Healthcare
Available nowHIPAA · Security, Breach & Privacy
HIPAA governs how covered entities and business associates protect Protected Health Information (PHI). Its Security Rule safeguards are what most technology vendors need to demonstrate.
92
requirements tracked
Core plans
Access
Add-on from $29/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below — all 92 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 92 requirements
- In Keel’s scored scope
- 92 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs HIPAA?
- Health-tech companies and any business associate handling PHI
- Vendors asked to sign a Business Associate Agreement (BAA)
- Teams needing administrative, physical, and technical safeguards in place
What Keel does
How Keel helps with HIPAA
- The HIPAA Security Rule safeguards as a control set you can implement and evidence
- Crosswalk to SOC 2 and ISO 27001 so overlapping controls count once
- Readiness tracking so you can answer a BAA request with confidence
Collect once, comply everywhere
HIPAA shares canonical controls with ISO/IEC 27001, NIST SP 800-53 and SOC 2 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding HIPAA rarely means starting from scratch.
Shares canonical controls with
- ISO/IEC 27001
- CIS Critical Security Controls
- PCI DSS
- SOC 2
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
Features that help with HIPAA: Policy management · Controls & crosswalk · Security awareness training
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks