Compyl
Industry · HealthcareProviders · health tech

Safeguard PHI. Prove HIPAA daily.

Protected health information lives across your EHR, cloud, and a long list of business associates. Compyl maps one control library across the HIPAA Security, Privacy, and Breach rules, and the frameworks around them, so you prove compliance continuously instead of before an OCR inquiry.

Last reviewed September 2026 by the Compyl GRC team
3 HIPAA rules125+ integrationsEvery BAA tracked
Your regulatory year · healthcareLive evidence status · every safeguard checked hourly
JanFebMarAprMayJunJulAugSepOctNovDec
JanWorkforce HIPAA trainingPrivacy and Security Rules97% complete
MarSecurity risk analysis§164.308(a)(1)Reviewed
May – JunBAA renewalsPrivacy Rule §164.504(e)1 expiring
Jul – AugSOC 2 Type II windowPartner assuranceEvidence current
SepAccess review · EHRSecurity Rule §164.312Current
OctPCI DSS SAQPatient paymentsScheduled
Always on · 60-day breach notification clock, audit logging, and OCR readinessContinuous monitoring, not a pre-inquiry scramble
The challenge

Why GRC is harder in healthcare

Three rules govern the same data, dozens of business associates touch it, and an investigator can ask for proof at any time.

PHI across three rules

HIPAA’s Security, Privacy, and Breach rules each impose requirements on the same data, multiplying the controls you must prove.

Business associate sprawl

EHRs, billing, cloud, and clinical vendors all touch PHI under BAAs, and you are accountable for every one of them.

Continuous OCR exposure

Audits and breach investigations can arrive at any time, and point-in-time evidence will not hold up.

Who you answer to

Every rule that governs PHI

Three HIPAA rules and the frameworks around them, one control library. Each tile shows who enforces it, what it asks, and the shared control Compyl evidences once.

Security Rule

HIPAA
HHS · OCR

Administrative, physical, and technical safeguards for electronic PHI.

Shared controlAccess control · audit logs · encryption
§164.308 – 164.312

Privacy Rule

HIPAA
HHS · OCR

Uses and disclosures of PHI, minimum necessary, and patient rights.

Shared controlAccess policies · workforce training
§164.500 – 164.534

Breach Notification

HIPAA
HHS · OCR

Notify individuals, HHS, and media after a breach of unsecured PHI.

Shared controlIncident response · encryption
60 days from discovery

HITECH

Federal
HHS · OCR

Strengthened enforcement, breach rules, and business-associate liability.

Shared controlEncryption safe harbor
Tiered penalties

State privacy laws

State
State attorneys general

Breach and privacy laws that layer on top of HIPAA in each state.

Shared controlIncident response · notification
Varies by state

PCI DSS v4.0.1

Card networks
PCI SSC

Protect cardholder data for patient payments and billing.

Shared controlMFA · encryption · logging
Annual SAQ or ROC

SOC 2

Assurance
AICPA

Partner and payer assurance that your safeguards operate as described.

Shared controlShared with the Security Rule
Type I / Type II

NIST CSF 2.0

Framework
NIST

A recognized security practice OCR must weigh under HITECH §13412.

Shared controlShared across every rule above
Recognized practices
One control library

Map one control library across every HIPAA rule

Define controls once and cross-map them to the Security, Privacy, and Breach rules, HITECH, SOC 2, and NIST CSF, so evidence collected once proves them all.

  • No duplicate work across rules or frameworks
  • Each new framework reuses safeguards you already have
  • Every artifact mapped to every requirement it satisfies
  • Coverage visible per rule, not buried in spreadsheets
One control library · every HIPAA ruleCross-mapped automatically
Encryption of ePHI enabledPulled automatically from AWS / Azure
5requirements
HIPAA Security§164.312(e)
Satisfied
HITECHEncryption safe harbor
Satisfied
SOC 2CC6.6
Satisfied
NIST CSF 2.0PR.DS-01
Satisfied
PCI DSS v4.0.1Req 3.5
Satisfied
ISO 27701Privacy controls
Also covered
Each new framework reuses safeguards you already haveNo duplicate work
OCR readiness

Stay continuously audit-ready for OCR

Integrations pull evidence from your EHR, identity, and cloud systems around the clock, and Evidence Health flags stale proof before an investigator asks.

