Solution

HIPAA compliance for enterprise

Multiple legal entities, tens of thousands of workforce members, and auditors who want evidence lineage, not screenshots.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Multiple legal entities, tens of thousands of workforce members, and auditors who want evidence lineage, not screenshots.

What you get

  • Multi-entity hierarchy with delegated administration and scoped roles
  • SSO, SCIM, and HRIS synchronisation
  • Evidence lineage and immutable audit trail
  • Control mapping across HIPAA, SOC 2, ISO 27001, and HITRUST from one control set

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

How do you handle multiple legal entities and hybrid entity designations?

Each entity gets its own risk register, BAA records, and evidence, under one workspace with delegated administration. If you have made a hybrid entity designation, the covered components are scoped explicitly so corporate functions outside the healthcare component are not dragged into every control.

What does OCR actually ask a large organisation in an investigation?

The first requests are predictable: the enterprise-wide risk analysis, the asset inventory behind it, and proof both cover every facility and system — not just the flagship EHR. Enforcement actions against large systems repeatedly cite risk analyses that skipped whole business units.

We are being asked for HITRUST by payers. Does this help?

The control set maps across HIPAA, SOC 2, ISO 27001, and HITRUST, so the implementation and evidence work reuses rather than restarting. HITRUST certification itself runs through their assessor ecosystem — we get you to the point where that engagement is an assessment, not a remediation project.

How do we migrate off our current GRC platform without losing history?

Migration is free and we do the mapping work — controls, evidence history, risk register, and vendor records carried across with lineage preserved. The six-year documentation retention requirement is exactly why we do not treat your history as disposable.

How does workforce training work at tens of thousands of employees?

HRIS-synced assignment, role-based modules, and automated chase on non-completion — annual cadence plus onboarding and material-change triggers. The metric that matters in an investigation is completion coverage with acknowledgements, and that is reportable per entity at any moment.

Does published pricing really extend to enterprise contracts?

Yes — pricing is published, and the 3-year price lock applies at enterprise scale too, which your procurement team can hold us to. Custom scoping affects services work, not the honesty of the platform price.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo