📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
HIPAA & HITRUST Compliance in India | SIRI Law LLP
HIPAA · HITRUST · Healthcare Data Security · Hyderabad, India

HIPAA & HITRUST compliance — protecting healthcare data with rigour and legal precision.

Healthcare data compliance is among the most demanding in any regulated sector, combining stringent technical security requirements with strict patient privacy obligations and significant enforcement risk. SIRI Law LLP's HIPAA/HITRUST practice serves Indian healthcare technology companies supplying to US customers, Indian healthcare providers processing data of international patients, and organisations seeking HITRUST certification for competitive advantage.

Proposed2026 Security Rule overhaul — NPRM published Jan 2025, still not final law
4,700+Public comments under OCR review — finalisation timeline has already slipped
$1.9MAnnual penalty cap per violation category, current tiered structure
3HITRUST certification tiers — e1, i1, r2 — matched to your compliance maturity
The HIPAA Security Rule clock
Live tracking · scroll to see every relevant date
Standing
2013
Current HIPAA Security Rule last substantively updated — the "addressable vs. required" distinction has stood unchanged since.
Proposed
6 JAN 2025
HHS publishes the Security Rule NPRM — the first major overhaul proposal since 2003, eliminating "addressable" flexibility entirely.
Closed
7 MAR 2025
Public comment period closes with over 4,700 submissions — a coalition of 100+ hospital and provider groups asks HHS to withdraw the proposal.
Slipped
Spring 2026 →
OCR's original finalisation target passes without a final rule — OMB's Unified Agenda now points toward mid-2027, not legally binding and subject to further change.
Still pending
Mid-2026
The 2026 Security Rule overhaul remains a proposed rule, not final law — the current 2013 Rule remains fully in effect and fully enforced.
If finalised
240 days
Compliance window once any final rule publishes — 60 days to effective date, plus 180 days to mandatory compliance, per the proposal as written.

Getting the 2026 overhaul's status right

A major HIPAA Security Rule rewrite is genuinely coming. It has not arrived yet, and the timeline has already slipped once.

Some HIPAA compliance content describes the current Security Rule's requirements without mentioning that HHS has proposed a genuinely significant overhaul — an omission that matters because the direction of travel is now clear enough to plan around. HHS published a Notice of Proposed Rulemaking on 6 January 2025, the first major Security Rule update proposal since 2003. Its central structural change is the elimination of the "addressable versus required" distinction that has defined implementation flexibility since 2013. Under the proposal, encryption of ePHI at rest and in transit, multi-factor authentication for all systems accessing ePHI, network segmentation to limit lateral movement, and regular vulnerability scanning and penetration testing would all become flatly mandatory rather than a documented risk-based choice.

What's equally important is what hasn't happened yet. As of mid-2026, this remains a proposed rule, not final law. The comment period closed 7 March 2025 with more than 4,700 submissions, including a coalition of over 100 hospital and provider groups asking HHS to withdraw the proposal outright, largely over its estimated first-year implementation cost. OCR's original Spring 2025 Unified Agenda targeted finalisation for spring 2026; that target has already passed without a final rule, and current tracking points toward the timeline slipping further, potentially into 2027. Federal rulemaking deadlines are not legally binding, and the proposal could still be finalised roughly as written, materially revised, delayed again, or withdrawn entirely.

The current rule is still the enforced rule
Throughout this entire process, the current 2013 Security Rule remains in full effect and fully enforced by OCR. Nothing about the proposal changes an organisation's compliance obligations today. The practical guidance is neither "ignore it" nor "panic" — it's to treat the direction of the proposed changes (mandatory MFA, mandatory encryption, mandatory segmentation, scheduled testing) as a credible signal of where the bar is heading, and begin budgeting and architecture planning now, while continuing to comply with the actual rule currently in force.

For Indian healthcare technology companies operating as Business Associates to US Covered Entities, this distinction is operationally important: a compliance programme built only to today's "addressable" flexibility risks a costly scramble if and when the proposal finalises, while a programme that already treats encryption, MFA, and segmentation as effectively mandatory today is simply ahead of a change that increasingly looks like a matter of when, not if.

Evidence, not guesswork

Current Security Rule vs. the proposed 2026 overhaul

What's enforced today versus what's been proposed but not finalised.

Requirement Current rule (in effect since 2013) Proposed rule (not final)
Encryption of ePHI Addressable — alternative or documented exception permitted Mandatory for all ePHI at rest and in transit
Multi-factor authentication Addressable Mandatory for all remote access and privileged accounts
Network segmentation Not explicit — treated as part of "reasonable and appropriate" measures Explicit technical safeguard requirement
Penetration testing Not on a defined schedule Annual, on a defined schedule
Risk analysis frequency "Periodic" — no specific frequency stated Explicitly annual

Sources: 45 CFR §164.306, §164.308, §164.312 (current rule); HHS Notice of Proposed Rulemaking, 90 FR 898, published 6 January 2025. The right-hand column describes a proposal only — confirm the current status of finalisation with counsel before treating any proposed requirement as a current legal obligation.

Scope of services

What our engagement covers

  • HIPAA Security Rule gap assessment — all current implementation specifications
  • HIPAA Privacy Rule gap assessment and advisory
  • ePHI identification and data flow mapping
  • Business Associate Agreement (BAA) review and negotiation
  • Administrative safeguards — workforce training, access management
  • Physical safeguards — facility access, workstation security
  • Technical safeguards — access control, audit controls, encryption
  • Risk analysis and risk management programme (§164.308)
  • HIPAA Breach Risk Assessment — 4-factor test
  • Breach notification procedures — HHS, individual, and media notification
  • Incident response plan development — HIPAA aligned
  • HITRUST CSF readiness assessment — applicable control categories
  • HITRUST e1/i1/r2 certification tier selection and preparation
  • HITRUST validated assessment liaison
  • Medical device security assessment — FDA and MDR context
  • Healthcare AI compliance — clinical decision support advisory

Choosing a certification tier

HITRUST e1, i1, and r2 — matched to your market and maturity

HITRUST CSF combines HIPAA requirements with ISO 27001, NIST, PCI DSS, and GDPR into a single assessable framework, increasingly required by US healthcare organisations from their technology vendors.

Essential

e1

A smaller set of foundational controls, typically completed in around 90 days — the fastest path to third-party validated assurance for organisations early in their compliance journey.

Implemented

i1

A broader control set for organisations wanting more comprehensive assurance than e1 provides, without committing to the full rigour of r2.

Risk-based

r2

The full HITRUST CSF assessment — the most rigorous and credible tier, and the one most often required by large US healthcare enterprise customers during procurement.

What the numbers actually mean

Four figures that frame HIPAA/HITRUST compliance today

$1.9M
Annual penalty cap

Per violation category — a single breach event can involve thousands of individual violations.

$100–$50K
Per-violation range

Tiered by culpability — from unknowing violation up to wilful neglect uncorrected.

240 days
Proposed compliance window

If the 2026 overhaul finalises as written — 60 days to effective date plus 180 to mandatory compliance.

4,700+
Comments under OCR review

Submitted by March 2025 — the volume itself is part of why finalisation has already slipped.

Our engagement process

How we work, step by step

01

Initial Scoping & Assessment

Gap assessment against the applicable framework, engagement scope definition, and a prioritised remediation roadmap with timeline and effort estimates.

02

Programme Design

Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation — designed with the proposed 2026 direction in view.

03

Implementation Advisory

Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.

04

Internal Audit & Validation

Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.

05

Certification / Attestation Support

Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.

06

Post-Certification Advisory

Ongoing support — surveillance audit preparation, change management, and regulatory update advisory as the Security Rule proposal moves toward finalisation.

Typical engagement timeline varies by organisation size and existing control maturity.

Benefits & deliverables

What you get from this engagement

HIPAA Risk Analysis

Comprehensive risk analysis of your ePHI environment — the foundational HIPAA Security Rule requirement and the starting point for every HIPAA compliance programme.

Gap Assessment

Control-by-control gap assessment against HIPAA Security Rule implementation specifications, with prioritised remediation roadmap.

BAA Review

Review and negotiation of Business Associate Agreements with your Covered Entity customers, ensuring appropriate risk allocation and contractual protections.

Safeguards Implementation

Advisory on implementing all three categories of HIPAA safeguards — administrative, physical, and technical — with practical, proportionate guidance.

HITRUST Readiness

Gap assessment against applicable HITRUST CSF control categories and selected certification tier (e1, i1, or r2), with a realistic programme to readiness.

Breach Response

HIPAA-compliant breach response procedures, including the 4-factor breach risk assessment, notification timelines, and HHS reporting requirements.

Integration advantage

Compliance engagements backed by qualified legal counsel

Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.

01 — Precision

We track the proposal without overclaiming its status

We tell clients exactly what's proposed, what's final, and what the realistic finalisation timeline looks like, rather than treating a still-pending NPRM as settled law or ignoring it entirely.

02 — Dual compliance

HIPAA alongside DPDPA, not instead of it

For Indian healthcare technology companies with both US and Indian operations, we build one integrated compliance programme rather than two disconnected ones.

03 — Forward planning

Building toward where the bar is heading

We architect encryption, MFA, and segmentation controls to the direction the proposed rule signals, so clients aren't caught flat-footed if and when it finalises.

04 — Credentials

Certified engineers

Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials, the mix HITRUST assessors and US healthcare enterprise procurement teams expect.

Frequently asked

HIPAA and HITRUST, answered directly

We are an Indian company building healthcare software for US hospitals. Do we need to comply with HIPAA?

Yes — if you process Protected Health Information (PHI) of US patients on behalf of a Covered Entity (hospital, health plan, healthcare clearinghouse), you are a Business Associate under HIPAA. You are required to comply with the HIPAA Security Rule and Privacy Rule, enter into a Business Associate Agreement with your Covered Entity customers, and notify them of any breaches of unsecured PHI. HIPAA applies to the data you handle, not where your company is based.

Is the 2026 HIPAA Security Rule overhaul already in effect?

No. HHS published the Notice of Proposed Rulemaking on 6 January 2025, proposing to eliminate the current distinction between "required" and "addressable" implementation specifications and make encryption, multi-factor authentication, network segmentation, and regular penetration testing mandatory rather than flexible. As of mid-2026, this remains a proposed rule, not final law — the comment period closed in March 2025 with over 4,700 submissions, and OCR's original spring 2026 finalisation target has already slipped, with some tracking now pointing to mid-2027. The current Security Rule, unchanged since 2013, remains fully in effect and fully enforced throughout this process. We recommend budgeting and preparing for the proposed changes now, since the direction of travel is clear even though the exact timing and final text are not.

What is the difference between HITRUST e1, i1, and r2 certification?

HITRUST offers three certification tiers: e1 (essential), a smaller set of foundational controls typically completed in around 90 days; i1 (implemented), a broader control set for organisations wanting more comprehensive assurance; and r2 (risk-based), the full HITRUST CSF assessment, the most rigorous and credible tier, required by many US healthcare enterprise customers. We advise on the appropriate tier for your market requirements and compliance maturity.

What are the penalties for HIPAA non-compliance?

HIPAA penalties are tiered by culpability: Tier 1 (unknowing violation) — $100–$50,000 per violation; Tier 2 (reasonable cause) — $1,000–$50,000; Tier 3 (wilful neglect, corrected) — $10,000–$50,000; Tier 4 (wilful neglect, uncorrected) — $50,000 per violation, with an annual cap of $1.9 million per violation category. Criminal penalties also apply in egregious cases. A single breach event can involve thousands of violations.

How does HIPAA interact with India's DPDPA?

HIPAA and DPDPA both apply to health data, but HIPAA is specific to US healthcare sector entities and their business associates, while DPDPA applies broadly to any personal data of Indian data principals. Indian healthcare technology companies with both Indian and US operations may need to comply with both. We design integrated compliance programmes that satisfy both frameworks, building a single, coherent approach rather than two parallel programmes.

Should we start implementing the proposed 2026 controls now, even though they aren't final?

For most organisations processing meaningful volumes of PHI, yes, on a prioritised basis. Encryption at rest and in transit, MFA on privileged and remote access, and network segmentation are strong security practices independent of whether the proposal finalises, and implementing them now avoids a compressed 240-day scramble later. We help clients sequence this work against actual risk rather than reacting to the proposal all at once.

Ready to start your HIPAA journey?

All engagements begin with a complimentary scoping call.

Let us understand your environment and propose the right approach, including how to prepare for changes still working through the federal rulemaking process.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes only. Compliance requirements vary by organisation, sector, and jurisdiction. References to the proposed 2026 HIPAA Security Rule overhaul reflect the status of a pending federal rulemaking as of publication and remain subject to change, including further delay, material revision, or withdrawal; confirm the current status directly with HHS/OCR publications before relying on any specific proposed requirement as a compliance obligation. Engagement with SIRI Law LLP requires a formal retainer. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top