  • Prove safeguards with current evidence, not screenshots
  • Surface control gaps weeks before they become findings
  • Keep the required risk analysis current and evidenced
  • Drift becomes a tracked task with an owner and a deadline
Safeguard monitoringContinuous control monitoring
Safeguards evidenced52 / 54
Risk analysisReviewed Q3
Breach clock60-day · armed
Workforce training97%
Access reviews · EHR and clinical appsEpic · Okta · 1,240 accounts reviewed
Current
Audit logging · PHI accessSIEM · retained 6 years · checked hourly
Current
BAA · billing vendorExpires in 21 days · renewal requested
Expiring
Gaps surface weeks before they become findingsEvidence Health 98
Business associates

Manage business associate (BAA) risk

Continuously assess and monitor every vendor that touches PHI, track BAAs, and quantify exposure in dollars for leadership and the board.

  • Continuous third-party monitoring and vendor risk
  • Track every BAA and surface expirations early
  • Automated security questionnaires for new vendors
  • FAIR-based risk reporting, board-ready
Business associate riskVendors touching PHI · FAIR
Cloud EHR hostHosts ePHI · BAA current · SOC 2 Type II on file
Critical
Medical billingClaims data · BAA expiring 21d · questionnaire sent
Medium
Analytics SaaSDe-identified data only · annual review
Low
Loss exposure$3.1M → $1.4M
Top scenarioBA breach
Every BAA tracked, every expiration surfaced earlyFAIR-based
Collect once, satisfy every regulator

One piece of evidence. Every rule it satisfies.

Compyl maps each control and its evidence across every rule and framework that requires it, so a single artifact, pulled automatically from your stack, counts everywhere at once.

  • One control library mapped to 70+ frameworks and regulations
  • Collect evidence once and reuse it across every audit and inquiry
  • See instantly how HIPAA work translates to SOC 2 or NIST CSF
  • Add the next framework without starting over
One controlEncryption of ePHI at rest and in transitPulled automatically from AWS KMS and TLS configuration · scored 98 by Evidence Health1 piece of evidence
Satisfies at once
HIPAA Security Rule§164.312(a)(2)(iv) · (e)(2)(ii) Encryption
Satisfied
HITECHEncryption safe harbor for unsecured PHI
Satisfied
SOC 2CC6.6 · CC6.7 Transmission and at-rest protection
Satisfied
NIST CSF 2.0PR.DS-01 · PR.DS-02 Data protected
Satisfied
+ 70 more frameworks cross-mapped automatically
Coverage

Frameworks that govern healthcare

All cross-mapped to one control library. Explore each, or see the full library of 70+.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
3
HIPAA rules mapped to one control library
125+
Native integrations feeding evidence automatically
Real-time
Evidence collection, no manual screenshots
Year-round
OCR readiness instead of a pre-inquiry scramble

“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”

JSJon SeniorCTO · via G2
Why Compyl for healthcare

Built for the way healthcare GRC actually works

Plenty of tools store a HIPAA policy. Compyl runs the whole program, safeguards, evidence, risk, and business associates, across every rule you answer to.

01

One source of truth

Controls, evidence, risk, and vendors in one connected system, across every regulator you answer to.

02

Continuous, not point-in-time

Evidence refreshes automatically and is scored for health, so you are audit-ready every day of the year.

03

125+ integrations

EHR, identity, cloud, and ticketing systems feed evidence automatically.

04

Agentic AI, human approved

AI drafts evidence, maps controls, and triages risk; your experts approve every decision.

05

Risk in dollars

FAIR-based quantification turns PHI and vendor risk into numbers leadership can act on.

What does compliance for healthcare require?

Healthcare organizations must protect electronic protected health information (ePHI) under the HIPAA Security, Privacy, and Breach Notification rules, reinforced by HITECH and state health-privacy laws. Many also handle PCI DSS for payments and pursue SOC 2 for partner assurance, while managing a wide network of business associates under BAAs. Compyl maps one control library across all of it and continuously collects the evidence to prove it.

Obligations

What does each rule expect you to prove?

The recurring obligations behind healthcare compliance, with the rule that sets each one.

ObligationRuleCadenceWith Compyl
Conduct a risk analysisHIPAA Security Rule §164.308(a)(1)Ongoing, reviewed regularlyRisk register tied to safeguards and evidence
Implement technical safeguardsHIPAA Security Rule §164.312ContinuousAccess, audit, integrity, and transmission controls monitored
Notify after a breachBreach Notification RuleNo later than 60 days; breaches under 500 logged yearlyIncident workflow with the notification record
Train the workforcePrivacy and Security RulesOn hire and periodicallyTraining tracked as evidence
Maintain business associate agreementsPrivacy Rule §164.504(e)Before sharing PHI, renewed on changeBAA register with expirations and vendor risk
Retain documentation§164.316Six yearsEvidence retained and versioned
Healthcare FAQ

Healthcare questions, answered

What compliance do healthcare organizations need?

Healthcare organizations must protect ePHI under the HIPAA Security, Privacy, and Breach Notification rules, reinforced by HITECH and state health-privacy laws. Many also handle PCI DSS for payments and pursue SOC 2 for partner assurance, while managing business associates under BAAs. Compyl maps one control library to all of it.

How does Compyl help with HIPAA compliance?

Compyl maps your controls to each HIPAA requirement across the Security, Privacy, and Breach rules, then continuously collects evidence from your EHR, identity, and cloud systems. Evidence Health scores every artifact, so safeguard gaps and stale proof surface well before an OCR inquiry or audit.

Can one piece of evidence satisfy HIPAA and other frameworks?

Yes. With cross-mapping, evidence that ePHI is encrypted can satisfy HIPAA §164.312(e), HITECH, SOC 2 CC6.6, NIST CSF PR.DS, and PCI DSS 3.5 at once. You collect it a single time and it counts everywhere it applies.

Does Compyl help manage business associates (BAAs)?

Yes. Compyl continuously assesses and monitors every vendor that touches PHI, tracks business associate agreements, surfaces expirations early, and quantifies third-party exposure in dollars, so you stay accountable for your entire BAA network.

How does Compyl support an OCR audit or investigation?

Compyl keeps a current, organized evidence pack for every safeguard, including the risk analysis, access reviews, audit logs, training records, and BAAs, so an OCR request is answered from live proof rather than a scramble.

Is the new HIPAA Security Rule final?

No. HHS proposed the overhaul in December 2024 and moved it to its long-term agenda with a July 2027 target. The existing Security Rule, including risk analysis, remains fully enforceable, and preparing now for encryption, MFA and asset inventory expectations still reduces enforcement risk.

What is OCR’s Risk Analysis Initiative?

An enforcement push targeting failures to perform an accurate, thorough HIPAA risk analysis. By mid-2026 it had produced more than a dozen enforcement actions, many after ransomware attacks, and a missing or stale risk analysis remains OCR’s most common finding.

What healthcare privacy deadlines passed on February 16, 2026?

The compliance date for the 2024 Part 2 final rule on substance use disorder records, when OCR enforcement began, and the deadline for Notice of Privacy Practices updates that survived the June 2025 court decision vacating the reproductive health privacy rule.

What is CIRCIA and when will it apply?

The Cyber Incident Reporting for Critical Infrastructure Act will require covered entities to report substantial cyber incidents to CISA within 72 hours and ransom payments within 24 hours. CISA’s final rule has been delayed several times and was targeted for fall 2026, and reporting obligations start only once the final rule takes effect.

GRC your way

See Compyl mapped to your PHI environment

One control library, every rule, continuous evidence, and agentic AI that removes the busywork, with your experts in control.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies