HIPAA Readiness
Audit-ready compliance for Canadian digital health companies, SaaS vendors, and service providers handling protected health information.
What This Engagement Covers
Canadian health-tech and digital health companies expanding into the US market or processing healthcare data for US covered entities must meet the stringent requirements of the Health Insurance Portability and Accountability Act (HIPAA). Our HIPAA readiness assessment bridges the gap between Canadian health privacy frameworks (such as Ontario PHIPA and Alberta HIA) and the US HIPAA Security, Privacy, and Breach Notification Rules. We ensure your technical safeguards, administrative policies, and business associate agreements withstand scrutiny from US partners and compliance auditors.
What This Means for Canadian Businesses
For Canadian health innovators based in Calgary, Toronto, or anywhere in Canada, handling US electronic protected health information (ePHI) brings direct exposure to HIPAA as a Business Associate (BA). Even when infrastructure resides in Canadian data centres or Canadian AWS/Azure regions, US healthcare providers require certified verification of HIPAA Security Rule compliance before executing Business Associate Agreements (BAAs). Our readiness engagement integrates Canadian privacy fundamentals (PIPEDA, PHIPA in Ontario, HIA in Alberta) with HIPAA Security Rule requirements (45 CFR Part 160 and Part 164, Subparts A and C), delivering a unified compliance roadmap.
Domains & Controls We Assess
We evaluate every technical, operational, and administrative requirement against authoritative criteria.
Administrative Safeguards (§ 164.308)
- § 164.308(a)(1) - Security Management Process: formal risk analysis and risk management plan
- § 164.308(a)(2) - Assigned Security Responsibility: designated HIPAA Security Official
- § 164.308(a)(3) - Workforce Security: clearance procedures, role-based authorization, and termination workflows
- § 164.308(a)(5) - Security Awareness & Training: mandatory annual training and phishing simulation
- § 164.308(a)(8) - Evaluation: periodic technical and non-technical security evaluations
Physical Safeguards (§ 164.310)
- § 164.310(a)(1) - Facility Access Controls: limiting physical access to ePHI systems and data centres
- § 164.310(b) - Workstation Use: policies specifying proper functions and workstation locations
- § 164.310(c) - Workstation Security: physical safeguards for all workstations accessing ePHI
- § 164.310(d)(1) - Device and Media Controls: receipt, movement, and secure disposal of storage media
Technical Safeguards (§ 164.312)
- § 164.312(a)(1) - Access Control: unique user identification, emergency access, and automatic logoff
- § 164.312(b) - Audit Controls: mechanisms to record and examine activity in ePHI systems
- § 164.312(c)(1) - Integrity Controls: mechanisms to protect ePHI from improper alteration or destruction
- § 164.312(d) - Person or Entity Authentication: verification of identity seeking access to ePHI
- § 164.312(e)(1) - Transmission Security: end-to-end encryption (TLS 1.3) of ePHI across public networks
Business Associate Agreements & Vendor Governance (§ 164.502)
- BAA Inventory: executed Business Associate Agreements with all cloud providers and subcontractors
- Subcontractor Compliance: verification that third-party processors maintain equivalent HIPAA safeguards
- Permitted Uses and Disclosures: strict contractual limitations on secondary data use
Breach Notification & Incident Response (§ 164.400-414)
- Breach Discovery & Four-Factor Risk Assessment for potential compromises of unsecured PHI
- Timely notification procedures to Covered Entities (typically within 10-30 days under BA contracts)
- Incident response plan tested against ransomware, credential theft, and accidental misconfiguration
Engagement Deliverables
Everything you need to prove control operating effectiveness to your auditors and enterprise clients.
HIPAA Security & Privacy Gap Assessment Report
Technical Safeguard Evaluation & Architecture Review
Comprehensive Risk Analysis Document (NIST SP 800-30 aligned)
Business Associate Agreement (BAA) Readiness Review
HIPAA Policy & Procedure Template Pack
Remediation Roadmap with Prioritized Timelines
Trusted by Growing Businesses
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Common Questions
Yes. If your Canadian organization handles, stores, or transmits protected health information (PHI) on behalf of a US healthcare provider, health plan, or healthcare clearinghouse, you are considered a Business Associate under US law and must sign and comply with a Business Associate Agreement (BAA).
While Canadian laws like PIPEDA, Ontario's PHIPA, and Alberta's HIA share foundational principles with HIPAA, HIPAA imposes very specific prescriptive technical safeguards (such as audit logging, encryption standards, automatic logoff, and formal risk assessment processes) that go beyond Canadian principles-based statutes. A dedicated HIPAA assessment is essential to prove compliance to US partners.
Under US federal HIPAA rules, ePHI may be stored outside the US provided appropriate safeguards and BAAs are executed. However, specific contracts or state laws may impose geographic restrictions. We evaluate your cloud deployment (AWS ca-central-1, Azure Canada Central, etc.) to ensure both HIPAA and Canadian data residency requirements are met.
Often Scoped Together
Ready for Your HIPAA Readiness Assessment?
Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.