Platform

Privacy built for HIPAA, not bolted onto it

Privacy Rule operations: minimum necessary, patient rights, notices, disclosure accounting, and breach determination.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Privacy Rule operations: minimum necessary, patient rights, notices, disclosure accounting, and breach determination.

What this module does

  • Notice of Privacy Practices manager with version and posting evidence
  • Patient rights workflow — access, amendment, restriction, accounting of disclosures
  • Disclosure log with purpose and minimum-necessary justification
  • Breach risk assessment wizard following the four-factor test
  • Breach notification clock with 60-day and annual HHS reporting tracks

What it replaces

  • Patient access requests handled over email with no 30-day clock
  • No accounting of disclosures when a patient finally asks
  • Guessing whether an incident is a reportable breach

How it maps to the rule

Every item above is linked to a specific implementation specification in 45 CFR §164. Open any control and you see the citation, whether it is required or addressable, what you have implemented, and the evidence proving it. If a specification is addressable and you chose not to implement it, the platform makes you record the rationale — because that rationale is the thing an investigator asks for.

Included in every plan

Starter, Growth, and Enterprise all include this module. We do not price HIPAA modules separately, because a partial Security Rule implementation is not a product, it is a liability.

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

Does Privacy work if we are a business associate, not a covered entity?

Yes. The module ships with both scopes. Business associates get the subcontractor and downstream-BAA views turned on by default; covered entities get patient-rights workflows turned on.

Can we export everything if we leave?

Yes — policies as DOCX, evidence as a timestamped ZIP, registers as XLSX. No export fee, no lock-in clause.

Is this the same platform as LowerPlane?

It runs on the LowerPlane compliance engine. SuperHIPAA is the HIPAA-specific configuration of it, so you can add SOC 2, ISO 27001, or GDPR later without re-implementing anything.

Does it track patient right-of-access requests?

Yes. Each request gets a deadline clock, an owner, and a logged outcome, so the 30-day window under §164.524 never slips because a request sat in someone's inbox.

Can it manage our Notice of Privacy Practices?

Yes — versioned like any policy, with a record of when each version went live. When the notice changes, the update trail is already there.

Does it handle accounting of disclosures?

Yes. A running disclosure log per patient covers the accounting requirement, so answering a request is an export rather than a records archaeology project.

What about state privacy laws that are stricter than HIPAA?

HIPAA is a floor, not a ceiling. You can layer stricter state requirements onto the same workflows, but we will not pretend one checklist covers every state — where it matters, involve counsel.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo