Wise Forge Labs · Industries · Healthcare

HIPAA, HITRUST, and thePHI perimeter mid-market health firms carry.

The healthcare deep dive for firms of roughly 25 to 500 headcount — large enough that the onboarding EHR review reads against BAA-bound workloads, small enough that improvising a platform team isn’t an option. The page below names the regulatory shape firms in this band arrive carrying, the HIPAA and HITRUST specifics the briefing memo cites by default, and the three per-vertical outcomes a 25–500- person firm typically sees at handover.

HIPAA Security & Privacy Rules
HITRUST CSF v11.x
NIST CSF 2.0
Mid-market · 25–500 headcount

The stakes

Regulated mid-market health firms arrive carrying a six-layer obligation map — not a checklist.

The cloud posture problems specific to this segment are not the cloud posture problems of a financial-services firm or a professional-services firm. PHI sits across multi-account footprints with the data-residency perimeter rarely documented in one place; the BAA inventory lives in a wiki the legal team stopped trusting; audit-evidence collection gets rebuilt every quarter because the workpaper that satisfied last quarter’s assessor doesn’t survive turnover. The page below is the deeper read on what the engagement inherits here, and what a 25–500-person firm typically sees at handover.

HIPAA navigation

HIPAA is the floor — the binding regime is the floor, the ceiling, and the breach-notification belt above both.

The three sub-blocks below name the regulatory references the briefing memo cites by default — the HIPAA Security Rule as the technical control map, the HIPAA Privacy Rule as the period on top of the Security Rule, and the 50-state backdrop that turns the federal floor into a moving ceiling as the firm’s footprint crosses state lines.

01

The Security Rule · 45 CFR § 164.308 · 164.310 · 164.312

Three categories of safeguard, three failure modes the auditor sees first.

The HIPAA Security Rule splits its 54 implementation specifications into administrative, physical, and technical safeguards — each with the same evidence-collection shape the last assessor accepted, and each with the same drift pattern mid-market health firms carry into the engagement. The briefing memo opens at risk analysis (164.308(a)(1)(ii)(A)) because that’s where every other safeguard returns to, then walks technical safeguards (164.312) against the cloud primitives the firm already has, so the control map lands on real buttons rather than a separate stack.

02

The Privacy Rule · 45 CFR § 164.500 – 534

The overlay on top of the Security Rule, not a separate programme.

The Privacy Rule is read as the minimum-necessary, accounting-of-disclosures, and patient-rights overlay that determines what gets logged, who sees it, and how a patient request for records is answered in 30 days. The engagement lands a Privacy Rule workflow that connects to the Security Rule audit trail — so the same evidence that satisfies the Privacy Rule’s accounting-of-disclosures obligation (164.528) also satisfies the Security Rule’s audit-control requirement (164.312(b)) without two parallel binders to maintain.

03

The 50-state backdrop

Federal floor, state ceiling — and the breach-notification belt above both.

HIPAA is the federal floor; the binding regime for a mid-market health firm is usually federal floor plus the strongest state law the firm’s footprint crosses — California CMIA, New York SHIELD, Texas Medical Records Privacy, Washington My Health My Data, Massachusetts 201 CMR 17.00, Illinois Biometric Information Privacy Act where biometric identifiers sit in the patient record. The HITECH breach-notification regime sits above both, and the engagement treats all three layers as one obligation map so the briefing memo says which standard a finding returns to when the letter arrives.

HITRUST CSF

One rubric, three reading levels — the rubric the briefing memo cites by default in healthcare.

HITRUST CSF v11.x is the working framework the practice cites by default in healthcare — not because it supersedes the underlying standards bodies it assembles, but because the catalogue is one place the OCR inquiry, the HITRUST assessor, and the procurement partner can each read against. The sub-blocks below name how the engagement reads HITRUST at three sizing bands, and how the same HITRUST control reference returns NIST CSF 2.0, ISO/IEC 27001, and the AICPA TSC in parallel so one binder answers several assessors at once.

01

HITRUST CSF v11.x as the working framework

One rubric, three reading levels — maturity, certification, and inheritance.

The HITRUST CSF assembles NIST 800-53, ISO/IEC 27001 + 27017, HIPAA Security and Privacy Rules, the AICPA TSC, and PCI DSS into one control catalogue with three reading levels — PRISMA-based maturity scores for the board, the certification posture (e1 / i1 / r2) for procurement and partners, and the inheritance model so each business unit doesn’t re-prove what the enterprise account already proves. The engagement reads v11.x as the rubric the briefing memo cites by default, with the underlying standards bodies called in as a finding needs them.

02

Certification posture against engagement sizing

e1 / i1 / r2 — what the firm actually needs at its headcount band.

A 25–60-person firm usually lands at HITRUST e1 (basic cybersecurity hygiene) with i1 in the path on a 12-month horizon. A 60–200-person firm usually lands at i1 (moderate assurance) with r2 scoping against one clinical workload. A 200–500-person firm usually lands at r2 (risk-based, two-year cycle) with the validated assessment tied to a regulator or health-system partner who already demands it. The certification scope starts at the perimeter the BAA inventory already describes — not at the cloud bill, which inflates both cost and timeline without adding controls.

