HIPAA Security Rule
Compliance Scanning
Healthcare providers and business associates must implement HIPAA Security Rule technical safeguards to protect electronic Protected Health Information (ePHI). ComplianceLayer maps external scan findings to the specific 45 CFR 164.312 controls.
HIPAA Technical Safeguards Mapped to Scan Modules
Each control reference follows 45 CFR Part 164 Subpart C — the HIPAA Security Rule technical safeguard requirements.
| Control ID | Safeguard | Scan Module | What We Check |
|---|---|---|---|
| 164.312(a)(1) | Access Control | Open Ports | Implement technical policies to allow access only to authorized persons. Detects exposed RDP, SSH, database ports, and SMB services. |
| 164.312(d) | Person or Entity Authentication | Open Ports | Verify identity of persons seeking access to ePHI. Identifies exposed authentication endpoints (RDP, database ports). |
| 164.312(e)(1) | Transmission Security | SSL/TLS / Email | Protect ePHI transmitted over electronic networks. Validates TLS configuration, HSTS enforcement, SPF, DKIM, and DMARC. |
| 164.312(e)(2)(ii) | Encryption | SSL/TLS | Implement encryption mechanism for ePHI in transit. Checks TLS versions, cipher strength, certificate validity, and HTTPS enforcement. |
| 164.312(c)(1) | Integrity | Security Headers | Protect ePHI from improper alteration or destruction. Validates Content-Security-Policy and integrity checking mechanisms. |
| 164.308(a)(1)(ii)(A) | Risk Analysis | All Modules | Conduct accurate and thorough assessment of risks to ePHI. ComplianceLayer scans 16 modules covering the external attack surface. |
| 164.308(a)(1)(ii)(B) | Risk Management | All Modules | Implement security measures to reduce risks to a reasonable level. Identifies expired certificates, vulnerable configurations, and exposures. |
| 164.308(a)(5)(ii)(B) | Protection from Malicious Software | Email / Headers | Guard against malicious software. Checks DMARC anti-phishing protection and Content-Security-Policy for script injection prevention. |
HIPAA applies to covered entities and business associates handling PHI. These are HIPAA Security Rule-relevant technical controls. Full compliance requires organizational safeguards beyond technical scanning.
HIPAA Compliance Evidence in 3 Steps
Enter your domain
Submit any domain handling ePHI. ComplianceLayer scans the external attack surface across 16 security modules.
Review HIPAA mapping
Each finding maps to specific 45 CFR 164.312 technical safeguard requirements with pass, fail, or partial status.
Export for auditors
Download the compliance report as evidence for HIPAA risk assessments, auditor reviews, or BAA documentation.
Common questions
Does ComplianceLayer make us HIPAA compliant?
No. HIPAA compliance requires administrative, physical, and technical safeguards. ComplianceLayer covers the technical safeguards that are externally observable — encryption in transit, access control verification, and transmission security. You still need policies, training, BAAs, and physical security.
Which HIPAA safeguards does ComplianceLayer cover?
ComplianceLayer maps to HIPAA Security Rule technical safeguards under 45 CFR Part 164 Subpart C, including: Access Control (164.312(a)), Transmission Security (164.312(e)), Integrity (164.312(c)), and Person/Entity Authentication (164.312(d)).
Can business associates use ComplianceLayer?
Yes. Business associates handling ePHI need the same technical safeguards as covered entities. ComplianceLayer helps BAs demonstrate their external security posture meets HIPAA requirements for transmission security and access control.
How does ComplianceLayer check transmission security?
The SSL/TLS module validates certificate validity, TLS version (1.2+), cipher suite strength, and HSTS header enforcement. The email module checks SPF, DKIM, and DMARC configuration to protect against email-based ePHI exposure.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.