If your business creates, receives, stores, or transmits patient health information, one thing is true no matter what industry framework you’re also working toward: HIPAA compliance isn’t optional. But HIPAA itself doesn’t hand you a checklist. This guide breaks down what HIPAA actually requires, the NIST guide built specifically to help you implement it, and the certification most healthcare partners actually ask to see.
HIPAA is a law, not a control standard
The Health Insurance Portability and Accountability Act is a federal law, not a security framework you can be “certified” against. It applies to covered entities — healthcare providers, health plans, and healthcare clearinghouses — and their business associates, the vendors and contractors those covered entities rely on. It’s enforced by the HHS Office for Civil Rights, and violations carry real financial and legal consequences.
HIPAA’s Privacy Rule and Security Rule require organizations to protect patient data and give individuals certain rights over their own health information. But the law is deliberately written around outcomes rather than specific technical controls: it says safeguards must be “reasonable and appropriate,” without listing exactly which tools, settings, or procedures satisfy that bar. That’s useful for flexibility, but it leaves a real question for any business owner: reasonable and appropriate, according to whom?
NIST SP 800-66: the implementation roadmap
NIST Special Publication 800-66 is the answer to that question. Now in its second revision — published in February 2024 and developed jointly with HHS — it’s NIST’s official cybersecurity resource guide for implementing the HIPAA Security Rule. Rather than leaving “reasonable and appropriate” open to interpretation, 800-66 walks through each Security Rule standard and maps it to concrete safeguards, including direct mappings to NIST SP 800-53 controls and the NIST Cybersecurity Framework.
In practice, this is what a business actually builds toward when it says it’s “HIPAA compliant.” It’s not a certification and nobody audits you against it directly — but it’s the closest thing to a technical checklist behind the law, and it’s what a knowledgeable IT or security partner should be building your safeguards around.
HITRUST CSF: the certification that proves it
HIPAA is a legal requirement, and NIST SP 800-66 is how you meet it — but neither gives you something to hand a partner, payer, or customer as proof. That’s where HITRUST CSF comes in. It’s a certifiable framework that pulls from more than 50 authoritative sources — including HIPAA, ISO/IEC 27001, and NIST — into a single, harmonized control set.
Instead of separately proving compliance with HIPAA, ISO, and whatever else a given partner asks for, a business completes one HITRUST assessment and gets a certification that stands in for all of them. There are three tiers, matched to risk and assurance level:
| Certification | Best for | Scope | Validity |
|---|---|---|---|
| e1 (Essentials) | Lower-risk organizations wanting baseline cyber hygiene proof | 44 foundational controls | 1 year |
| i1 (Implemented) | Organizations needing moderate assurance | 219 controls | 1 year |
| r2 (Risk-based) | Organizations facing the highest scrutiny — typically health systems, payers, and their larger vendors | Comprehensive, risk-tailored control set | 2 years, with a year-one interim check |
It’s become the certification health systems and insurers most often require from their vendors, precisely because it saves everyone from re-proving the same underlying controls five different ways for five different partners.
How the three fit together
Put simply: HIPAA is the law that says you must protect patient data. NIST SP 800-66 is the roadmap for what “protecting it” actually looks like in practice. HITRUST CSF is how you prove it — formally and repeatably — to a partner who asks. A healthcare business doesn’t get to pick just one; the law applies regardless, 800-66 is the sensible way to build toward it, and HITRUST becomes relevant the moment a partner, payer, or contract requires documented proof rather than your word for it.
How BCS helps Austin healthcare businesses navigate HIPAA
Business Communication Solutions works with healthcare providers, clinics, and their vendors across Austin and the surrounding area to build IT environments that hold up to HIPAA’s Security Rule — using NIST SP 800-66 as the practical blueprint, and preparing for HITRUST when a partner or payer requires it. For related reading, see our guide to cybersecurity control standards (NIST SP 800-53, ISO/IEC 27001, and CMMC) if you’re weighing multiple compliance requirements at once.
Not sure where your practice or business stands on HIPAA?
Get a straightforward review of your current safeguards against the HIPAA Security Rule — not a generic checklist. Contact BCS to schedule a conversation.