03

CSF to NIST CSF 2.0 / ISO 27001 / SOC 2 TSC mapping

Same artefact, three assessors — the inheritance a multi-framework firm needs.

The HITRUST CSF control catalogue maps cleanly into NIST CSF 2.0 functions, ISO/IEC 27001 Annex A, and the AICPA TSC SOC 2 common criteria. The engagement authors the control map once — usually as a Rubrickeeper-style rubric tied to the workpaper the audit firm reads — and the same evidence responds to the HITRUST assessor in year one, the SOC 2 auditor in year two, and the OCR inquiry that follows a breach disclosure in year three. Three binders becomes one; the briefing memo states which control each finding returns to.

Per-vertical outcomes

Three engagements the practice lands for healthcare clients in this band.

The cards below are the three engagements the practice lands most often for 25–500-person healthcare clients — patient portal migration off a hosted EHR add-on, EHR cloud posture review against the HITRUST CSF, and third-party BAA risk review. Each names the symptom the firm arrives carrying, what the engagement lands in plain language, and the outcome a 25–500-person firm typically sees at handover — with the metric a board member can quote.

01Outcome
Patient portal migration off a hosted EHR add-on
Time to defensible cutover: ~10 weeks

What the engagement lands

A wave-planned migration of the patient portal, identity, and adjacent clinical applications from a hosted EHR add-on into a BAA-scoped cloud account, with the cutover choreography preserving patient-facing uptime against published scheduled windows. Identity flows (federated SSO, MFA, SCIM) land alongside the migration so the post-cutover portal inherits the same authentication controls the workback assumed.

Outcome at handover

The migration lands in roughly ten weeks across two clinic-weekend cutovers, with patient-facing systems live against published windows. The BAA perimeter moves from a vendor add-on to the cloud control plane — so the next portal refresh, the next EHR add-on review, and the next HITRUST assessment all read against one set of boundary claims. The post-engagement portal retention is tied to a one-quarter steering committee, not a permanent external team.

02Outcome
EHR workload cloud posture review against HITRUST CSF
HITRUST domains scored: 23 of 23

What the engagement lands

A workload-by-workload read of where the EHR footprint actually lives against the HITRUST CSF v11.x control catalogue — audit logging, encryption at rest and in transit, identity and access management, segmentation between clinical and corporate accounts, vendor and BAA inventory, and the contingency-plan posture (164.308(a)(7)). Each finding ties to a control reference and a remediation workstream sized to the platform team that has to inherit it.

Outcome at handover

A defensible target architecture lands in roughly eight weeks, with the EHR workload segmented from corporate development accounts at the cloud control plane rather than by convention. The HITRUST readiness scoring reads twenty-three domains against the rubric the engagement uses on the discovery call; remediation runs on a 60-90 day cadence with the firm’s platform team owning the workstream, not an external body.

03Outcome
Third-party BAA-bound vendor risk review
BAA perimeter rebuilt: in ~4 weeks

What the engagement lands

An inventory-and-control read of the third-party BAA perimeter — which PHI workloads run under which BAA, which business associate has the security exhibit attached, which doesn’t, and which vendor change was approved without an updated BAA on the contract file. The engagement lands a BAA inventory that maps to the cloud control plane, plus a vendor-risk questionnaire grounded in the same rubric the firm uses on its own posture, so each business associate reads against the same control catalogue the assessor reads.

Outcome at handover

The BAA inventory rebuilds in roughly four weeks against the actual cloud control plane, not the wiki the legal team stopped trusting. Vendors drop into three buckets — current, renewal-window, and out-of-scope-with-action — and the renewal cycle reads against the same rubric the firm applies internally. The OCR response if a business associate breach lands in the next 18 months reads against an artefact that survived staff turnover, because the artefact is the platform’s output, not a binder someone maintains.

These three outcomes are the engagements most often preceded by a discovery call in the healthcare band. Other engagements — cloud readiness, landing zone, fractional advisor — are surfaced on the parent Services page; the healthcare-specific deep dive is the page above.

Framework anchors

The vocabulary the briefing memo already speaks.

Every recommendation in a healthcare engagement cites the standards bodies the OCR inquiry, the HITRUST assessor, and the procurement partner each read without translation. The anchors listed here are the same anchors cited on /why, /industries, and /case-studies — one source of truth, surfaced in one place.

HIPAA Security Rule
HIPAA Privacy Rule
HITRUST CSF v11.x
NIST CSF 2.0
ISO/IEC 27001
ISO/IEC 27017

The HITRUST CSF is the rubric the assessment reads against. The underlying NIST CSF 2.0, ISO/IEC 27001 + 27017, and the AICPA TSC remain the publication each finding returns to.

Anchors used on this page match /why and /industries — one source of truth, surfaced on every read.

Start the conversation

Tell us the workload that worries you most.

The first conversation is a one-hour briefing. We listen, ask three or four pointed questions — usually about the BAA inventory, the EHR footprint, and the audit-evidence workflow — and tell you whether we are the right firm for the next step, or whether you should hire elsewhere.

We respond within two business days. No newsletter signup, no AI triage. BAA-bound engagements are quoted under the same engagement framework as non-BAA engagements — the contract terms, not the regulator, set the relationship.