HIPAA Security Rule
Compliance Scanning
Healthcare providers and business associates must implement HIPAA Security Rule technical safeguards to protect electronic Protected Health Information (ePHI). ComplianceLayer maps external scan findings to the specific 45 CFR 164.312 controls.
HIPAA Technical Safeguards Mapped to Scan Modules
Each control reference follows 45 CFR Part 164 Subpart C — the HIPAA Security Rule technical safeguard requirements.
| Control ID | Safeguard | Scan Module | What We Check |
|---|---|---|---|
| 164.312(a)(1) | Access Control | Open Ports | Implement technical policies to allow access only to authorized persons. Detects exposed RDP, SSH, database ports, and SMB services. |
| 164.312(d) | Person or Entity Authentication | Open Ports | Verify identity of persons seeking access to ePHI. Identifies exposed authentication endpoints (RDP, database ports). |
| 164.312(e)(1) | Transmission Security | SSL/TLS / Email | Protect ePHI transmitted over electronic networks. Validates TLS configuration, HSTS enforcement, SPF, DKIM, and DMARC. |
| 164.312(e)(2)(ii) | Encryption | SSL/TLS | Implement encryption mechanism for ePHI in transit. Checks TLS versions, cipher strength, certificate validity, and HTTPS enforcement. |
| 164.312(c)(1) | Integrity | Security Headers | Protect ePHI from improper alteration or destruction. Validates Content-Security-Policy and integrity checking mechanisms. |
| 164.308(a)(1)(ii)(A) | Risk Analysis | All Modules | Conduct accurate and thorough assessment of risks to ePHI. ComplianceLayer scans across 15 modules covering the external attack surface. |
| 164.308(a)(1)(ii)(B) | Risk Management | All Modules | Implement security measures to reduce risks to a reasonable level. Identifies expired certificates, vulnerable configurations, and exposures. |
| 164.308(a)(5)(ii)(B) | Protection from Malicious Software | Email / Headers | Guard against malicious software. Checks DMARC anti-phishing protection and Content-Security-Policy for script injection prevention. |
HIPAA applies to covered entities and business associates handling PHI. These are HIPAA Security Rule-relevant technical controls. Full compliance requires organizational safeguards beyond technical scanning.
HIPAA Compliance Evidence in 3 Steps
Enter your domain
Submit any domain handling ePHI. ComplianceLayer scans the external attack surface across 15 scan modules.
Review HIPAA mapping
Each finding maps to specific 45 CFR 164.312 technical safeguard requirements with pass, fail, or partial status.
Export for auditors
Download the compliance report to support HIPAA risk assessments, auditor reviews, or BAA documentation.
Common questions
Does ComplianceLayer make us HIPAA compliant?
No. HIPAA compliance requires administrative, physical, and technical safeguards. ComplianceLayer covers the technical safeguards that are externally observable — encryption in transit, access control verification, and transmission security. You still need policies, training, BAAs, and physical security.
Which HIPAA safeguards does ComplianceLayer cover?
ComplianceLayer maps to HIPAA Security Rule technical safeguards under 45 CFR Part 164 Subpart C, including: Access Control (164.312(a)), Transmission Security (164.312(e)), Integrity (164.312(c)), and Person/Entity Authentication (164.312(d)).
Can business associates use ComplianceLayer?
Yes. Business associates handling ePHI need the same technical safeguards as covered entities. ComplianceLayer helps BAs document their external security posture in support of the HIPAA transmission security and access control safeguards. It does not determine HIPAA compliance.
How does ComplianceLayer check transmission security?
The SSL/TLS module validates certificate validity, TLS version (1.2+), cipher suite strength, and HSTS header enforcement. The email module checks SPF, DKIM, and DMARC configuration to protect against email-based ePHI exposure.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. The free tier is here to stay.
All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.