Home All services
Start a project → Call Now

ePHI security controls engineering

Security controls for systems that hold health data — built before your HITRUST assessor arrives.

We build security controls into systems that hold electronic protected health information (ePHI), document them and write the policies behind them. We don't assess them against HITRUST's requirements. HITRUST licenses other firms to do that, and only HITRUST issues a certification.

  • Controls built into code and configuration
  • Policies that match what was built
  • We reply within one working day.
  • HITRUST Assessment Handbook v1.2
  • HITRUST CSF v11.8.0
  • HIPAA Security Rule
Illustration: a server with a key, a gear and a tick above it, a health record folder with a heartbeat line leaning against it, and a panel of glowing cells with the last one still unlit

In brief

What it is
Hands-on security engineering in the systems that hold health data: access control, audit logs, encryption, key handling and the written policies behind them.
Why it matters
A control has to be in place and running for a while before an assessor can test it as implemented. HITRUST's Assessment Handbook v1.2 says a new or fixed control must operate in its current state for at least 90 consecutive days first.
What you get
Fixes for the gaps on your list, built and documented, so the licensed assessor you choose has working controls to test once they have run long enough.

The engineering itself

What we build into systems that handle ePHI.

The work is code and configuration, plus the documents that describe them. We work in React, Next.js, Node, Python and PostgreSQL. We don't present any of these items as a HITRUST requirement. Each is ordinary security engineering that your gap list may or may not call for.

Access by role

Role-based access to ePHI, enforced in your application code, so each person reaches only the records their role allows.

Audit logs

Logging that records who read or changed ePHI, kept where you agreed, from the day the control goes live.

Encryption

ePHI encrypted in transit and at rest: while it moves between systems and while it is stored.

Secrets and keys

Passwords, API keys and encryption keys kept out of source code and out of logs.

Configuration and dependency fixes

Fixes to settings and to the third-party libraries your code depends on, for gaps already on your list.

Security policies

Policies that describe your controls as they are actually built, for your management to approve and own.

HIPAA places its own duties on a business associate, and they apply with or without a HITRUST assessment. Our HIPAA compliance page covers the Security Rule evidence those duties call for.

Builders and assessors

A HITRUST program has an engineering half and a licensed half.

We work only on the first, and HITRUST's own rules explain why.

Before any assessor arrives, a HITRUST program needs controls that exist and work, and written policies that match what your systems really do. That is engineering, and it is the half we do.

The other half is assessment against the HITRUST CSF, HITRUST's security framework, currently v11.8.0. HITRUST licenses that work. Its Become an Assessor page says HITRUST CSF readiness work for clients belongs to firms it has licensed as External Assessors or Readiness Licensees. We are not one of them.

HITRUST's rules keep the two halves apart. The team that assesses you may not write your policies or build your controls. Nobody who built or ran your controls in the past 12 months may work on your validated assessment. The table below shows where the line falls.

Frameworks we do advise on sit under GRC and compliance services.

What this work does not include. We hold no HITRUST license and perform no HITRUST readiness assessment, gap assessment or advisory service. We don't map policies to the HITRUST CSF or score them against HITRUST's requirements, and we do no HITRUST testing.

Independence rules

What an assessor may do for a client it assesses, and what we do.

HITRUST keeps building and assessing apart. Each row shows where it draws the line.

Assessor column: HITRUST Assessment Handbook v1.2. SecWiz column: SecWiz's own scope.
Work for the same clientThe assessor's own teamSecWiz
Readiness or gap review before assessmentPermittedNot offered; it needs a HITRUST license
Writing the client's security policiesNot permittedYes
Implementing or operating a controlNot permittedYes, implemented and documented
Staffing the validated assessmentNobody who built or ran the controls in the past yearNo; only an Authorized External Assessor can
Deciding how much testing is neededThe assessor; the client cannot restrict itNo role in that choice

Order of work

Where engineering sits in a HITRUST program, and where it stops.

We appear in step two only. Each control's running time starts the day it goes live, so plan the build early.

  1. Find the gaps

    Your own team, or a firm HITRUST has licensed, compares your environment with HITRUST's requirements and writes down each place it falls short.

  2. Build and document the fixes

    Working from that written list, we build each fix into the application and its data layer, document how it works and draft the security policies behind it. Your team and your assessor judge it against HITRUST's requirements.

  3. Let the controls run

    Each new or fixed control must run in its current state for at least 90 consecutive days before an assessor can test it as implemented. That wait is the incubation period set in HITRUST's Assessment Handbook v1.2.

  4. Validated assessment

    The assessment firm you choose must be a HITRUST Authorized External Assessor. No other kind of firm can perform the validated assessment submitted to HITRUST for certification.

  5. HITRUST decides

    HITRUST reviews the assessor's work in its own quality assurance step. It then issues a certification if the scores meet its thresholds, or a validated-only report if they do not.

Related work

Related questions, and the page that answers each.

HITRUST may not be the only request on your desk. Pick the question closest to yours.

FAQ

Questions buyers ask about HITRUST and SecWiz.

Licenses, guarantees, independence and timing. For anything else, ask us directly.

No. SecWiz is not an Authorized External Assessor or a Readiness Licensee, and it holds no other HITRUST license. It does the engineering: implementing and documenting security controls, writing security policies and fixing known gaps in systems that handle ePHI. Only an Authorized External Assessor can perform the validated assessment submitted to HITRUST for certification, so you contract that firm separately.

No, and no consultant or engineering firm can. Under HITRUST's Assessment Handbook v1.2, the External Assessor submits its validated assessment, HITRUST runs a quality assurance review, and HITRUST issues a certification only when the scores meet its thresholds. When they fall short, it issues a validated-only report instead. SecWiz's part ends with controls built and documented.

No. HITRUST's Assessment Handbook v1.2 bars anyone who helped implement or operate a client's controls in the past 12 months from working on that client's validated assessment. Where an assessor relies on earlier testing, the handbook also says people who designed, implemented or operated a control are not objective testers of it. SecWiz builds controls and holds no HITRUST license, so it does no HITRUST testing.

HITRUST's Assessment Handbook v1.2 sets that clock. A new or remediated control must operate in its current state for at least 90 consecutive days before it can be tested as implemented, and a shorter run earns no partial credit. Allow that time between the day an engineering fix goes live and the day an assessor tests it.

Yes, SecWiz writes security policies that describe your controls as they are actually built, for your management to approve and own. It does not map those policies to the HITRUST CSF or score them against HITRUST's requirements. That judgment belongs to your own team or to a HITRUST-licensed firm, and HITRUST keeps the assessor's team from writing them.

Search the directory of External Assessors and Readiness Licensees on HITRUST's own website. HITRUST says organizations not listed there are not authorized to conduct HITRUST readiness or assessment work. Check it before signing with anyone offering readiness, gap assessment or advisory services under the HITRUST name. SecWiz is not listed, which is why it offers engineering only.

Let's talk

Bring your gap list, and we'll scope the build.

Tell us which systems hold ePHI and share the gaps already written down. Anything we scope is engineering only. We reply within one working day.