HIPAA & HITRUST compliance — protecting healthcare data with rigour and legal precision.
Healthcare data compliance is among the most demanding in any regulated sector, combining stringent technical security requirements with strict patient privacy obligations and significant enforcement risk. SIRI Law LLP's HIPAA/HITRUST practice serves Indian healthcare technology companies supplying to US customers, Indian healthcare providers processing data of international patients, and organisations seeking HITRUST certification for competitive advantage.
Getting the 2026 overhaul's status right
A major HIPAA Security Rule rewrite is genuinely coming. It has not arrived yet, and the timeline has already slipped once.
Some HIPAA compliance content describes the current Security Rule's requirements without mentioning that HHS has proposed a genuinely significant overhaul — an omission that matters because the direction of travel is now clear enough to plan around. HHS published a Notice of Proposed Rulemaking on 6 January 2025, the first major Security Rule update proposal since 2003. Its central structural change is the elimination of the "addressable versus required" distinction that has defined implementation flexibility since 2013. Under the proposal, encryption of ePHI at rest and in transit, multi-factor authentication for all systems accessing ePHI, network segmentation to limit lateral movement, and regular vulnerability scanning and penetration testing would all become flatly mandatory rather than a documented risk-based choice.
What's equally important is what hasn't happened yet. As of mid-2026, this remains a proposed rule, not final law. The comment period closed 7 March 2025 with more than 4,700 submissions, including a coalition of over 100 hospital and provider groups asking HHS to withdraw the proposal outright, largely over its estimated first-year implementation cost. OCR's original Spring 2025 Unified Agenda targeted finalisation for spring 2026; that target has already passed without a final rule, and current tracking points toward the timeline slipping further, potentially into 2027. Federal rulemaking deadlines are not legally binding, and the proposal could still be finalised roughly as written, materially revised, delayed again, or withdrawn entirely.
For Indian healthcare technology companies operating as Business Associates to US Covered Entities, this distinction is operationally important: a compliance programme built only to today's "addressable" flexibility risks a costly scramble if and when the proposal finalises, while a programme that already treats encryption, MFA, and segmentation as effectively mandatory today is simply ahead of a change that increasingly looks like a matter of when, not if.
Evidence, not guesswork
Current Security Rule vs. the proposed 2026 overhaul
What's enforced today versus what's been proposed but not finalised.
| Requirement | Current rule (in effect since 2013) | Proposed rule (not final) |
|---|---|---|
| Encryption of ePHI | Addressable — alternative or documented exception permitted | Mandatory for all ePHI at rest and in transit |
| Multi-factor authentication | Addressable | Mandatory for all remote access and privileged accounts |
| Network segmentation | Not explicit — treated as part of "reasonable and appropriate" measures | Explicit technical safeguard requirement |
| Penetration testing | Not on a defined schedule | Annual, on a defined schedule |
| Risk analysis frequency | "Periodic" — no specific frequency stated | Explicitly annual |
Sources: 45 CFR §164.306, §164.308, §164.312 (current rule); HHS Notice of Proposed Rulemaking, 90 FR 898, published 6 January 2025. The right-hand column describes a proposal only — confirm the current status of finalisation with counsel before treating any proposed requirement as a current legal obligation.
Scope of services
What our engagement covers
- HIPAA Security Rule gap assessment — all current implementation specifications
- HIPAA Privacy Rule gap assessment and advisory
- ePHI identification and data flow mapping
- Business Associate Agreement (BAA) review and negotiation
- Administrative safeguards — workforce training, access management
- Physical safeguards — facility access, workstation security
- Technical safeguards — access control, audit controls, encryption
- Risk analysis and risk management programme (§164.308)
- HIPAA Breach Risk Assessment — 4-factor test
- Breach notification procedures — HHS, individual, and media notification
- Incident response plan development — HIPAA aligned
- HITRUST CSF readiness assessment — applicable control categories
- HITRUST e1/i1/r2 certification tier selection and preparation
- HITRUST validated assessment liaison
- Medical device security assessment — FDA and MDR context
- Healthcare AI compliance — clinical decision support advisory
Choosing a certification tier
HITRUST e1, i1, and r2 — matched to your market and maturity
HITRUST CSF combines HIPAA requirements with ISO 27001, NIST, PCI DSS, and GDPR into a single assessable framework, increasingly required by US healthcare organisations from their technology vendors.
e1
A smaller set of foundational controls, typically completed in around 90 days — the fastest path to third-party validated assurance for organisations early in their compliance journey.
i1
A broader control set for organisations wanting more comprehensive assurance than e1 provides, without committing to the full rigour of r2.
r2
The full HITRUST CSF assessment — the most rigorous and credible tier, and the one most often required by large US healthcare enterprise customers during procurement.
What the numbers actually mean
Four figures that frame HIPAA/HITRUST compliance today
Per violation category — a single breach event can involve thousands of individual violations.
Tiered by culpability — from unknowing violation up to wilful neglect uncorrected.
If the 2026 overhaul finalises as written — 60 days to effective date plus 180 to mandatory compliance.
Submitted by March 2025 — the volume itself is part of why finalisation has already slipped.
Our engagement process
How we work, step by step
Initial Scoping & Assessment
Gap assessment against the applicable framework, engagement scope definition, and a prioritised remediation roadmap with timeline and effort estimates.
Programme Design
Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation — designed with the proposed 2026 direction in view.
Implementation Advisory
Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.
Internal Audit & Validation
Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.
