Protected health information lives across your EHR, cloud, and a long list of business associates. Compyl maps one control library across the HIPAA Security, Privacy, and Breach rules, and the frameworks around them, so you prove compliance continuously instead of before an OCR inquiry.
Three rules govern the same data, dozens of business associates touch it, and an investigator can ask for proof at any time.
HIPAA’s Security, Privacy, and Breach rules each impose requirements on the same data, multiplying the controls you must prove.
EHRs, billing, cloud, and clinical vendors all touch PHI under BAAs, and you are accountable for every one of them.
Audits and breach investigations can arrive at any time, and point-in-time evidence will not hold up.
Three HIPAA rules and the frameworks around them, one control library. Each tile shows who enforces it, what it asks, and the shared control Compyl evidences once.
Administrative, physical, and technical safeguards for electronic PHI.
Uses and disclosures of PHI, minimum necessary, and patient rights.
Notify individuals, HHS, and media after a breach of unsecured PHI.
Strengthened enforcement, breach rules, and business-associate liability.
Breach and privacy laws that layer on top of HIPAA in each state.
Protect cardholder data for patient payments and billing.
Partner and payer assurance that your safeguards operate as described.
A recognized security practice OCR must weigh under HITECH §13412.
Define controls once and cross-map them to the Security, Privacy, and Breach rules, HITECH, SOC 2, and NIST CSF, so evidence collected once proves them all.
Integrations pull evidence from your EHR, identity, and cloud systems around the clock, and Evidence Health flags stale proof before an investigator asks.
Continuously assess and monitor every vendor that touches PHI, track BAAs, and quantify exposure in dollars for leadership and the board.
Compyl maps each control and its evidence across every rule and framework that requires it, so a single artifact, pulled automatically from your stack, counts everywhere at once.
All cross-mapped to one control library. Explore each, or see the full library of 70+.
“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”
Plenty of tools store a HIPAA policy. Compyl runs the whole program, safeguards, evidence, risk, and business associates, across every rule you answer to.
Controls, evidence, risk, and vendors in one connected system, across every regulator you answer to.
Evidence refreshes automatically and is scored for health, so you are audit-ready every day of the year.
EHR, identity, cloud, and ticketing systems feed evidence automatically.
AI drafts evidence, maps controls, and triages risk; your experts approve every decision.
FAIR-based quantification turns PHI and vendor risk into numbers leadership can act on.
Healthcare organizations must protect electronic protected health information (ePHI) under the HIPAA Security, Privacy, and Breach Notification rules, reinforced by HITECH and state health-privacy laws. Many also handle PCI DSS for payments and pursue SOC 2 for partner assurance, while managing a wide network of business associates under BAAs. Compyl maps one control library across all of it and continuously collects the evidence to prove it.
The recurring obligations behind healthcare compliance, with the rule that sets each one.
| Obligation | Rule | Cadence | With Compyl |
|---|---|---|---|
| Conduct a risk analysis | HIPAA Security Rule §164.308(a)(1) | Ongoing, reviewed regularly | Risk register tied to safeguards and evidence |
| Implement technical safeguards | HIPAA Security Rule §164.312 | Continuous | Access, audit, integrity, and transmission controls monitored |
| Notify after a breach | Breach Notification Rule | No later than 60 days; breaches under 500 logged yearly | Incident workflow with the notification record |
| Train the workforce | Privacy and Security Rules | On hire and periodically | Training tracked as evidence |
| Maintain business associate agreements | Privacy Rule §164.504(e) | Before sharing PHI, renewed on change | BAA register with expirations and vendor risk |
| Retain documentation | §164.316 | Six years | Evidence retained and versioned |
Healthcare organizations must protect ePHI under the HIPAA Security, Privacy, and Breach Notification rules, reinforced by HITECH and state health-privacy laws. Many also handle PCI DSS for payments and pursue SOC 2 for partner assurance, while managing business associates under BAAs. Compyl maps one control library to all of it.
Compyl maps your controls to each HIPAA requirement across the Security, Privacy, and Breach rules, then continuously collects evidence from your EHR, identity, and cloud systems. Evidence Health scores every artifact, so safeguard gaps and stale proof surface well before an OCR inquiry or audit.
Yes. With cross-mapping, evidence that ePHI is encrypted can satisfy HIPAA §164.312(e), HITECH, SOC 2 CC6.6, NIST CSF PR.DS, and PCI DSS 3.5 at once. You collect it a single time and it counts everywhere it applies.
Yes. Compyl continuously assesses and monitors every vendor that touches PHI, tracks business associate agreements, surfaces expirations early, and quantifies third-party exposure in dollars, so you stay accountable for your entire BAA network.
Compyl keeps a current, organized evidence pack for every safeguard, including the risk analysis, access reviews, audit logs, training records, and BAAs, so an OCR request is answered from live proof rather than a scramble.
No. HHS proposed the overhaul in December 2024 and moved it to its long-term agenda with a July 2027 target. The existing Security Rule, including risk analysis, remains fully enforceable, and preparing now for encryption, MFA and asset inventory expectations still reduces enforcement risk.
An enforcement push targeting failures to perform an accurate, thorough HIPAA risk analysis. By mid-2026 it had produced more than a dozen enforcement actions, many after ransomware attacks, and a missing or stale risk analysis remains OCR’s most common finding.
The compliance date for the 2024 Part 2 final rule on substance use disorder records, when OCR enforcement began, and the deadline for Notice of Privacy Practices updates that survived the June 2025 court decision vacating the reproductive health privacy rule.
The Cyber Incident Reporting for Critical Infrastructure Act will require covered entities to report substantial cyber incidents to CISA within 72 hours and ransom payments within 24 hours. CISA’s final rule has been delayed several times and was targeted for fall 2026, and reporting obligations start only once the final rule takes effect.
One control library, every rule, continuous evidence, and agentic AI that removes the busywork, with your experts in control.