Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

How to Get HIPAA: A Step-by-Step Guide

Getting HIPAA compliant means implementing the administrative, physical, and technical safeguards the HIPAA Security Rule requires, then documenting them well enough to hold up under a covered entity's vendor risk review. There is no HIPAA "certification" issued by the government, so the real goal is a defensible compliance posture, typically built over 8 to 14 weeks, that satisfies the Business Associate Agreements (BAAs) US healthcare customers will demand before they sign.

For Canadian digital health companies selling into the US market, this catches founders off guard. You assumed there would be an exam, a badge, a certificate to put on the website. Instead there is a body of evidence: policies, risk assessments, access controls, and a signed BAA, all of which a hospital system's procurement team or a health plan's security office will pick apart line by line. Here is how to build that evidence set without over-engineering it.

Step 1: Confirm You Actually Need HIPAA (and What Kind)

Before spending a dollar, nail down your role under HIPAA. Most digital health startups fall into one of two buckets:

  • Business Associate (BA): you handle Protected Health Information (PHI) on behalf of a covered entity (a hospital, clinic, insurer, or another BA). This is the common case for SaaS vendors, EHR integrations, and remote monitoring platforms.
  • Covered Entity: you are a healthcare provider or health plan yourself, which is rarer for a startup but happens with telehealth and direct-to-consumer clinical services.

If you never touch, store, or transmit PHI, you may not need HIPAA at all, though your customer's legal team will still want that determination in writing. This step alone saves companies weeks of unnecessary work, and it is where a partner who has scoped this before earns their fee immediately.

Step 2: Run a HIPAA Risk Assessment

The Security Rule's Risk Analysis requirement, 45 CFR 164.308(a)(1)(ii)(A), is the foundation everything else sits on. It is also the single most-requested artifact in vendor security reviews. A proper risk assessment inventories:

  • Every system, database, and third-party service that stores or processes PHI
  • Threats and vulnerabilities against each asset (unencrypted backups, shared admin credentials, unpatched servers)
  • The likelihood and impact of each risk, with a remediation plan and owner

Skip the generic checklist template. Auditors and enterprise security teams can tell within a page whether a risk assessment reflects your actual infrastructure or was copied from a boilerplate. Expect this step to take one to two weeks for a typical SaaS stack on AWS, Azure, or GCP.

Step 3: Build the Required Policies and Procedures

HIPAA does not prescribe a specific framework, but it does require documented policies covering access management, incident response, breach notification, workforce training, device and media controls, and business continuity. Most digital health companies need 15 to 20 policies at minimum. The trap here is writing policies nobody follows, an examiner or customer will ask for evidence, not just the document, so build policies your team can realistically operate day to day.

This is also where it pays to think ahead to SOC 2. Many of the same controls, access reviews, change management, vendor management, satisfy both frameworks, and running HIPAA readiness alongside a SOC 2 engagement avoids duplicating the same evidence collection twice. We cover this overlap in detail on our HIPAA compliance for digital health page, which is worth reviewing before you scope the work.

Step 4: Implement Technical Safeguards

This is the engineering-heavy phase. At minimum you need:

  • Encryption for PHI at rest and in transit (AES-256 and TLS 1.2+ are the practical defaults)
  • Access controls with unique user IDs, role-based permissions, and automatic session timeouts
  • Audit logging that captures who accessed PHI, when, and what they did with it
  • Multi-factor authentication on any system touching PHI, including admin consoles and cloud infrastructure
  • Backup and disaster recovery procedures with tested restoration

Most modern cloud-native health tech companies already have a good chunk of this in place. The work is usually closing gaps, tightening logging, and documenting configurations rather than rebuilding infrastructure from zero. Budget two to four weeks depending on how much of your stack is already hardened.

Step 5: Execute Business Associate Agreements

Every vendor that touches PHI on your behalf, your cloud host, your email provider, your analytics tool, needs a signed BAA. And every covered entity or upstream BA that sends you PHI will require one from you before go-live. Build a BAA tracking log early. Sales cycles stall for weeks when a customer's legal team sends a BAA and nobody on the vendor side knows who owns getting it signed.

Step 6: Train Your Workforce

HIPAA requires documented security awareness training for anyone with access to PHI, delivered at onboarding and at least annually after. For a small team this can be a half-day session covering phishing, password hygiene, incident reporting, and acceptable use, but it has to be tracked with completion records. Customers will ask for training logs during due diligence.

Step 7: Decide Between a Readiness Assessment and Full HITRUST Certification

This is the decision point where most Canadian founders overspend. HITRUST CSF certification is a rigorous, expensive, multi-month undertaking that some large health systems require, but it is overkill for an early-stage company trying to close its first few US healthcare deals. A properly documented HIPAA readiness assessment, backed by a risk analysis, policy set, and technical safeguards, satisfies the vast majority of enterprise vendor security reviews and BAAs. Save HITRUST for the point where a specific deal genuinely requires it, not as a default starting posture.

Realistic Timelines

For a digital health company with a reasonably modern cloud stack:

  • Weeks 1 to 2: scoping and risk assessment
  • Weeks 3 to 6: policy development and technical remediation
  • Weeks 7 to 10: BAA execution, training rollout, evidence collection
  • Weeks 11 to 14: internal review, gap closure, readiness sign-off

Companies that already have SOC 2 controls in place, or that run SOC 2 and HIPAA readiness in parallel, often move faster because access management, logging, and vendor management evidence carries over between the two.

Where a Compliance Partner Actually Helps

The parts of this process that eat the most founder time, translating generic policy templates into something specific to your product, scoping the risk assessment correctly, and knowing which controls double up with SOC 2, are exactly where an experienced partner shortens the timeline. traztech works with Canadian digital health and healthtech companies selling into the US, building HIPAA readiness that stands up to enterprise procurement without the cost or timeline of a full HITRUST engagement. We serve teams in Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal, and we build compliance programs that account for Canadian obligations too, including PIPEDA and Quebec's Law 25, alongside the US requirements your customers are asking about. If your roadmap includes broader security work, our compliance solutions page outlines how HIPAA readiness fits alongside SOC 2 and other frameworks.

Get Your HIPAA Readiness Roadmap

If you are fielding a security questionnaire from a US health system or preparing to sign your first BAA, get in front of it now rather than during a stalled deal. Contact traztech to scope a HIPAA readiness engagement built around your actual stack, your actual sales timeline, and the deals you are trying to close.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation