HIPAA compliance, without the enterprise price tag.
Run your Security Rule program, track breach deadlines, and get a BAA — in one platform built for teams without a compliance department.
What HIPAA actually asks of you
The HIPAA Security Rule does not hand you a checklist. It asks you to perform a risk analysis, act on what you find, document your safeguards, control who can reach protected health information, and be able to show all of it to an auditor or an investigator years later.
That is a governance problem, and it is the reason so many small healthcare organisations end up managing HIPAA in a folder of spreadsheets that nobody trusts by the second year.
OpenGRC gives you one place to run it. Import the HIPAA framework — one of 152 frameworks included, at no extra cost — and connect the requirements to the controls, evidence, risks and people that actually satisfy them.
The parts of HIPAA that cause the most pain.
Risk analysis that stays current
§164.308(a)(1) requires an accurate, thorough risk analysis and a plan to reduce what it finds. Score inherent and residual risk on a 5x5 matrix, link each risk to the assets and vendors it concerns, and track treatment to completion.
Breach deadlines you cannot miss
The Breach Notification Rule gives you 60 days. Our incident module tracks that clock from the moment an incident is opened, alongside the six-phase NIST 800-61r3 response process, forensic evidence with SHA-256 chain of custody, and a full timeline.
Evidence an auditor will accept
Every control carries its implementation, test procedures and evidence. Run internal audits, export draft or final report PDFs, and give an external assessor their own time-bounded portal rather than a shared folder.
How OpenGRC maps to the Security Rule
| HIPAA requirement | In OpenGRC |
|---|---|
| §164.308(a)(1) Risk analysis and risk management | Risk register with inherent and residual scoring, treatment strategies, and AI-assisted risk assessment |
| §164.308(a)(3)–(4) Workforce security and information access management | User Access Review campaigns over applications and assets, with reviewer sign-off and round finalisation |
| §164.308(a)(5) Security awareness and training | Checklists and recurring campaigns with signature approval |
| §164.308(a)(6) Security incident procedures | Incident response with playbooks, tasks, timeline and lessons learned |
| §164.308(a)(7) Contingency planning | Policy management with full lifecycle, revision history and exceptions |
| §164.308(b) Business associate contracts | Vendor management with compliance document tracking, expiry alerts and risk scoring |
| §164.310 Physical safeguards | Asset management with hierarchy, ownership, lifecycle and security posture |
| §164.312 Technical safeguards | Control catalogue and implementation tracking with maturity and test procedures |
| §164.316 Documentation and retention | Versioned policies, immutable audit trail, activity logging on every record |
| §164.400–414 Breach Notification Rule | Breach notification deadline tracking, 60-day clock from incident open |
BAAs, PHI, and being straight with you
We sign BAAs
If you are a Covered Entity or a Business Associate, we will execute a Business Associate Agreement with you. Where a BAA is in place, it governs how protected health information is handled between us. Many GRC vendors at this price point will not do this at all.
OpenGRC is not a PHI repository
This matters, so we would rather say it plainly than let you find out later. OpenGRC is a governance tool: it manages your compliance program — risks, controls, evidence, policies, vendors and incidents. It is not designed or intended as a general store for patient records, and you should not use it as one.
Do not process, store or transmit PHI through the platform unless you are a Covered Entity or Business Associate with a BAA executed with us. If you are unsure where the line sits for your situation, ask us before you upload anything — we would rather have that conversation early.
How we protect what you do store
Encryption in transit and at rest, logical isolation with a key unique to your instance, an annual SOC 2 Type II examination by an independent auditor, annual third-party penetration testing, and 24-hour security incident notification. Full detail on our security page.
HIPAA questions, answered
Does OpenGRC make my organisation HIPAA compliant?
No software can do that. HIPAA compliance depends on your safeguards, your workforce and your decisions. What OpenGRC does is give you one place to run the program the Security Rule expects: the risk analysis, the controls and their evidence, access reviews, incident handling, vendor agreements and the documentation trail an auditor will ask for.
™