Skip to main content
Home/Readiness/HIPAA Readiness
HIPAA Compliance

HIPAA Readiness

Audit-ready compliance for Canadian digital health companies, SaaS vendors, and service providers handling protected health information.

Standard HIPAA
Typical Timeline 2-3 weeks
Starting Price $8,500
Scope Delivery Calgary, Toronto & Remote
Assessment Scope

What This Engagement Covers

Canadian health-tech and digital health companies expanding into the US market or processing healthcare data for US covered entities must meet the stringent requirements of the Health Insurance Portability and Accountability Act (HIPAA). Our HIPAA readiness assessment bridges the gap between Canadian health privacy frameworks (such as Ontario PHIPA and Alberta HIA) and the US HIPAA Security, Privacy, and Breach Notification Rules. We ensure your technical safeguards, administrative policies, and business associate agreements withstand scrutiny from US partners and compliance auditors.

Canadian Operations & Law

What This Means for Canadian Businesses

For Canadian health innovators based in Calgary, Toronto, or anywhere in Canada, handling US electronic protected health information (ePHI) brings direct exposure to HIPAA as a Business Associate (BA). Even when infrastructure resides in Canadian data centres or Canadian AWS/Azure regions, US healthcare providers require certified verification of HIPAA Security Rule compliance before executing Business Associate Agreements (BAAs). Our readiness engagement integrates Canadian privacy fundamentals (PIPEDA, PHIPA in Ontario, HIA in Alberta) with HIPAA Security Rule requirements (45 CFR Part 160 and Part 164, Subparts A and C), delivering a unified compliance roadmap.

Calgary HubAlberta Operations
Toronto HubOntario Operations
Control Framework

Domains & Controls We Assess

We evaluate every technical, operational, and administrative requirement against authoritative criteria.

Administrative Safeguards (§ 164.308)

  • § 164.308(a)(1) - Security Management Process: formal risk analysis and risk management plan
  • § 164.308(a)(2) - Assigned Security Responsibility: designated HIPAA Security Official
  • § 164.308(a)(3) - Workforce Security: clearance procedures, role-based authorization, and termination workflows
  • § 164.308(a)(5) - Security Awareness & Training: mandatory annual training and phishing simulation
  • § 164.308(a)(8) - Evaluation: periodic technical and non-technical security evaluations

Physical Safeguards (§ 164.310)

  • § 164.310(a)(1) - Facility Access Controls: limiting physical access to ePHI systems and data centres
  • § 164.310(b) - Workstation Use: policies specifying proper functions and workstation locations
  • § 164.310(c) - Workstation Security: physical safeguards for all workstations accessing ePHI
  • § 164.310(d)(1) - Device and Media Controls: receipt, movement, and secure disposal of storage media

Technical Safeguards (§ 164.312)

  • § 164.312(a)(1) - Access Control: unique user identification, emergency access, and automatic logoff
  • § 164.312(b) - Audit Controls: mechanisms to record and examine activity in ePHI systems
  • § 164.312(c)(1) - Integrity Controls: mechanisms to protect ePHI from improper alteration or destruction
  • § 164.312(d) - Person or Entity Authentication: verification of identity seeking access to ePHI
  • § 164.312(e)(1) - Transmission Security: end-to-end encryption (TLS 1.3) of ePHI across public networks

Business Associate Agreements & Vendor Governance (§ 164.502)

  • BAA Inventory: executed Business Associate Agreements with all cloud providers and subcontractors
  • Subcontractor Compliance: verification that third-party processors maintain equivalent HIPAA safeguards
  • Permitted Uses and Disclosures: strict contractual limitations on secondary data use

Breach Notification & Incident Response (§ 164.400-414)

  • Breach Discovery & Four-Factor Risk Assessment for potential compromises of unsecured PHI
  • Timely notification procedures to Covered Entities (typically within 10-30 days under BA contracts)
  • Incident response plan tested against ransomware, credential theft, and accidental misconfiguration
What You Receive

Engagement Deliverables

Everything you need to prove control operating effectiveness to your auditors and enterprise clients.

HIPAA Security & Privacy Gap Assessment Report

Technical Safeguard Evaluation & Architecture Review

Comprehensive Risk Analysis Document (NIST SP 800-30 aligned)

Business Associate Agreement (BAA) Readiness Review

HIPAA Policy & Procedure Template Pack

Remediation Roadmap with Prioritized Timelines

Client Stories

Trusted by Growing Businesses

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
FAQ

Common Questions

Can a Canadian company be required to comply with HIPAA? +

Yes. If your Canadian organization handles, stores, or transmits protected health information (PHI) on behalf of a US healthcare provider, health plan, or healthcare clearinghouse, you are considered a Business Associate under US law and must sign and comply with a Business Associate Agreement (BAA).

Does Canadian PIPEDA or PHIPA compliance satisfy HIPAA? +

While Canadian laws like PIPEDA, Ontario's PHIPA, and Alberta's HIA share foundational principles with HIPAA, HIPAA imposes very specific prescriptive technical safeguards (such as audit logging, encryption standards, automatic logoff, and formal risk assessment processes) that go beyond Canadian principles-based statutes. A dedicated HIPAA assessment is essential to prove compliance to US partners.

Can ePHI be hosted in Canadian cloud data centres? +

Under US federal HIPAA rules, ePHI may be stored outside the US provided appropriate safeguards and BAAs are executed. However, specific contracts or state laws may impose geographic restrictions. We evaluate your cloud deployment (AWS ca-central-1, Azure Canada Central, etc.) to ensure both HIPAA and Canadian data residency requirements are met.

Get Started

Ready for Your HIPAA Readiness Assessment?

Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.