Platform

Vendors & Business Associates built for HIPAA, not bolted onto it

Every vendor that touches ePHI, the BAA that governs it, and the risk review that justifies keeping them.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Every vendor that touches ePHI, the BAA that governs it, and the risk review that justifies keeping them.

What this module does

  • Vendor inventory with ePHI flag and data flow notes
  • BAA lifecycle: request, sign, store, renew, terminate
  • Subcontractor mapping for downstream business associates
  • Tiered vendor risk questionnaires with scoring
  • Annual review scheduling with automatic escalation

What it replaces

  • BAAs signed in 2019, stored in someone’s inbox, never renewed
  • No idea which vendors are actually in scope for ePHI
  • Failing a customer’s vendor review because you cannot produce a BAA in 24 hours

How it maps to the rule

Every item above is linked to a specific implementation specification in 45 CFR §164. Open any control and you see the citation, whether it is required or addressable, what you have implemented, and the evidence proving it. If a specification is addressable and you chose not to implement it, the platform makes you record the rationale — because that rationale is the thing an investigator asks for.

Included in every plan

Starter, Growth, and Enterprise all include this module. We do not price HIPAA modules separately, because a partial Security Rule implementation is not a product, it is a liability.

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

Does Vendors & Business Associates work if we are a business associate, not a covered entity?

Yes. The module ships with both scopes. Business associates get the subcontractor and downstream-BAA views turned on by default; covered entities get patient-rights workflows turned on.

Can we export everything if we leave?

Yes — policies as DOCX, evidence as a timestamped ZIP, registers as XLSX. No export fee, no lock-in clause.

Is this the same platform as LowerPlane?

It runs on the LowerPlane compliance engine. SuperHIPAA is the HIPAA-specific configuration of it, so you can add SOC 2, ISO 27001, or GDPR later without re-implementing anything.

Do you provide a BAA template?

Yes — a plain-language BAA covering the provisions §164.314 requires. Your counsel can redline it, and the executed copy lives against the vendor record with its renewal date.

What if a vendor refuses to sign a BAA?

Then they cannot handle your PHI — that is the rule, not a preference. The module flags vendors with no executed BAA so the exposure is visible instead of buried in a spreadsheet.

We are a business associate — does it track our subcontractors?

Yes. Downstream BAAs with subcontractors are tracked the same way, because under §164.314 you carry obligations for what your subcontractors do with the PHI you pass them.

How does vendor risk review actually work?

Each vendor gets a risk tier based on what PHI they touch, which drives review cadence and questionnaire depth. Renewal and review dates surface before they lapse, not after.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo