HIPAA compliance isn't about knowing the rule. It's about proving the work is getting done.
Most organizations handling protected health information already know HIPAA exists. The hard part is maintaining the evidence, documentation, reviews, training and security activities that demonstrate it over time.
Built for Business Associates
Designed for organizations that support healthcare and have to demonstrate compliance as part of doing business — the ones being asked to prove it, rather than the ones asking.
Not the covered entity's, and not inherited. You signed it, so the duty attaches to you directly — including for the subcontractors you pass protected information to.
What HIPAA actually requires
Many organizations treat HIPAA as a policy requirement. It isn't. It's an ongoing operational program built around safeguards — and every one of them is work somebody has to do and evidence.
None of these is a document you write once. Every item above recurs, and every one has to be evidenced when somebody asks. That's the difference between having a HIPAA policy and running a HIPAA program.
“Addressable” does not mean optional
This is the most common HIPAA misunderstanding, and it surfaces at exactly the wrong moment — during a customer review, an assessment or an evidence request.
“It's addressable, so we can skip it.”
An organization that skipped an addressable specification and wrote nothing down has no answer when an assessor or a customer asks why. One that assessed it, chose an alternative and documented the reasoning has a defensible position — which is the entire difference.
HIPAA compliance is continuous
HIPAA is not a one-time project. These activities repeat, and every one of them has to be evidenced when somebody asks.
| Activity | Typical frequency |
|---|---|
| Risk assessment | Annually or on change |
| Workforce training | Annually, plus new hires |
| Access reviews | Quarterly |
| Policy reviews | Annually |
| Vendor reviews | Ongoing |
| Incident response testing | Periodically |
| Evidence collection | Continuous |
Getting a program started is the easy part. Keeping it current — between audits, between customer requests, while everyone has another job — is where programs quietly decay. Nothing tells you it's happening until somebody asks for evidence.
HIPAA, turned into work your team can finish
Greypike converts HIPAA requirements into structured tasks. Instead of interpreting regulatory language, your team sees exactly what needs to be done, who owns it, what evidence is required, and when it's due.
Conduct the quarterly access review
Export the current list of accounts with access to systems holding ePHI. Confirm each is still required, record the decision, and remove what isn't.
Accepted. Two contractor accounts removed and recorded. Worth noting the review date in the BAA response you send next month — it's the evidence they'll ask for.
One program, multiple requirements
HIPAA work overlaps heavily with the other things your customers ask about. Pick a task and see everything it already answers.
Complete the work once, and it answers everything that asks about it. The same evidence satisfies HIPAA, the Business Associate Agreement, the customer questionnaire, the insurance renewal and the SOC 2 control — because it's the same underlying work described in different language.
Why Business Associates choose Greypike
Most HIPAA tools document compliance. Greypike helps complete it — which is the only version a customer can actually verify.
Straightforward pricing
No sales process required to see the number. HIPAA is one framework, and one framework is what the subscription covers.
or $4,000 a year, saving $788
First 25 customers only. Standard pricing is higher. Founding customers keep this rate for 24 months. 12-month term, no setup fee.
Book a demoAdding SOC 2 later? See framework pricing →
Make HIPAA something your team can actually finish
Clear tasks, a dedicated compliance manager reviewing the work, and evidence that's already there when a covered entity, an insurer or a customer asks. The next request is coming whether the program is ready or not.