← back to overview
HIPAA · regulation pack · preview

Health Insurance Portability and Accountability Act

HIPAA Privacy, Security, and Breach Notification Rules governing protected health information (PHI). Strategy Builder supports HIPAA BAA-capable ops from day 1.

jurisdiction · US version · 2013.01 effective · Sept. 23, 2013 requirements · 5
requirements — preview
164.308 · Clause high-risk gate

Administrative safeguards

Security management process, workforce security, contingency plan.

artifact: ai_policyartifact: ai_committee_charter evidence: incident_runbookevidence: access_review
164.310 · Clause

Physical safeguards

Facility access, workstation use, device controls.

evidence: facility_access_policy
164.312 · Clause high-risk gate

Technical safeguards

Access control, audit controls, integrity, transmission security.

evidence: llm_logsevidence: sso_mfa_evidenceevidence: encryption_audit
remaining 2 requirements — locked
164.314 · Clause

Business associate contracts

All BAs must have executed BAAs before PHI is shared.

164.402 · Clause

Breach notification

Breach notification within 60 days of discovery.

Unlock the full HIPAA pack

Get all 2 remaining requirements, generated reports, evidence-mapping templates, and the audit-chain export. Cancel anytime.

Unlock the pack → or full platform

Not ready to buy? Run the free EU AI Act gap report.

12-question intake mapped to Articles 9-15. Branded PDF in your inbox in minutes. No card required.

Free gap report →