Platform

Risk Management built for HIPAA, not bolted onto it

The Security Rule requires an accurate and thorough risk analysis. This is where you do it, keep it, and prove you revisited it.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

The Security Rule requires an accurate and thorough risk analysis. This is where you do it, keep it, and prove you revisited it.

What this module does

  • Asset-and-ePHI inventory as the base of the analysis, not an afterthought
  • Threat/vulnerability pairing with likelihood × impact scoring
  • Risk register with treatment decisions, owners, and target dates
  • Vulnerability intake from your scanner or pen test, triaged into the register
  • Point-in-time snapshots so you can show what you knew and when

What it replaces

  • A risk analysis done once in 2021 and never reopened
  • A consultant’s PDF you cannot update yourself
  • No documented rationale for accepted risks — the single most common OCR finding

How it maps to the rule

Every item above is linked to a specific implementation specification in 45 CFR §164. Open any control and you see the citation, whether it is required or addressable, what you have implemented, and the evidence proving it. If a specification is addressable and you chose not to implement it, the platform makes you record the rationale — because that rationale is the thing an investigator asks for.

Included in every plan

Starter, Growth, and Enterprise all include this module. We do not price HIPAA modules separately, because a partial Security Rule implementation is not a product, it is a liability.

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

Does Risk Management work if we are a business associate, not a covered entity?

Yes. The module ships with both scopes. Business associates get the subcontractor and downstream-BAA views turned on by default; covered entities get patient-rights workflows turned on.

Can we export everything if we leave?

Yes — policies as DOCX, evidence as a timestamped ZIP, registers as XLSX. No export fee, no lock-in clause.

Is this the same platform as LowerPlane?

It runs on the LowerPlane compliance engine. SuperHIPAA is the HIPAA-specific configuration of it, so you can add SOC 2, ISO 27001, or GDPR later without re-implementing anything.

Will the output satisfy what OCR expects from a risk analysis?

It is structured around what §164.308(a)(1)(ii)(A) actually requires — asset-by-asset threats, vulnerabilities, likelihood, and impact — not a generic questionnaire. No vendor can guarantee an OCR outcome, and we will not claim to.

What methodology does the risk register use?

A NIST-aligned approach: identify where ePHI lives, enumerate threats and vulnerabilities, rate likelihood and impact, and tie each risk to a treatment decision with an owner. Nothing exotic — just done properly and kept current.

How often should the risk analysis be updated?

At least annually and after any significant change — a new system, a new vendor, an incident, or an acquisition. Because it is a living register, updates are incremental instead of a yearly rebuild.

How is this different from the free HHS SRA tool?

The SRA tool is a reasonable questionnaire for a first pass. It does not maintain a living register, assign remediation owners, track treatment over time, or link risks to evidence — which is the part that holds up later.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo