HIPAA Compliance — the Security Rule, Actually Operated
Whether you’re a practice or the vendor that serves one, if electronic protected health information flows through your systems, HIPAA’s Security Rule is your responsibility. We implement and run the administrative, physical, and technical safeguards it requires — and we sign the BAA to stand behind them.
The honest part up front: there’s no such thing as a “HIPAA certificate.” What a regulator wants to see is a documented risk analysis and safeguards that are actually running. That’s exactly what we build.
HIPAA in plain English
HIPAA has two rules that matter to IT. The Privacy Rule governs how PHI may be used and disclosed — that’s your policies and your clinical workflows. The Security Rule governs how electronic PHI is protected, and it’s where an IT and security partner does the heavy lifting: risk analysis, access control, audit logging, encryption, and recovery. We own the Security Rule side and support your program around it.
| Safeguard family | What it covers | Where we operate |
|---|---|---|
| Administrative | Risk analysis, security responsibility, training, contingency planning | Risk analysis support, training, incident response, tested backup (published retention rates) |
| Physical | Facility and device access, media controls | Hosting on infrastructure we own in an access-controlled, third-party facility held to published standards; device management |
| Technical | Access control, audit controls, integrity, transmission security | MFA and unique IDs, SIEM audit logging, encryption in transit and at rest |
The Security Rule is deliberately scalable — a two-provider clinic and a hospital are held to the same families of safeguards, sized to their risk. Small doesn’t mean exempt; it means right-sized.
The HIPAA safeguards we implement and operate
The Security Rule reads like a checklist of good IT discipline. That discipline is our product:
Risk Analysis
A documented, periodic assessment of where ePHI lives and what threatens it — the required foundation every safeguard is built to answer, and the first thing an investigator asks for.
Access Control & MFA
Unique user IDs, least-privilege access, and multi-factor authentication into anything holding PHI — the technical safeguard attackers test first.
Audit Controls (SIEM)
Centralized logging that records who touched what, when — the audit-control requirement, and the evidence that turns “we think we’re fine” into proof.
Encryption
PHI encrypted at rest and in transit, including email — the “addressable” control that is, in practice, expected, and the difference between an incident and a reportable breach.
Backup & Contingency
Encrypted, tested backup (published retention rates) and a data-recovery plan — the contingency safeguard that keeps a ransomware event from becoming a patient-care emergency.
Training & Response
Recurring workforce security-awareness training (Secure IT) with completion records, plus a written, tested incident-response plan for breach handling and notification.
Where HIPAA readiness lives in our plans
The safeguards HIPAA expects — SIEM audit logging, MFA, encryption, awareness training and Microsoft 365 backup at one-year immutable retention — are the substance of Secure IT, on Core IT’s foundation; server and endpoint backup for the rest of your environment are itemized at published rates. PHI is hostable on infrastructure we own through Cloud Complete under a BAA. Already have internal IT or an EHR vendor? Co-Managed IT adds the security depth alongside them. See every published rate →
Working the Security Rule yourself first? Our printable HIPAA Security Rule checklist walks the three safeguard families — free, no form wall.
HIPAA is one lane of a wider practice. See how we approach SOC 2, PCI DSS, and the rest on our compliance hub →
HIPAA, asked and answered
Will CRC Cloud sign a Business Associate Agreement (BAA)?
Yes. If we manage systems that create, receive, maintain, or transmit your electronic protected health information, HIPAA makes us your business associate, and a signed BAA is required before we touch that data. We treat the BAA as a baseline, not a favor — it defines exactly what we safeguard, how we report, and what happens to your data at the end of the relationship. We sign it with you directly, and where a vendor of ours handles PHI those obligations flow down to them. If your compliance team wants that chain documented for their vendor file — who touches what, under which agreement — ask, and we will put it in writing.
Is there such a thing as being “HIPAA certified”?
No official HIPAA certification exists — the government does not certify anyone, and any vendor selling you a “HIPAA certified” stamp is selling marketing. What actually matters is a documented risk analysis and a set of administrative, physical, and technical safeguards you can show a regulator. That is what we build and operate: the Security Rule made real, with the evidence to back it.
Who has to comply — is it only hospitals and doctors?
No. HIPAA covers “covered entities” — healthcare providers, health plans, and clearinghouses — and equally their “business associates,” the vendors who handle PHI on their behalf. That sweeps in dental and behavioral-health practices, medical billing and transcription firms, IT providers, and many SaaS companies. If PHI flows through your systems, the Security Rule applies to you.
What does the HIPAA Security Rule actually require?
Three families of safeguards for electronic PHI. Administrative: a risk analysis, assigned security responsibility, workforce training, and contingency planning. Physical: controls over facilities and devices. Technical: access control, unique user IDs, audit controls, integrity protection, and transmission security. Encryption and offsite backup are “addressable,” which in practice means required unless you can document why not — and you rarely can.
Which HIPAA safeguards does CRC Cloud implement and operate?
The technical and much of the administrative core: risk analysis support, access control with MFA and unique IDs, audit controls through centralized SIEM logging (Secure IT), encryption of data at rest and in transit, tested backup (published retention rates) and contingency (published retention rates) for data recovery, workforce security-awareness training (Secure IT), and an incident-response plan for breach handling. We keep the documentation current so an OCR inquiry meets a binder, not a scramble.
Is the Security Rule changing?
Yes — a proposed update would make long-“addressable” practices explicitly mandatory: MFA, encryption, asset inventories, network segmentation, and regular testing. The direction is unmistakable, so we build to the stronger standard now. Practices that already run these controls will absorb the change quietly; those relying on 2013-era minimums will not.
Does hosting with CRC Cloud help with HIPAA?
It simplifies the physical and infrastructure safeguards. PHI can live on infrastructure we own inside a third-party Southern California datacenter held to published standards — access-controlled, monitored, with N+1 redundant power and cooling and tested recovery — under our BAA, rather than a server closet you have to defend. The administrative and technical safeguards we operate on top supply the ongoing evidence.
Priced openly, like everything else we do. HIPAA work carries a published uplift of +15% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $287.50 per user per month. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →