Software category

HIPAA compliance software

HIPAA compliance software is the system of record for what 45 CFR Part 164 requires of a covered entity or a business associate: the Security Rule's administrative, physical and technical safeguards, the Breach Notification Rule, and the Privacy Rule provisions that impose a duty. It holds the policies, the risk analysis, the workforce training records and the evidence that each safeguard is operating, so a BAA request or an investigation is answered from a system rather than from a folder.

A software company that handles protected health information for a customer is a business associate, and for many the trigger is a BAA request sitting in a deal. There is nothing to be certified against, so what the counterparty actually wants is the safeguards written down, assigned to someone, and evidenced. Healthcare providers and practices need the same artifacts, with more of the Privacy Rule in play.

Differentiators

Why teams choose Keel for this

  • Part 164 to leaf level, with the scope published

    Keel models 45 CFR Part 164 to leaf level, 100+ scored requirements across the Security Rule, the Breach Notification Rule and the Privacy Rule's duty-imposing provisions. Which Privacy Rule sections are scored, and which are deliberately not, is published on the framework's scope page before you buy.

  • The SOC 2 and ISO 27001 overlap is reused

    Keel crosswalks controls across HIPAA, SOC 2 and ISO 27001, so a safeguard you already evidence counts against each framework it satisfies instead of being collected three times. The control-to-requirement dataset is published as open data, so you can check a mapping before you build a program on it.

  • HIPAA policy templates, not generic ones

    The library ships HIPAA-specific policies alongside the general security set: business associate management, breach risk assessment and notification, the contingency plan, individual rights and the notice of privacy practices, and workforce security and information access management. Each one is authored in plain English with placeholders you fill in.

  • Risk analysis, training and vendors in the same workspace

    The risk register carries the analysis with owners and treatments, security training records who has completed what, and the vendor register ranks each third party by criticality with a review cadence. Those are the artifacts most often missing when a BAA request arrives.

  • Published price, self-serve start

    HIPAA takes one of the paid frameworks a plan includes: 3 paid frameworks on Starter ($99/mo), 5 paid frameworks on Pro ($299/mo). A Free workspace can buy it as a framework add-on. Pro is free for 14 days with no credit card. No sales call to see the number or to open a workspace.

Best for

Health-tech and SaaS companies handling PHI as a business associate, and small providers or practices that need the safeguards documented and evidenced without hiring a consultant.

Not the right fit if

Anyone looking for a HIPAA certificate or legal advice. Nobody certifies HIPAA compliance, and Keel runs the program rather than advising on it. Clinical, billing and coding compliance are outside it.

Common questions

Is there such a thing as HIPAA certification?

No. There is no certifying body for HIPAA and no vendor can confer compliance on you. What you can do is document the safeguards, keep the risk analysis current, train the workforce, and hold evidence that all of it operates. That is what a BAA counterparty asks for, and what an investigation would look at.

We are a business associate, not a covered entity. Does that change what we need?

The Security Rule binds a business associate directly, and so does §164.410, which requires you to notify the covered entity of a breach. Some Privacy Rule provisions also apply to you directly, such as limiting uses and disclosures to what the BAA permits and the minimum necessary standard, and the BAA passes down further obligations on top.

Can we reuse our SOC 2 or ISO 27001 work?

A large share of the technical and administrative work overlaps, and Keel proposes your existing controls against the HIPAA requirements they already satisfy. The overlap is not total: most of the Breach Notification Rule and the Privacy Rule duties have no counterpart in a Security-only SOC 2 report, and those show up as the work that is genuinely new.

Does it handle the HIPAA risk analysis?

The risk register is where the analysis lives: each risk scored on likelihood and impact, with an owner, a treatment, and links to the controls that reduce it. AI can draft a first set of candidate risks from your context, and you keep the ones that apply. A person still makes every risk decision.

What does it cost?

HIPAA takes one of the paid frameworks a plan includes: 3 paid frameworks on Starter ($99/mo), 5 paid frameworks on Pro ($299/mo). A Free workspace can buy it as a framework add-on. Pro is free for 14 days with no credit card. The published plans are on the pricing page, and there is no implementation fee.

Try it on your own program

Start free, apply a framework, and see how much of the work AI can draft for you. No credit card.