Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Work through the HIPAA Security Rule safeguards across administrative, physical, and technical controls. Check off what you have in place, watch your completion score update, and export a summary to share with your team. For the broader picture, see our guide to HIPAA for digital health.
No. HIPAA compliance is determined by your actual implemented safeguards, documentation, and risk analysis, not by a self-checklist. This tool helps you see where you stand against the Security Rule safeguards so you can prioritize the work.
It requires administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). That includes a risk analysis, access controls, workforce training, encryption where reasonable, audit controls, and a contingency plan, among others.
Covered entities such as healthcare providers and health plans, and business associates that handle ePHI on their behalf. If you build software that touches health data for a covered entity, you are likely a business associate and need a Business Associate Agreement.
Yes. A documented, periodic risk analysis is an explicit Security Rule requirement and one of the most commonly cited gaps in enforcement actions. It is the foundation everything else builds on.
Yes, it is free with no signup, and nothing you check is sent anywhere. If you need help reaching and documenting HIPAA compliance, our team can guide the program.
Not ready for a call yet?
A few short notes from Jacob on getting audit-ready without months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Want it done for you?
HIPAA Readiness
We get you aligned to the HIPAA Security Rule safeguards.
Explore HIPAA Readiness →We help teams in the healthcare & healthtech industry run the risk analysis, implement the safeguards, and produce the documentation HIPAA actually requires. Turn this checklist into a real program.
See our compliance services Book a callThis gives you the shape of the problem. The full picture is all 84 HIPAA safeguards, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.
No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the workspace.