii)(B) Protection from malicious software
    Procedures for guarding against, detecting and reporting malicious software, including phishing-related controls.
    Email authentication (SPF / DKIM / DMARC)
    We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses.
    BREACH-1
    §164.308(a)(6) Security incident procedures
    Identify and respond to suspected or known security incidents — including credential exposure on the public internet.
    Credential exposure monitoring
    We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts.
    REP-1
    §164.308(a)(8) Evaluation
    Perform a periodic technical and non-technical evaluation, in response to environmental or operational changes affecting ePHI security.
    Reputation & threat intelligence
    We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing.
    DNS-1
    §164.312(c)(1) Integrity
    Implement policies and procedures to protect ePHI from improper alteration or destruction — including DNS integrity.
    DNS hygiene & DNSSEC
    We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls.
    WEB-1
    §164.312(a)(1) Access control
    Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to authorised persons.
    Secure HTTP response headers
    We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site.
    EXP-1
    §164.308(a)(1)(ii)(A) Risk analysis
    Conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI — including externally exposed assets.
    Exposed files & admin panels
    We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable.
    SUB-1
    §164.308(b)(1) & §164.314(a) Business associate contracts
    Maintain contracts with business associates and identify the systems they touch. The third-party data flow map shows which vendors are actually loaded on patient-facing pages — often a gap versus the BAA register.
    Third-party data flow map (subdomains & external services)
    We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses.
    Honest scope

    What we don’t cover for HIPAA Security Rule

    External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:

    • Workforce training and access management (§164.308(a)(3), §164.308(a)(5))
    • Physical safeguards (§164.310 entire subpart)
    • Audit controls — internal logging of ePHI access (§164.312(b))
    • Breach notification submission to HHS — we surface the trigger; you submit
    FAQ

    HIPAA Security Rule questions

    See your HIPAA Security Rule readiness now

    One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    ISO 27001Aligned
    SOC 2 Type IIControls
    GDPRCompliant
    AES-256Encryption