Skip to content

Compliance matrix

Health Insurance Portability and Accountability Act (Security Rule)

United States · Updated 2026-07-19

Applies to: Covered entities and their business associates that handle electronic protected health information (ePHI).

Vendor certification snapshot

HIPAA (BAA available) status across the 48 vendors we track, read live from each profile.

27

Certified

3

Partial

18

Not stated

Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.

Requirements mapped to CIAM

Access control (§164.312(a))

Only authorized users may reach ePHI, enforced with unique IDs, automatic logoff, and encryption.

CIAM controls

  • Unique user identification, no shared accounts
  • Automatic session logoff / timeout
  • Role-based, minimum-necessary access
  • Encryption of ePHI

Evidence

  • Role-to-permission mappings
  • Session timeout configuration

Ask the vendor

  • Can we enforce unique IDs, automatic logoff, and minimum-necessary RBAC?

Person or entity authentication (§164.312(d))

You must verify that a person seeking access is who they claim to be.

CIAM controls

  • MFA for access to ePHI
  • Phishing-resistant authentication for privileged access

Evidence

  • MFA enforcement policy
  • Authentication logs

Ask the vendor

  • Is MFA enforceable for all users with access to ePHI?

Audit controls (§164.312(b))

Activity involving ePHI, including access and authentication, must be recorded and examinable.

CIAM controls

  • Immutable audit logs of access and auth events
  • Log retention aligned to policy

Evidence

  • Audit log samples
  • Retention configuration

Ask the vendor

  • What access and authentication events are logged, and how long are they retained?

Business Associate Agreement

A vendor processing ePHI on your behalf is a business associate and must sign a BAA.

CIAM controls

  • Executed BAA before ePHI is processed

Evidence

  • Signed BAA

Ask the vendor

  • Will you sign a BAA, and on which plans is it available?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

Does HIPAA require MFA?
The Security Rule requires 'person or entity authentication' without naming MFA, but it is treated as an addressable-to-baseline control for ePHI access, and proposed updates push toward mandatory MFA. In practice, enforce MFA for anyone who can reach ePHI.
Is a HIPAA-compliant CIAM vendor enough?
No single product makes you HIPAA compliant. You need a signed BAA plus correctly configured access controls, authentication, audit logging, and session controls in your tenant. The vendor enables compliance; your configuration achieves it.

Source

45 CFR §164.312 (HIPAA Security Rule technical safeguards)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.