Carry HIPAA weight without an enterprise budget or team.
The obligations are yours. The tooling wasn't built for you.
HIPAA does not check your headcount before it applies. The moment protected health information passes through your systems, the Security Rule's administrative, physical, and technical safeguards apply in full, the same rule a 5,000-person health plan operates under. Most of the tooling and firms built to help with HIPAA are priced, staffed, and scoped for that health plan: contracts sized for a compliance department you don't have, platforms that assume someone is hired full-time to run them, consulting engagements billed like the client is a hospital system.
If you're a health tech or healthcare company well under the enterprise tier, roughly eleven to two hundred employees, none of that fits. You don't need lighter obligations. You need the same safeguards, operated for you, at a size and a cost that make sense for where your company actually is.
“We touch PHI, and nobody here has HIPAA in their job title.”
You don't need a compliance hire. You need the safeguards operated by the people already running your identity, devices, and infrastructure, with HIPAA built into how that work gets done.
“Every enterprise customer's security review asks the same HIPAA questions, and we rebuild the answers from scratch each time.”
When the safeguards are operated and documented continuously, the answers already exist. The next questionnaire gets the same organized answer instead of a scramble.
“Every HIPAA vendor we've priced out is built for a hospital system, not a company our size.”
This page is written for the segment underneath that market: real safeguards, without the department, the headcount, or the invoice that usually comes with them.
The HIPAA safeguards we operate, and you inherit
The HIPAA Security Rule (45 CFR Part 164, Subpart C) groups your obligations into three safeguard categories. Here is what moves onto our side of the line when we operate your environment.
Administrative safeguards
45 CFR § 164.308
Risk analysis support, workforce access management, onboarding and offboarding, incident response planning, and the contingency and backup program. The paperwork that usually eats a founder's weekend, run as ongoing operations instead.
Physical safeguards
45 CFR § 164.310
Device and media controls, encryption, mobile device management, and remote wipe, operated across your fleet. Facility and data center controls stay with your cloud providers, who carry their own compliance programs for that layer.
Technical safeguards
45 CFR § 164.312
Access control with multi-factor authentication and least privilege, audit logging, integrity controls, and encryption in transit and at rest, across the systems we manage on your behalf.
Some safeguards move fully to our side: the technical controls, workforce access, and incident response planning above. Others stay genuinely shared: physical security of a data center inherits from your cloud provider's own compliance program, and decisions only your team can make, like what qualifies as a reportable incident under your Business Associate Agreements, stay yours. We draw that line explicitly instead of leaving you to assume it.
For the full family-by-family breakdown, alongside SOC 2 and ISO 27001, see the inherited controls matrix. For how we scope a HIPAA program end to end, from risk analysis through ongoing monitoring, see HIPAA compliance.
Evidence that comes from running the safeguards, not screenshotting them.
A dashboard can flag that a control drifted. It can't tell your auditor, or your biggest customer's security team, that the control was actually operated, day after day. When we run your identity, devices, and infrastructure, the proof is a by-product of that work: who had access and when, what changed and why, how an incident was actually handled, whether a backup actually restores.
That evidence does two jobs at once. It's what a HIPAA risk analysis under the Security Rule asks you to document, and it's what shows up, already organized, when a customer's due-diligence questionnaire or vendor security review lands in your inbox instead of a hospital's.
What the evidence looks like
- Access reviews and offboarding records
- Change and configuration history
- Incident response documentation
- Backup and recovery verification
- Security awareness training records
Where the evidence lives
Every safeguard we operate, documented in one place.
Policies, access reviews, incident response records, and the evidence behind them live in the platform, ready for your own HIPAA risk analysis or the next customer's security questionnaire, not scattered across email threads and spreadsheets.
See what carrying HIPAA weight actually looks like.
Read the published plan structure, or walk the whole operated partnership.
Published tiers sized for teams well below the enterprise tier, with an entry rung you can start today.
The safeguards, the evidence, and the boundary of what stays yours, laid out section by section.