Compliance Scanning

HIPAA Security Rule
Compliance Scanning

Healthcare providers and business associates must implement HIPAA Security Rule technical safeguards to protect electronic Protected Health Information (ePHI). ComplianceLayer maps external scan findings to the specific 45 CFR 164.312 controls.

Control Mapping

HIPAA Technical Safeguards Mapped to Scan Modules

Each control reference follows 45 CFR Part 164 Subpart C — the HIPAA Security Rule technical safeguard requirements.

Control IDSafeguardScan ModuleWhat We Check
164.312(a)(1)Access ControlOpen PortsImplement technical policies to allow access only to authorized persons. Detects exposed RDP, SSH, database ports, and SMB services.
164.312(d)Person or Entity AuthenticationOpen PortsVerify identity of persons seeking access to ePHI. Identifies exposed authentication endpoints (RDP, database ports).
164.312(e)(1)Transmission SecuritySSL/TLS / EmailProtect ePHI transmitted over electronic networks. Validates TLS configuration, HSTS enforcement, SPF, DKIM, and DMARC.
164.312(e)(2)(ii)EncryptionSSL/TLSImplement encryption mechanism for ePHI in transit. Checks TLS versions, cipher strength, certificate validity, and HTTPS enforcement.
164.312(c)(1)IntegritySecurity HeadersProtect ePHI from improper alteration or destruction. Validates Content-Security-Policy and integrity checking mechanisms.
164.308(a)(1)(ii)(A)Risk AnalysisAll ModulesConduct accurate and thorough assessment of risks to ePHI. ComplianceLayer scans 16 modules covering the external attack surface.
164.308(a)(1)(ii)(B)Risk ManagementAll ModulesImplement security measures to reduce risks to a reasonable level. Identifies expired certificates, vulnerable configurations, and exposures.
164.308(a)(5)(ii)(B)Protection from Malicious SoftwareEmail / HeadersGuard against malicious software. Checks DMARC anti-phishing protection and Content-Security-Policy for script injection prevention.

HIPAA applies to covered entities and business associates handling PHI. These are HIPAA Security Rule-relevant technical controls. Full compliance requires organizational safeguards beyond technical scanning.

How It Works

HIPAA Compliance Evidence in 3 Steps

01

Enter your domain

Submit any domain handling ePHI. ComplianceLayer scans the external attack surface across 16 security modules.

02

Review HIPAA mapping

Each finding maps to specific 45 CFR 164.312 technical safeguard requirements with pass, fail, or partial status.

03

Export for auditors

Download the compliance report as evidence for HIPAA risk assessments, auditor reviews, or BAA documentation.

FAQ

Common questions

Does ComplianceLayer make us HIPAA compliant?

No. HIPAA compliance requires administrative, physical, and technical safeguards. ComplianceLayer covers the technical safeguards that are externally observable — encryption in transit, access control verification, and transmission security. You still need policies, training, BAAs, and physical security.

Which HIPAA safeguards does ComplianceLayer cover?

ComplianceLayer maps to HIPAA Security Rule technical safeguards under 45 CFR Part 164 Subpart C, including: Access Control (164.312(a)), Transmission Security (164.312(e)), Integrity (164.312(c)), and Person/Entity Authentication (164.312(d)).

Can business associates use ComplianceLayer?

Yes. Business associates handling ePHI need the same technical safeguards as covered entities. ComplianceLayer helps BAs demonstrate their external security posture meets HIPAA requirements for transmission security and access control.

How does ComplianceLayer check transmission security?

The SSL/TLS module validates certificate validity, TLS version (1.2+), cipher suite strength, and HSTS header enforcement. The email module checks SPF, DKIM, and DMARC configuration to protect against email-based ePHI exposure.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.