Certification / Attestation Support
Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.
Post-Certification Advisory
Ongoing support — surveillance audit preparation, change management, and regulatory update advisory as the Security Rule proposal moves toward finalisation.
Typical engagement timeline varies by organisation size and existing control maturity.
Benefits & deliverables
What you get from this engagement
HIPAA Risk Analysis
Comprehensive risk analysis of your ePHI environment — the foundational HIPAA Security Rule requirement and the starting point for every HIPAA compliance programme.
Gap Assessment
Control-by-control gap assessment against HIPAA Security Rule implementation specifications, with prioritised remediation roadmap.
BAA Review
Review and negotiation of Business Associate Agreements with your Covered Entity customers, ensuring appropriate risk allocation and contractual protections.
Safeguards Implementation
Advisory on implementing all three categories of HIPAA safeguards — administrative, physical, and technical — with practical, proportionate guidance.
HITRUST Readiness
Gap assessment against applicable HITRUST CSF control categories and selected certification tier (e1, i1, or r2), with a realistic programme to readiness.
Breach Response
HIPAA-compliant breach response procedures, including the 4-factor breach risk assessment, notification timelines, and HHS reporting requirements.
Integration advantage
Compliance engagements backed by qualified legal counsel
Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.
We track the proposal without overclaiming its status
We tell clients exactly what's proposed, what's final, and what the realistic finalisation timeline looks like, rather than treating a still-pending NPRM as settled law or ignoring it entirely.
HIPAA alongside DPDPA, not instead of it
For Indian healthcare technology companies with both US and Indian operations, we build one integrated compliance programme rather than two disconnected ones.
Building toward where the bar is heading
We architect encryption, MFA, and segmentation controls to the direction the proposed rule signals, so clients aren't caught flat-footed if and when it finalises.
Certified engineers
Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials, the mix HITRUST assessors and US healthcare enterprise procurement teams expect.
Frequently asked
HIPAA and HITRUST, answered directly
We are an Indian company building healthcare software for US hospitals. Do we need to comply with HIPAA?
Yes — if you process Protected Health Information (PHI) of US patients on behalf of a Covered Entity (hospital, health plan, healthcare clearinghouse), you are a Business Associate under HIPAA. You are required to comply with the HIPAA Security Rule and Privacy Rule, enter into a Business Associate Agreement with your Covered Entity customers, and notify them of any breaches of unsecured PHI. HIPAA applies to the data you handle, not where your company is based.
Is the 2026 HIPAA Security Rule overhaul already in effect?
No. HHS published the Notice of Proposed Rulemaking on 6 January 2025, proposing to eliminate the current distinction between "required" and "addressable" implementation specifications and make encryption, multi-factor authentication, network segmentation, and regular penetration testing mandatory rather than flexible. As of mid-2026, this remains a proposed rule, not final law — the comment period closed in March 2025 with over 4,700 submissions, and OCR's original spring 2026 finalisation target has already slipped, with some tracking now pointing to mid-2027. The current Security Rule, unchanged since 2013, remains fully in effect and fully enforced throughout this process. We recommend budgeting and preparing for the proposed changes now, since the direction of travel is clear even though the exact timing and final text are not.
What is the difference between HITRUST e1, i1, and r2 certification?
HITRUST offers three certification tiers: e1 (essential), a smaller set of foundational controls typically completed in around 90 days; i1 (implemented), a broader control set for organisations wanting more comprehensive assurance; and r2 (risk-based), the full HITRUST CSF assessment, the most rigorous and credible tier, required by many US healthcare enterprise customers. We advise on the appropriate tier for your market requirements and compliance maturity.
What are the penalties for HIPAA non-compliance?
HIPAA penalties are tiered by culpability: Tier 1 (unknowing violation) — $100–$50,000 per violation; Tier 2 (reasonable cause) — $1,000–$50,000; Tier 3 (wilful neglect, corrected) — $10,000–$50,000; Tier 4 (wilful neglect, uncorrected) — $50,000 per violation, with an annual cap of $1.9 million per violation category. Criminal penalties also apply in egregious cases. A single breach event can involve thousands of violations.
How does HIPAA interact with India's DPDPA?
HIPAA and DPDPA both apply to health data, but HIPAA is specific to US healthcare sector entities and their business associates, while DPDPA applies broadly to any personal data of Indian data principals. Indian healthcare technology companies with both Indian and US operations may need to comply with both. We design integrated compliance programmes that satisfy both frameworks, building a single, coherent approach rather than two parallel programmes.
Should we start implementing the proposed 2026 controls now, even though they aren't final?
For most organisations processing meaningful volumes of PHI, yes, on a prioritised basis. Encryption at rest and in transit, MFA on privileged and remote access, and network segmentation are strong security practices independent of whether the proposal finalises, and implementing them now avoids a compressed 240-day scramble later. We help clients sequence this work against actual risk rather than reacting to the proposal all at once.
Ready to start your HIPAA journey?
All engagements begin with a complimentary scoping call.
Let us understand your environment and propose the right approach, including how to prepare for changes still working through the federal rulemaking process.
Related services
Other ways SIRI Law LLP supports your compliance posture
Privacy compliance — DPDPA/GDPR/CCPA
Integrated multi-jurisdiction privacy programme, including India's DPDPA.
Healthcare technology law
CDSCO SaMD classification and regulatory advisory for connected medical devices.
Cybersecurity GRC & compliance
All nine frameworks we cover, under one privileged engagement.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

