Healthcare
Available nowHIPAA · Security, Breach & Privacy
HIPAA governs how covered entities and business associates protect Protected Health Information (PHI). Keel models 45 CFR Part 164 to leaf level: the Security Rule’s general rules and its administrative, physical and technical safeguards with every required and addressable implementation specification, the Breach Notification Rule, and the Privacy Rule’s duty-imposing provisions (§164.502, §164.504, §164.514, §164.520, §164.522, §164.524, §164.526, §164.528 and §164.530). A Privacy Rule paragraph is scored where it imposes a duty, or states a prohibition, that binds without the organization first electing to perform an optional act. So the minimum necessary standard, the business associate and group health plan contract requirements, the duty to verify identity and authority before disclosing, and the prohibitions on selling PHI, on genetic-information underwriting and on using PHI to investigate reproductive health care are all scored. What is not scored is said out loud rather than left to be discovered: the use-and-disclosure regimes at §164.506, §164.508, §164.509, §164.510 and §164.512, and the de-identification, limited data set and fundraising provisions at §164.502(d) and §164.514(b), (c), (e), (f) and (g), each govern an act an organization elects to perform rather than a duty that binds whether or not it ever does. The verb is not the test: §164.520(d) reads “may” and is scored, because it sets the terms of a notice duty the entity already holds. The Security Rule safeguards are the part most technology vendors are asked to demonstrate.
126
requirements tracked
Core plans
Access
Add-on from $29/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below, all 126 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 126 requirements
- In Keel’s scored scope
- 126 leaf requirements
What Keel scores here, and what it does not
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs HIPAA?
- Health-tech companies and any business associate handling PHI
- Vendors asked to sign a Business Associate Agreement (BAA)
- Teams needing administrative, physical, and technical safeguards in place
What Keel does
How Keel helps with HIPAA
- The Security Rule’s general rules and its administrative, physical and technical safeguards, every required and addressable implementation specification, as controls you implement and evidence
- The Breach Notification Rule and the Privacy Rule’s duty-imposing provisions (individual rights, the minimum necessary standard, business associate and group health plan contracts, and verification before disclosure) scored alongside them, rather than left out
- Crosswalk to SOC 2 and ISO 27001 so overlapping controls count once
- Readiness tracking so you can answer a BAA request with confidence
Collect once, comply everywhere
HIPAA shares canonical controls with FedRAMP Rev5 Class C, FedRAMP Rev5 Class D and ISO/IEC 27001 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding HIPAA rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls shares canonical controls
- PCI DSS shares canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- FedRAMP Consolidated Rules shares canonical controls
- NIST SP 800-171 shares canonical controls
- GDPR shares canonical controls
- COPPA shares canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- PIPEDA shares canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials no shared canonical controls
- ISO/IEC 42001 shares canonical controls
- NIST AI Risk Management Framework no shared canonical controls
- EU AI Act no shared canonical controls
- ESG Essentials shares canonical controls
- US Employment Law - Federal Baseline shares canonical controls
A framework is lit when at least one canonical control satisfies both HIPAA and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 20 of 26 are lit here.
Features that help with HIPAA: Policy management · Controls & crosswalk · Security awareness training
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks