Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →If your product touches protected health information and you are selling into hospitals, payers, or providers, HIPAA is going to come up fast. This guide explains, in plain language, when HIPAA actually applies to you, what it requires, why your buyers also want SOC 2, and how a Toronto team gets you ready without the guesswork.
Book a free readiness callHIPAA does not care whether you call yourself a health company. It cares about protected health information, or PHI, which is identifiable health data such as a patient name tied to a diagnosis, a claim, a test result, or a device reading. The moment you create, receive, store, or transmit PHI on behalf of someone else, HIPAA is in play.
The two roles that matter are simple. A covered entity is the organization at the center of care or payment: a hospital, a clinic, a physician group, a health plan, or a payer. A business associate is a company that handles PHI on behalf of a covered entity. If you are a digital health, medtech, or healthtech vendor, you are almost always the business associate, not the covered entity.
In practice the trigger is a signature. When a hospital, clinic, or payer wants to use your product with real patient data, they will ask you to sign a Business Associate Agreement, or BAA. That contract is usually the moment the obligation becomes visible, but it is not what creates it. Under 45 CFR 160.103 you are a business associate because of what you do with the data, and since HITECH the Security Rule and the breach rules apply to you directly whether or not anyone ever signed a BAA. Operating without one does not mean HIPAA does not apply, it means you are already non-compliant. So the honest test is not "are we a health company," it is "are we about to sign a BAA," and for most companies selling into providers or payers the answer is yes.
The HIPAA Security Rule groups your obligations into three categories of safeguards. Here is what each one means without the legalese.
The people and process side. A documented risk analysis that identifies where PHI lives and what could go wrong, written policies and procedures, a named security official, workforce training, and access management so only the right people can reach the data. This is where most first-time programs are thinnest, because the risk analysis is a genuine requirement, not a formality.
Protecting the physical places and devices where PHI can be reached. For a cloud-native product this leans heavily on your hosting provider, but it still covers facility access, workstation use, and how laptops and drives are controlled and disposed of. You inherit a lot of this from your cloud, and you document what you inherit.
The controls in your systems: access control so each user is uniquely identified and limited to what they need, encryption of PHI in transit and at rest, audit logging so you can reconstruct who did what, and integrity and transmission controls. This is the part a buyer's technical reviewer will actually test, so it needs to be real, not just written down.
Two things people miss: a HIPAA program is anchored by a documented risk analysis, and you need signed BAAs flowing in both directions, with the covered entities you serve and with your own subprocessors such as your cloud host and any vendor that touches PHI on your behalf.
Here is the friction point almost every digital health company hits. HIPAA is a legal obligation, but it produces no certificate. There is nothing to hand a hospital's vendor security team that proves you did the work, because the government does not certify anyone as HIPAA compliant. So buyers ask for something they can independently verify, and increasingly that is a SOC 2 Type II report on top of HIPAA.
The good news is that the two overlap heavily. Access control, encryption, audit logging, risk assessment, vendor management, and incident response show up in both. Building them twice is wasteful. Building them once and mapping the same evidence to both HIPAA safeguards and SOC 2 criteria is how experienced teams do it, which is why we run HIPAA readiness and SOC 2 as one program rather than two disconnected projects.
If you want the SOC 2 side in detail, see our playbook on SOC 2 for Canadian SaaS and how our compliance program works end to end.
The honest answer is that it depends on scope. A small team with clean cloud infrastructure and only a few subprocessors gets ready faster than a company retrofitting an older product that was not built with PHI boundaries in mind. What we can promise is a fixed scope, so you know the number and the plan before you start, rather than an open hourly meter that grows every week.
A typical readiness engagement runs the risk analysis, closes the priority gaps, and gets your policies, training, and BAAs in order in a matter of weeks. If you are running HIPAA and SOC 2 together, the SOC 2 Type II observation window then adds the usual monitoring period on top, which is worth planning for early.
One caveat worth setting up front. Some large buyers ask specifically for HITRUST. If a buyer demands full HITRUST certification, that is a larger, separate program with its own cost and timeline, and it sits outside our prep-only lane. We will tell you plainly if that is what you are facing so you can budget for it, rather than discovering it late.
We are a Toronto boutique prep partner, and we run HIPAA readiness and SOC 2 together so you build the evidence once. We are also unusually technical about it. Our founder is a published security researcher with five published CVEs, including CVE-2024-45163 (CVSS 9.1), the kill-switch for the Mirai botnet, so when we build technical safeguards like access control, encryption, and audit logging, they are real controls that hold up when a hospital or payer starts testing them. We quote fixed scope, we coordinate your independent SOC 2 auditor, and when a penetration test is needed as evidence we run it with our offensive-security partner. If you do not have security leadership in-house, our fractional CISO service can own the program end to end, and once you are live we keep watching for new gaps through ongoing vulnerability management. To be clear about our lane, we do HIPAA readiness and SOC 2 prep, and if a buyer insists on full HITRUST certification we will scope that honestly as a separate, larger program.
Tell us what you are building, who is asking, and your deadline. We will tell you honestly what HIPAA requires of you, whether you also need SOC 2, and how fast we can get you there. Once you are underway, you can track evidence requests and policies through our traztech Workspace.
Book a free readiness callIf you create, receive, store, or transmit protected health information on behalf of a covered entity like a hospital, clinic, or payer, then yes. You are a business associate because of what you do with the data, not because of the paperwork, and the Security Rule applies to you directly. A Business Associate Agreement documents that relationship, it does not create it. If you never touch identifiable health data, HIPAA may not apply, but most digital health and medtech products do handle it at some point.
No. There is no official HIPAA certificate and no government body that certifies you as HIPAA compliant. You demonstrate compliance through a documented risk analysis, written policies, technical safeguards, training records, and signed Business Associate Agreements. Any vendor selling a HIPAA certificate is selling something HIPAA does not define. What you can show a buyer is evidence of a real program, which is why many companies pair HIPAA readiness with a SOC 2 report.
Often, yes. HIPAA is a legal requirement when you handle protected health information, but it produces no certificate a buyer can file. Hospitals and payers increasingly ask for a SOC 2 Type II report on top of HIPAA because it is an independent, audited attestation. The two frameworks overlap heavily on access control, encryption, and monitoring, so they are best run as one program rather than two.
A Business Associate Agreement is a contract between a covered entity and a business associate, or between a business associate and its own subcontractors. It requires you to safeguard protected health information, limit how you use it, report breaches, and hold your subprocessors to the same standard. Signing a BAA is usually when the obligation becomes concrete, though HIPAA applies to a business associate directly regardless, and you also need BAAs in place with vendors like your cloud host and any subprocessor that touches the data.
It depends on scope and where you are starting. A small digital health team with clean cloud infrastructure and few subprocessors moves faster than a company retrofitting an older product. With a fixed scope, we can complete a risk analysis, close the priority gaps, and get your policies and BAAs in order in a matter of weeks. If you are running HIPAA and SOC 2 together, the SOC 2 Type II observation window then adds the usual monitoring period on top.
Every readiness programme needs a control library, an evidence register, policies and a score for the board. Being quoted five figures a year for that is normal. Paying it is not.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.