Administrative, physical, and technical safeguards — each one mapped to a control, an owner, and live evidence.
What this module does
- Asset inventory covering every system that creates, receives, maintains, or transmits ePHI
- Access review campaigns with attestation records
- Encryption posture: at rest, in transit, and on endpoints
- Backup and contingency plan testing with recorded results
- MFA coverage reporting and audit log retention checks
What it replaces
- Assuming your cloud provider’s compliance covers your obligations
- Access reviews that exist as a calendar invite and nothing else
- Backups that have never been restore-tested
How it maps to the rule
Every item above is linked to a specific implementation specification in 45 CFR §164. Open any control and you see the citation, whether it is required or addressable, what you have implemented, and the evidence proving it. If a specification is addressable and you chose not to implement it, the platform makes you record the rationale — because that rationale is the thing an investigator asks for.
Included in every plan
Starter, Growth, and Enterprise all include this module. We do not price HIPAA modules separately, because a partial Security Rule implementation is not a product, it is a liability.
What happens after you fill the form
- You get the deliverable immediately. No “a rep will contact you to unlock your download.”
- We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
- You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.
On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.