HIPAA compliance, without the enterprise price tag.

Run your Security Rule program, track breach deadlines, and get a BAA — in one platform built for teams without a compliance department.

What HIPAA actually asks of you

The HIPAA Security Rule does not hand you a checklist. It asks you to perform a risk analysis, act on what you find, document your safeguards, control who can reach protected health information, and be able to show all of it to an auditor or an investigator years later.

That is a governance problem, and it is the reason so many small healthcare organisations end up managing HIPAA in a folder of spreadsheets that nobody trusts by the second year.

OpenGRC gives you one place to run it. Import the HIPAA framework — one of 152 frameworks included, at no extra cost — and connect the requirements to the controls, evidence, risks and people that actually satisfy them.

Built for the Security Rule

The parts of HIPAA that cause the most pain.

Risk analysis that stays current

Risk analysis that stays current

§164.308(a)(1) requires an accurate, thorough risk analysis and a plan to reduce what it finds. Score inherent and residual risk on a 5x5 matrix, link each risk to the assets and vendors it concerns, and track treatment to completion.

Breach deadlines you cannot miss

Breach deadlines you cannot miss

The Breach Notification Rule gives you 60 days. Our incident module tracks that clock from the moment an incident is opened, alongside the six-phase NIST 800-61r3 response process, forensic evidence with SHA-256 chain of custody, and a full timeline.

Evidence an auditor will accept

Evidence an auditor will accept

Every control carries its implementation, test procedures and evidence. Run internal audits, export draft or final report PDFs, and give an external assessor their own time-bounded portal rather than a shared folder.

How OpenGRC maps to the Security Rule

HIPAA requirementIn OpenGRC
§164.308(a)(1) Risk analysis and risk managementRisk register with inherent and residual scoring, treatment strategies, and AI-assisted risk assessment
§164.308(a)(3)–(4) Workforce security and information access managementUser Access Review campaigns over applications and assets, with reviewer sign-off and round finalisation
§164.308(a)(5) Security awareness and trainingChecklists and recurring campaigns with signature approval
§164.308(a)(6) Security incident proceduresIncident response with playbooks, tasks, timeline and lessons learned
§164.308(a)(7) Contingency planningPolicy management with full lifecycle, revision history and exceptions
§164.308(b) Business associate contractsVendor management with compliance document tracking, expiry alerts and risk scoring
§164.310 Physical safeguardsAsset management with hierarchy, ownership, lifecycle and security posture
§164.312 Technical safeguardsControl catalogue and implementation tracking with maturity and test procedures
§164.316 Documentation and retentionVersioned policies, immutable audit trail, activity logging on every record
§164.400–414 Breach Notification RuleBreach notification deadline tracking, 60-day clock from incident open

BAAs, PHI, and being straight with you

We sign BAAs

If you are a Covered Entity or a Business Associate, we will execute a Business Associate Agreement with you. Where a BAA is in place, it governs how protected health information is handled between us. Many GRC vendors at this price point will not do this at all.

OpenGRC is not a PHI repository

This matters, so we would rather say it plainly than let you find out later. OpenGRC is a governance tool: it manages your compliance program — risks, controls, evidence, policies, vendors and incidents. It is not designed or intended as a general store for patient records, and you should not use it as one.

Do not process, store or transmit PHI through the platform unless you are a Covered Entity or Business Associate with a BAA executed with us. If you are unsure where the line sits for your situation, ask us before you upload anything — we would rather have that conversation early.

How we protect what you do store

Encryption in transit and at rest, logical isolation with a key unique to your instance, an annual SOC 2 Type II examination by an independent auditor, annual third-party penetration testing, and 24-hour security incident notification. Full detail on our security page.

HIPAA questions, answered

Does OpenGRC make my organisation HIPAA compliant?

No software can do that. HIPAA compliance depends on your safeguards, your workforce and your decisions. What OpenGRC does is give you one place to run the program the Security Rule expects: the risk analysis, the controls and their evidence, access reviews, incident handling, vendor agreements and the documentation trail an auditor will ask for.

Will you sign a Business Associate Agreement?

Can I store patient records in OpenGRC?

Is HIPAA included, or is it an add-on?

How does OpenGRC handle the 60-day breach notification deadline?

Can our external auditor get access without seeing everything?

We are small. Is this going to be too much?