Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

HIPAA

HIPAA, the US Health Insurance Portability and Accountability Act, sets national rules for protecting individuals' health information. Its Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI). It applies to healthcare providers, health plans, and the business associates that handle health data on their behalf.

In practice

If your software touches patient data on behalf of a covered entity, you are likely a business associate and must sign a Business Associate Agreement (BAA) and meet the Security Rule. That obligation flows down your subcontractor chain too.

HIPAA is principles-based rather than a fixed checklist, centered on a documented risk analysis. Many health-tech vendors layer SOC 2 on top to give buyers an independent attestation alongside their HIPAA posture.

// how traztech helps

traztech delivers HIPAA Security Rule readiness for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

HIPAA arrives through a customer contract far more often than through a regulator. A health system or payer asks you to sign a Business Associate Agreement, and the obligations follow from that.

The most common gap is the Security Rule risk analysis. It is mandatory, it is specific, and it is frequently missing entirely because teams assumed a policy set covered it.

HIPAA: common questions

Is there a HIPAA certification?

No. Nobody issues a HIPAA certificate. What your customers are asking for is evidence: the risk analysis, your safeguards, your BAAs and your breach notification process.

Does our cloud provider make us HIPAA compliant?

No. A BAA from AWS, GCP or Azure covers their layer. Your application, access controls, logging and staff training sit outside it and are exactly what a customer security team will ask about.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.